Privacy
How FightCardIQ handles analytics, videos, accounts, comments, moderation, and rights requests.
Last updated: 12 July 2026. Comments are live where comments.enabled is true. This notice covers the comments feature's data lifecycle, including sign-in, moderation, privacy, account export, and account deletion controls.
Who runs this site
FightCardIQ is an independent, fan-made MMA editorial site. For privacy, account, export, deletion, or removal requests, use the contact path published on the site or email the operator at [email protected]. We act as the controller for data we collect directly through the site.
Our legal bases are: legitimate interests for site operation, security, abuse prevention, moderation, and privacy-preserving analytics; contract or account-service necessity for signed-in comments, sessions, exports, and deletion requests; consent or your deliberate action where you choose to sign in with Google or activate an embedded YouTube video or X post; and legal obligation where we must preserve, disclose, or remove information to comply with law.
Analytics and embedded media
Signed-out reading is cookieless. We use Umami Cloud for aggregate analytics with Do Not Track enabled, including page views, approximate country, referrer, browser/device class, and a small number of video/open events. We do not use analytics cookies, ad tracking, profiling, or cross-site identifiers.
YouTube embeds use the privacy-enhanced youtube-nocookie.com host where possible and do not load a player until you choose to play a video. Once you play or open a YouTube video, Google/YouTube may process data under its own privacy terms.
X posts stay static until you choose to open an inline photo or video. On activation, we load X's official post widget with Do Not Track requested; X may still process data under its own privacy terms. If X cannot load the post, we show the captured text and a link to the original post instead.
Comments accounts
If you sign in to comment, authentication uses Google Sign-In. We store the Google account subject identifier (google_sub), account metadata needed to operate the account, a generated public display name, session records, comments, votes, reports you file, and moderation/audit targets linked to comments or accounts. We do not publish your email address.
Comments/auth uses strictly necessary cookies only: __Host-session for the signed-in session and __Host-gnonce for sign-in nonce protection. Signed-out visitors do not receive comments cookies from FightCardIQ.
What becomes public
Your generated display name and any comments you post are public. Other account metadata, reports, votes, moderation notes, sessions, and security logs are not public except where disclosure is required to handle abuse, legal requests, or site security.
Abuse prevention and moderation
We may use Cloudflare Turnstile, Google Sign-In signals, IP hash checks, nonce checks, and rate limits to prevent spam, abuse, credential misuse, and automated attacks. IP addresses are transformed with an IP_HASH_SALT; salt rotation limits long-term linkability. Rate-limit/security logs are kept for 2 days unless needed for an active abuse investigation.
Reports and moderation actions may include filing age, reporter account id, reported comment id, target account id, status, moderator notes, and audit timestamps. Report filing-age retention may be longer than the public comment so repeat-abuse handling and safety decisions remain accountable.
Retention
Comments remain public until removed by the author, by moderation, or as required by law. Deleted comments may be replaced with a removal marker where needed to preserve thread context. Session and nonce data expire with the session/security window. Rate-limit/security logs are retained for 2 days. Resolved or closed reports are deleted after 180 days from filing age / created_at. Separate moderation audit events and account-safety records may be retained for up to 365 days to handle repeat abuse, disputes, and accountability.
Cloudflare D1 backup/time-travel residual copies may persist for up to about 30 days after deletion before aging out of backup systems.
Your choices and rights
You may request export, correction, deletion, or removal of account/comment data through the contact path above. Where UK GDPR or EU GDPR applies, you may also object to processing, restrict processing, request portability, and lodge a complaint with your local supervisory authority. In the UK, that supervisory authority is the Information Commissioner's Office; in the EU, it is the relevant data protection authority for your member state.
Processors
Processors and external services may include Cloudflare for hosting, D1 storage, security, logs, and Turnstile; Google for Google Sign-In and YouTube embeds; X for visitor-activated post embeds; and Umami Cloud for privacy-preserving analytics. These services may involve cross-border or international transfers, including processing in the United States. Where applicable, we rely on processor terms, safeguards, and transfer mechanisms offered by those providers.