We cannot hand over what we never stored
Spegeln scrutinises powerholders, not users. User-side data collection is deliberately too thin to become a tool of abuse.
No IP address in the database
The application never writes an IP address to the database. Providers' short-lived security logs are minimised as far as technically possible and are never used to identify a contribution.
Votes without identity
To prevent duplicate votes, an irreversible hash of a local device proof is stored. Raw device data is never stored, and the hash cannot be reversed into a person or device.
An account without a person
An account can be a random secret token with no email, name or phone number. You may instead choose or later link an email address or username; only details you deliberately provide for login, recovery or authority replies are retained. They are never displayed publicly.
Anonymous tips
A tip retains its case token and the normal operational minimum. The contribution stores the terms version and time, without a person or device ID. The token opens an encrypted dialogue for follow-up questions without revealing who you are.
What you control
You choose whether a contribution uses your pseudonym or is fully anonymous. You choose whether metadata accompanies uploaded media. You choose whether a delivered authority case becomes public.