Privacy notice
This notice explains what this wiki processes, why it is processed, how long it is retained, and the controls available to visitors and contributors.
Last updated 2026-09-091. Controller and contact
The operator/controller for this wiki is The High Satanic Church, operating under the Church’s current status as an informal, fully online religious congregation rather than a separately incorporated company, nonprofit, charity, or association. Privacy requests can be sent through the official contact form or contact@thesatanicchurch.org.
The wiki does not publish a separate registered-office address or entity number because none is claimed under the current unincorporated online status. See the current Church legal & organisational notice. If the operating structure changes, this notice should be updated before the new structure begins processing data for the service.
2. Data processed
Public reading and technical operation
For public pages, the server processes information necessarily sent with an HTTP request. The wiki’s own aggregate telemetry retains the requested path without query parameters, broad bot/human classification, referrer domain only, HTTP status category, and server-side PHP render duration. User-agent strings may be inspected transiently to classify common bots but are not written to analytics storage. Raw IP addresses are not written to the wiki analytics file.
The web server or hosting provider may maintain separate infrastructure logs, which can contain IP addresses and request metadata. Their exact retention depends on the hosting configuration and should be documented by the operator.
Security and abuse prevention
Short-lived rate-limit records may use a one-way hash derived from an IP address to prevent abuse. Authentication uses a first-party secure session cookie. Security challenges can use Cloudflare Turnstile when it is enabled for the deployment.
3. Optional cookies and site statistics
Optional measurement is disabled until the visitor chooses Allow optional cookies. If enabled, the site creates random first-party visitor and session identifiers. The raw identifiers are HttpOnly cookies; only HMAC-derived tokens are persisted in analytics storage.
Because this wiki concerns religion, philosophy, ritual, and belief, browsing behavior can sometimes reveal or suggest particularly sensitive interests. The design therefore avoids storing exact search terms, selected text, form fields, detailed fingerprints, or cross-site profiles. Optional analytics are not combined with Church member profiles.
Behavioral analytics are limited to public reading/discovery pages. Administration, editor, authentication, legal/privacy, API and service paths are excluded so operator activity is not mixed into reader behavior. Acquisition reports use likely-human referrer domains and keep crawler traffic separate.
A browser Global Privacy Control or Do Not Track signal is treated as an analytics refusal by this build.
4. Accounts, authentication and contributions
Contributors authenticate through the connected Church account system. The wiki keeps only the account/session information needed for permissions and contribution features. Successful sign-ins are counted in administration analytics using a one-way HMAC token rather than a raw account identifier.
Edits, article revisions, discussion posts, moderation actions, and attribution information may be retained as part of the public editorial record. Public contributions are intentionally durable so readers can inspect provenance and revision history. Private drafts are stored separately from published content.
The connected Church account provider has its own processing activities and privacy responsibilities. This wiki should not be used to silently enrich member profiles with reading analytics.
5. Purposes and legal bases
| Purpose | Typical basis | Data minimisation |
|---|---|---|
| Deliver pages, authenticate users, prevent abuse and maintain security | Necessary service operation and/or legitimate interests in security and reliability, depending on the processing context | Secure first-party sessions, bounded rate limits, no advertising identifiers |
| Optional behavioral measurement and return-visitor analysis | Consent | First-party only, coarse events and page-type transitions, no search text, 90-day visitor identifier |
| Publish and maintain contributor edits | Operation of the requested contribution service and legitimate interests in an auditable encyclopedia record; other bases may apply depending on the operator relationship | Public attribution and revision data only as needed for the editorial record |
This page is an implementation-oriented privacy notice, not a substitute for jurisdiction-specific legal advice. The operator should review the final legal bases, especially if account eligibility itself reveals religious affiliation or if the hosting/provider setup changes.
6. Retention
- Operational daily analytics aggregates: up to 180 days in the active analytics dataset.
- Consent-based visitor summaries: up to 90 days after last activity.
- Consent-based session summaries: up to 30 days.
- Analytics-choice cookie: up to 180 days.
- Analytics visitor cookie: up to 90 days.
- Analytics session cookie: sliding 30 minutes.
- Signed-in wiki session cookie: session duration.
- Public revisions, contribution attribution, moderation and audit records: retained as part of the editorial/publication record unless deletion is legally required or editorially appropriate.
Aggregate counters that no longer identify or single out a visitor may be retained longer for historical site-performance comparison.
7. Recipients and transfers
The wiki does not send behavioral analytics to Google Analytics, Meta, advertising networks, or data brokers. Data can be processed by the hosting provider (Digi Host), by the connected Church authentication service when signing in, and by Cloudflare Turnstile when that security feature is enabled.
External article-source links are ordinary outbound links. Most wiki assets are served locally. Where an article explicitly uses a trusted Wikimedia Commons cover, the browser may request that image from Wikimedia; Wikimedia can therefore receive ordinary network metadata such as the reader’s IP address and browser user-agent for that image request. The wiki sends no referrer header with those requests and does not use Wikimedia as an analytics or advertising service.
The hosting provider currently identified for this deployment is Digi Host. If any provider processes data outside the EEA, the operator should verify the applicable transfer mechanism and contractual safeguards for the actual production arrangement.
8. Your rights
Depending on the processing and applicable law, you may have rights of access, rectification, erasure, restriction, objection, portability, and withdrawal of consent. Withdrawing optional-cookie consent does not affect processing performed while consent was valid. You can change your optional-cookie choice at any time through .
You may also have the right to complain to your competent supervisory authority. In Belgium, this is the Belgian Data Protection Authority.
9. Changes
Material changes to what is collected, why it is collected, retention periods, or recipients should be reflected here before the changed processing begins. Consent should be requested again where required.