Skip to content

We are still building this site. We are adding more listings and features.

Privacy policy

No ad-tech, no tracking pixels, no user accounts — just an honest account of what data this directory handles, and why.

Who we are

directory.lgbt is an independent, UK-wide directory of LGBTQIA+ groups, services and spaces. It's currently run by one person (Pete), who is the "data controller" for the personal data described on this page — the person legally responsible for deciding how and why it's used. Our ICO (Information Commissioner's Office) registration reference will be added here once registration is complete. You can contact us about anything on this page at [email protected].

What data this directory publishes

The core of this site is a directory of organisations, not individuals: names, descriptions, services offered, categories, locations and contact details for LGBTQIA+ groups, charities and services across the UK. This information comes from public registers (the Charity Commission for England & Wales, the Scottish Charity Regulator OSCR, the Charity Commission for Northern Ireland, and Companies House), from organisations' own websites, and occasionally from Google Places. An organisation's own name, mission and services aren't personal data under data protection law — they describe an organisation, not an identifiable individual — but where a listing includes a named individual's own contact details (for example, a charity's registered complaints contact), that detail is personal data, and this policy applies to it.

Special category data — how we handle it

Because this directory is about LGBTQIA+ organisations, some of what we publish sits close to "special category data" under Article 9 of UK GDPR — information that could reveal someone's sexual orientation or gender identity. An organisation's own published mission and services aren't personal data about a specific person, so Article 9 doesn't apply there. It does apply, narrowly, where a specific named individual's own sexual orientation or gender identity is disclosed alongside their name — for example, in a free-text report or a register filing. Our policy is that content like that should not be published without redacting the individual's identity or attribute — this is a discipline our reviewers apply, not an automated filter, so please also see "If you're named in an organisation's listing" below for how to flag anything we've missed.

Why we're allowed to process this data (our lawful basis)

For publishing organisation and listing data, our lawful basis under UK GDPR Article 6 is "legitimate interests": running a public-interest directory that helps people find genuinely LGBTQIA+ services, republishing information the organisations themselves already make public (their own charity filings, their own websites), with a straightforward way for an organisation to ask us to correct or remove a listing if they object. For handling a report or a suggested correction you send us, our lawful basis is the same — legitimate interests in keeping the directory accurate and dealing with problems people flag.

If you just use the site

Searching the directory doesn't create an account and isn't logged against your identity. If you tap "Use my location", your device's location is rounded to about a kilometre before it's used for that one search — that rounding happens on your device, before anything is sent anywhere, and the location is never stored. If you type a postcode instead, we only ever send the first part of it (the outward code, like "SW9") to our own server by default — that's deliberately what we cache, so a full postcode is never stored. You can choose to search with your exact postcode for a more precise result; that's an explicit choice you make, never the default. Our own server turns whichever you send into an approximate location using postcodes.io, a free government-open-data-backed lookup service, so postcodes.io never sees your personal IP address either way. If you use the map view, map tiles are requested directly by your browser from Protomaps, a third party — unlike the postcode lookup above, that request isn't proxied through our server, so Protomaps can see your IP address and the map area you're viewing, the same way any map tile provider works. Forms on this site — like reporting a problem — use Cloudflare Turnstile to screen out automated abuse, which means your IP address is sent to Cloudflare as part of that check. The only cookie this site sets is a simple, non-tracking preference for light/dark theme — see our short Cookies page for the detail. We use Plausible, a privacy-friendly analytics service run from the EU that doesn't use cookies and doesn't build a profile of you across visits. It counts page views, and when you search it records only a general region or radius band and a rough range for how many results came back — the words you actually typed are never sent to Plausible at all, so there's nothing search-text-shaped for a third party to hold, however long its retention period runs. Visits to our Need help now page (/help-now) are never sent to Plausible at all — we filter those out on our own server before they'd ever reach it, so nothing about that visit is recorded by Plausible or kept anywhere in our own logs.

If you report a problem or suggest an edit

If you use the "Report a problem" or "Suggest an edit" link on a listing, we collect what you type — an optional email address (only if you'd like a reply), a reason, and any free-text description or suggested correction. Your email address is stored in its own field and is never sent to any AI system, however you reach us. The words you write in the free-text box are read by two AI systems — Anthropic's Claude and Google's Gemini — that help us judge how urgent a report is; a person reviews every report regardless of what those systems suggest. Please don't put your own name or other contact details in the free-text box itself — we can't reliably strip personal details out of free text, so anything typed there could in principle be read by those AI systems. Use the dedicated email field instead if you'd like us to be able to reply to you directly.

If you're named in an organisation's listing

An organisation's published contact details can sometimes be a named individual's own — a small, unincorporated LGBTQIA+ group's "organisation" phone number or address is often genuinely someone's personal mobile or home address. We treat that as personal data, and we take a broader view of when it counts as special category data than a typical business listing would need to: associating a named person's contact detail with, say, a trans youth group or an HIV support service can itself reveal something about sexual orientation, gender identity or health. We deliberately do not collect or publish the names of trustees, officers or directors, even on registers (like Companies House) that would let us. If a personal contact detail in a listing is yours and you'd like it removed, replaced with an organisational one, or corrected, email [email protected] or use the "Suggest an edit" link on the listing — we'll action it quickly.

If you run a listed organisation

If you run an organisation listed here and want to correct, update or remove your entry, that's not a data protection request (an organisation isn't a "data subject" under GDPR) — it's a straightforward listing change, and we'll action it quickly. Use the "Suggest an edit" link on your listing, or email [email protected].

Who else sees this data

Running the site: Railway hosts the website and its database infrastructure; Supabase is our database and enforces who can see what; Meilisearch (which we run ourselves on Railway) powers on-site search using only already-published listing data; Cloudflare sits in front of the site for security and performance, and screens public forms for automated abuse (see "If you just use the site" above for what that means for your IP address); Plausible (EU-based) provides the cookieless analytics described above. Sentry helps us notice when something breaks in our internal admin tools specifically — it is not wired up on the public site you're using now. Sourcing and checking organisation data (admin side, never visible to the public): the Charity Commission, OSCR, Companies House, CharityBase, Google Places, Firecrawl and Ideal Postcodes. AI services: we use Google's Vertex AI (Gemini) and Anthropic's Claude to help categorise new organisations, check whether they belong in the directory, and — as described above — help score how urgent a report is; organisation names, descriptions and, for reports, your free-text description can be sent to either. Some listing descriptions are also written by these same automated tools and checked against the source material they were written from — a listing that has one says so on its own page. We also use Perplexity to help research and corroborate organisation details, and Serper to run the search queries that research needs. We've evaluated OpenAI's models during development, but OpenAI is not part of the live pipeline — no visitor or organisation data reaches it today. A real share of our automated checks run on Ollama, open-source AI models hosted on our own hardware, which sends nothing to any third party at all.

Do AI vendors train on our data?

We don't train AI models on anything here — not ours, and not the vendors'. Every AI service we use is an enterprise API whose terms prohibit training on our data: Google Vertex AI, Anthropic's Claude API and Perplexity's API all contractually commit to this, and a good share of our classification runs on models hosted on our own hardware that send nothing anywhere. Vendors do hold data briefly for abuse monitoring — typically up to 30 days — before deleting it.

How long we keep data

Published listing data is kept for as long as the organisation is listed, since that's the whole point of the directory; if an organisation closes or asks to be removed, we take it down. Behind the scenes, our policy is to keep records of changes and admin activity (our audit trail) for up to 24 months, ingestion run logs for up to 6 months, and reports or suggested edits you send us for up to 18 months. We don't send the words you type into search to Plausible at all (see "If you just use the site" above), so there's no separate third-party retention question for it. The general region/radius band and result-count range we do record with Plausible are ordinary analytics data, kept for as long as our Plausible plan's standard retention period runs (currently several years) — the same as our page views — and we can delete it all in one go, for that data specifically or for the whole site, at any time. We're building automatic clean-up to enforce the other limits above; no data has yet reached its retention window, but you can ask us to erase yours sooner at any time regardless (see "Your rights"). Backups of the whole database are kept for up to 30 days before being automatically overwritten.

Your rights

Under UK GDPR you can ask us to: confirm what personal data we hold about you and get a copy of it (a "subject access request"); correct it if it's wrong; ask us to erase it; and object to how we're using it. Because this site has no user accounts, most of these rights concern things like a report you sent us, or a personal contact detail (not an organisation's general listing) that appears somewhere in the directory. To make any of these requests, email [email protected] — we aim to respond within one month, as UK GDPR requires. You also have the right to complain to the Information Commissioner's Office (ico.org.uk) if you think we've got something wrong.

Changes to this policy

We'll update this page whenever what we do with data changes materially — for example, if we add analytics, a new external service, or user accounts. We don't expect to make changes without saying so here first.