Skip to content

Privacy Policy

Privacy Policy

Last updated: September 6, 2026

1. Who we are

Magen is a Title VI complaint platform operated by the National Jewish Advocacy Center (“NJAC”), a U.S. nonprofit organization (EIN 84-5075213). This Privacy Policy describes how we collect, use, store, and share information when you visit magenreport.org or use any of our services (collectively, the “Service”).

Other legal and advocacy organizations also use Magen to handle their own cases. This Policy uses your Filing Organization for the organization that holds your report and would file your complaint — NJAC if you came to Magen directly, or the partner organization whose intake link you followed — and says “NJAC” only where the operator of the platform is meant.

2. Information you give us

When you report an incident through Magen, you may provide:

  • Identity and contact information — your name, email, phone number, and the institution you attend or attended.
  • Incident details — descriptions of what happened, when and where it occurred, who was involved, and how it affected you.
  • Evidence — documents, screenshots, photos, video, audio, emails, and other files you upload, as well as links to online posts, articles, or web pages you submit as evidence.
  • Demographic information — limited information relevant to a Title VI claim, such as protected-class status, provided voluntarily.
  • Information about co-complainants — if you report together with others, each person provides their own contact and protected-class information and signs their own authorization. We treat each complainant’s information under this Policy.
  • Communications — messages you exchange with lawyers at your Filing Organization and any notes or follow-ups you add to your case.

3. Information we collect automatically

When you use the Service we automatically collect basic technical information, including IP address, browser type, device identifiers, pages visited, and timestamps. We use this information to operate the Service securely, prevent abuse, and improve usability. We do not sell this information.

To protect the Service we use a bot-protection tool (Cloudflare Turnstile), which receives your IP address to verify that report submissions come from a person and not an automated script. We also use error- and performance-monitoring tools (Sentry) to detect and fix technical problems; these tools are configured to strip out the contents of your report and other personal information before recording an error.

4. Cookies and similar technologies

We use a small number of cookies, and we store a small amount of information directly in your browser. All of it is strictly necessary to provide the Service you requested or to keep it secure. We do not use analytics, advertising, or cross-site-tracking cookies.

Cookies

  • Session cookies for guests — when you start a report without an account, we set two first-party cookies that together let you continue past the first step: magen_session (an encrypted, HTTP-only token, expires after 6 hours) and magen_has_session (a marker that records you have an active session, cleared when you close the browser). Both are required to use the report form as a guest.
  • Login session for lawyers and administrators — when a lawyer or administrator signs in, our authentication provider (Auth0) sets an encrypted session cookie so they stay logged in across pages. This cookie is required to use the lawyer dashboard.
  • Bot protection — the bot check on the report form and the status page (Cloudflare Turnstile) sets cookies and stores related data in your browser to confirm that requests come from a real person and not an automated script. Most of this is set by Cloudflare within its own challenge frame rather than by magenreport.org directly. Cloudflare classifies it as strictly necessary for security.

Information stored in your browser

So that you don’t lose your work, the Service also keeps some information in your browser’s local and session storage. This is not a cookie: it stays on your device and is not sent to us automatically with every request.

  • Your in-progress report — as you fill in the report form, your answers (including the incident description and any contact or identity details you have entered) are held in session storage under magen-report so that a refresh or a sign-in redirect doesn’t discard them. Session storage is erased when you close the tab.
  • Your status-check session — if you open your case status from an emailed link, the access token for that session is held in session storage under magen-status-check and is erased when you close the tab.
  • Your guest sign-in details — after you start a report as a guest, your account identifier and the email address you entered are saved in local storage under magen-auth so the form knows who you are as you move between steps. Unlike the two items above, local storage is not cleared when you close the browser — it stays until you or your browser removes it. If you are using a shared or public computer, clear your browsing data when you are finished.

Because everything described in this section is strictly necessary, we do not show a cookie consent banner. If you block these cookies or clear this information mid-report, the corresponding part of the Service — submitting a report, signing in, passing the bot check, or restoring answers you haven’t submitted yet — will not work.

You can remove all of it at any time through your browser’s privacy or “clear browsing data” settings. Doing so signs you out and discards any unsubmitted answers held on your device. Anything you have already submitted stays in your case file and is governed by Section 9 (Data retention).

5. How we use your information

We use the information you provide to:

  • Generate a draft Title VI complaint using AI based on the information you submit.
  • Analyze your report against the IHRA Working Definition of Antisemitism (opens in a new tab) and run automated quality checks to help our lawyers assess your case.
  • Allow lawyers at your Filing Organization to review, edit, and (with your consent) file your complaint with the Office for Civil Rights or another appropriate federal or state agency.
  • Send you transactional notifications about your case (status updates, lawyer messages, filing confirmations).
  • Maintain records required for legal, compliance, or regulatory purposes.
  • Improve the Service, debug issues, and prevent fraud or abuse.
  • Generate aggregated, de-identified statistics about antisemitism on U.S. campuses. We never publish information that could identify you without your explicit consent.

6. Who we share information with

Your report is confidential. We share information only with:

  • Lawyers and authorized staff at your Filing Organization who review and prepare your complaint. Lawyers at another organization on the platform cannot open your report unless your Filing Organization gives them access, which the next two bullets describe.
  • NJAC as the operator of the platform — a small number of NJAC administrators can reach any report, including one held by another organization, in order to run, support, and secure the Service. That access is recorded in an audit log. It is separate from NJAC’s role as a Filing Organization: it does not make NJAC part of your case, and NJAC lawyers do not work a case another organization holds.
  • Another organization joining your case — your Filing Organization may share the information in your report — including your identity, incident details, and the evidence and links you submit — with another legal or advocacy organization only where a lawyer determines that organization should act as a co-filer on your complaint, or that your complaint should be filed jointly with others against the same institution. Your authorization to file extends to an organization brought onto your case in one of those two ways.
  • Other legal and advocacy organizations working the same school — separately from the above, your Filing Organization chooses how much of its cases those organizations can see. Most share only an anonymized one-sentence summary that does not identify you, and an organization that wants more must ask, as described above. An organization may instead choose to make its cases readable in full to those organizations’ lawyers, which includes your name and contact details — keeping your name out of the complaint does not change that, because it is a choice about the complaint and the documents filed with it, not about which lawyers may read the case. Ask your Filing Organization which it does.
  • The Office for Civil Rights or other government agencies, but only after you have signed a consent form authorizing us to file on your behalf. When we file, we transmit the complaint, the evidence and links supporting it, your signed authorization, and the identity and incident information needed to process the complaint.
  • Service providers who help us operate the Service under contractual confidentiality and security obligations — including cloud hosting and storage (Amazon Web Services), authentication (Auth0), bot protection (Cloudflare), email delivery (Resend), AI processing (large language models from providers such as Anthropic and OpenAI, accessed through OpenRouter), AI observability (Langfuse), and error monitoring (Sentry).
  • A public web archive — when you submit a link as evidence, we may ask the Internet Archive’s Wayback Machine to capture that page so there is a reliable record before the content can be changed or deleted. Captured pages are stored by the Internet Archive and may be publicly accessible there. We send only the link you provide — not your name or contact information.
  • Law enforcement or courts, when required by valid legal process or to protect the rights, safety, or property of users, NJAC, or the public.

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

7. AI processing

Magen uses large language models to ask follow-up questions, classify incidents against the IHRA Working Definition of Antisemitism (opens in a new tab), run automated checks, and draft Title VI complaints from the information you provide. These models are accessed through OpenRouter, which routes requests to AI providers such as Anthropic and OpenAI. Inputs are processed under contractual terms that prohibit using your data to train their models. AI-generated content is always reviewed by a lawyer at your Filing Organization before any complaint is filed.

8. Group reports and reports filed on your behalf

Magen supports two situations beyond a single person filing their own report:

  • Group reports — several people who experienced related conduct can be named together on one complaint. Each complainant provides their own contact and protected-class information, signs their own authorization, and is notified about the case.
  • Reports prepared on your behalf — if you speak with a lawyer by phone or in person, the lawyer may create a draft report from your intake conversation. We email you a secure, time-limited link so you can review and correct the draft and sign your authorization. Nothing is filed until you have authorized it.

9. Data retention

We retain case information for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. Once a complaint is filed, evidence files are subject to a legal hold and may not be deletable. You may withdraw an unfiled report at any time from the report status page; withdrawal permanently deletes it (see Section 10).

If you start a report and never submit it, we keep it for as long as you can still open it, and no longer. An unsubmitted report stays available for 30 days after you last worked on it — or 90 days if you chose “Save and finish later” — and is then permanently deleted, along with your contact details and anything you uploaded to it. You can pick up an unfinished report from the status page at any point in that window. Nothing you submitted is affected; this applies only to reports that were never sent to us.

10. Withdrawal and research retention

You can withdraw an unfiled report at any time from the report status page. When you withdraw:

  • We permanently delete the report — your name, contact details, electronic signature, every narrative, and every file you uploaded — from our systems. This cannot be undone.
  • We keep only a minimal, non-identifying record that a report existed and was withdrawn on a given date — no name, no contact details, no narrative — so our data-retention stays auditable. It cannot be used to identify you.
  • If any evidence you submitted was already filed with OCR (for example, as part of a combined complaint), we retain limited audit records of that filing — which can include original file names — so the filing stays auditable, even after you withdraw.
  • If you are one of several complainants on a group report, we delete your report; the combined complaint continues for the remaining complainants, regenerated as if you had never been included.
  • Reports already filed with the Office for Civil Rights cannot be withdrawn through this page; contact us to request administrative withdrawal at OCR.
  • AI processing logs: when our system drafts or reviews complaint text, the content is processed by an AI-observability service. Those processing logs are automatically deleted after 30 days, on a rolling basis, independent of whether a report is withdrawn.
  • Records that already left our systems in the course of handling your report — such as email delivery logs held by our email provider, and public web archives of links you submitted (which were already public) — are outside what deletion here can reach.

11. Security

We use industry-standard administrative, technical, and physical safeguards to protect your information, including encryption in transit and at rest, access controls, audit logging, malware scanning of uploaded files, and immutable storage of filed evidence. No system is perfectly secure, however, and we cannot guarantee absolute security.

12. Your choices

You may:

  • Access and update information in your account.
  • Withdraw an unfiled report at any time — see Section 10 for what we keep and what we erase.
  • Request a copy of the personal information we hold about you.
  • Request correction or deletion of inaccurate or unnecessary personal information, subject to our legal obligations.
  • Opt out of non-essential email communications by following the unsubscribe link in any message.

13. Children’s privacy

Magen is not intended for children under 13. If you are between 13 and 18, please review this policy with a parent or guardian before submitting a report.

14. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, if the changes are material, notify you by email or through the Service.

15. Contact us

Questions about this Privacy Policy or our handling of your information? Email us at njac@njaclaw.org.