Privacy Policy
Effective 2026-05-16. This Privacy Policy explains what information The 250 collects, how it is used, who it is shared with, and the choices you have.
Who we are
The 250 (the "Site") is operated by LSG, a public-affairs and strategic-communications firm based in Washington, D.C. References to "we," "us," and "our" mean LSG.
If you have questions about this policy or wish to exercise any right described below, contact us at privacy@teamlsg.com.
Information we collect
We collect the minimum information needed to operate the Site:
- Account information — if you are invited as an editor, we store your email address, display name, role (storyteller or admin), the storyteller record you are linked to (if any), and the timestamp of your last sign-in. We do not store passwords; authentication uses single-use magic links delivered by email.
- Editorial activity — every change you make through the editor is recorded in an audit log (who, when, what changed, before/after diff). The log is append-only.
- Storyteller content — names, locations, biographies, phrases, photographs, video clips, and posts that storytellers (or their authorized editor) choose to publish on the Site. Publication implies consent to display.
- Server logs — IP address, user-agent, request path, status code, and timestamp. Used to operate the Site, debug, and detect abuse.
- Analytics — if you accept the analytics cookie, we receive aggregate, pseudonymous metrics (page views, performance, geographic region at country level) via Vercel Analytics and Vercel Speed Insights.
We do not collect: precise geolocation, payment data, social-graph information, contents of other sites you visit, or sensitive special-category data (health, biometrics, sexual orientation, religious belief, etc.) unless a storyteller affirmatively chooses to disclose such information as part of their own story.
How we use information
- To run the Site, including authentication, publishing, and audit history.
- To detect and respond to abuse, errors, or security incidents.
- To improve the Site through aggregate, pseudonymous analytics — only with your prior consent (analytics cookie).
- To respond to your requests for access, correction, deletion, or export.
- To comply with law and to enforce the Terms of Use.
We do not sell or rent personal information. We do not use personal information for behavioral advertising, profiling, or automated decision-making with legal effect on you.
Cookies
A cookie is a small file your browser stores when you visit the Site. We use two categories:
- Essential cookies, set without consent because the Site does not function without them:
authjs.session-token— your sign-in session, if you are an editor. HttpOnly, Secure (in production), SameSite=Lax, 30-day rolling.td-consent— your cookie preference (accepted / rejected). 365-day expiry. SameSite=Lax.- CSRF and routing cookies set transiently during sign-in.
- Analytics cookies, set only after you click "Accept all" on the consent banner:
- Vercel Analytics — pseudonymous page-view counts.
- Vercel Speed Insights — pseudonymous Core Web Vitals (LCP, INP, CLS).
Selecting "Reject non-essential" sets td-consent=rejected and prevents the analytics scripts from loading on subsequent navigations. You can change your choice at any time by clearing the td-consent cookie in your browser.
Service providers (subprocessors)
The Site relies on the following third parties to operate. Each handles only the data described and is bound by its own privacy commitments:
- Vercel, Inc. — hosting, CDN, analytics, speed insights.
- Neon, Inc. (planned for production) — managed Postgres for site data.
- Twilio SendGrid, Inc. — transactional email (magic-link sign-in messages).
- Mux, Inc. (when video upload is enabled) — adaptive video streaming.
- GitHub, Inc. — source control for site code (no personal data of visitors).
Where data is stored
Site data is stored in the United States. If you access the Site from outside the U.S., your information will be transferred to and processed in the U.S. and other jurisdictions in which our service providers operate.
Retention
- Sessions: deleted at sign-out or after 30 days of inactivity.
- Verification tokens (magic links): deleted on use, or after 24 hours, whichever comes first.
- Audit log: retained for the life of the project (append-only).
- Server logs: 30 days.
- Storyteller content: retained while published. On request from the storyteller (or, if deceased, their estate), we will remove their record and all linked posts within 30 days.
Your rights
Depending on where you live, you may have the right to:
- Access — receive a copy of the information we hold about you.
- Correction — correct inaccurate information.
- Deletion — request removal of your information.
- Export — receive a portable copy of your information.
- Withdraw consent — opt out of analytics at any time.
- Lodge a complaint with a data-protection authority in your jurisdiction.
To exercise any of these, email privacy@teamlsg.com. We respond within 30 days.
California residents (CCPA / CPRA)
We do not "sell" or "share" personal information for cross-context behavioral advertising. California residents have the rights to know, delete, correct, and non-discrimination described above. Contact privacy@teamlsg.com to exercise them.
European Economic Area & United Kingdom (GDPR / UK GDPR)
Our lawful bases are: legitimate interest (running and securing the Site), consent (analytics cookies), and contract (for invited editors). The data controller is LSG. We do not have an EU representative; the operator may be contacted directly at the email above.
Children
The Site is intended for adults. We do not knowingly collect personal information from children under 16. If we learn we have done so, we will delete it promptly.
Security
The Site uses HTTPS for all traffic, HSTS for browser pinning, strict transport headers (X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy), and parameterized database queries. We log authentication attempts and audit every editor action. No system is perfectly secure; if you believe your information has been compromised, contact privacy@teamlsg.com.
Changes to this policy
We may update this policy as the Site evolves. Material changes will be announced on the Site at least 14 days before they take effect. The "Effective" date at the top reflects the most recent revision.
Contact
LSG
Washington, District of Columbia, USA
privacy@teamlsg.com


