Privacy Policy

Last Updated: 2026-08-13

Introduction

Welcome to Everything PHP. We are an independent, unofficial platform designed to aggregate, organise, and present public data related to the PHP programming language. The official records of PHP governance are hosted by the PHP project itself; our goal is to provide developers with a modernised, consistent, and highly accurate interface for exploring those existing public records.

For the purposes of applicable data protection laws, Echelith Ltd is the Data Controller of the information processed on this site.

Because our platform functions by mapping the relationships between governance decisions, code changes, and community discussions, we process certain personal data - specifically, identifiers tied to public open-source contributions and governance.

The Data We Process

Data from Public Sources

In the course of aggregating public PHP governance data, we process the following publicly available information:

  • Identifiers: Usernames, handles, and names used on official PHP platforms, mailing lists, and GitHub.

  • Communications: The contents of emails and posts submitted to official, public PHP newsgroups and mailing lists.

  • Governance Records: Voting records on PHP RFCs and issue tracker activity.

  • Metadata: Timestamps, message IDs, and links back to the original official sources.

A Note on Sensitive Data: We do not intentionally seek out or categorize sensitive personal data (such as health information, political opinions, or religious views). However, because we index open-text communications from mailing lists, such data may inadvertently be processed if you voluntarily and manifestly made it public in the original upstream sources.

Website Visitor Data and Analytics

When you browse Everything PHP, we automatically process technical data to keep the site secure and functional. If you provide consent, we also process analytics data to understand site usage:

Technical Logs: Your IP address, browser type, operating system, and the timestamps of your page requests.

Analytics Data: Page views, navigation paths, and interaction metrics gathered via Google Analytics.

If you choose to create an account on Everything PHP, we process the email address, username, and authentication details you provide. We process this data on the basis of Contract (Article 6 (1)(b) GDPR) to provide you with personalised site features and secure your account.

How We Collect Data

We do not collect this governance data directly from you. All personal data processed by Everything PHP is ingested, scraped, or aggregated automatically from existing, permanent public records, including:

  • Official PHP newsgroups and mailing lists.
  • The official PHP RFC wiki.
  • The PHP organisation on GitHub.
  • The official PHP bug tracker.
  • Identifiers belonging to community sources such as RSS feeds and events.

Notification Exemption: Because we aggregate thousands of records from public historical archives rather than collecting this data directly from you, notifying every individual PHP contributor directly about this processing would involve disproportionate effort (under Article 14 (5)(b) of the UK/EU GDPR). We provide this privacy policy to fulfill our transparency obligations and ensure you understand how your publicly sourced data is handled.

Automated Server Logs & Analytics

We collect visitor IP addresses via automated infrastructure logs, and usage metrics via Google Analytics.

Legal Basis for Processing

Under data protection laws, we process this data on the basis of Legitimate Interest (Article 6 (1)(f) of the UK/EU GDPR).

As an independent interface, our legitimate interests are:

Tool Utility and Accuracy: Providing developers with a consistent, unfragmented, and accurate reflection of official PHP project activities.

Contextual Integrity: In technical discussions and governance, the identity of the author (e.g., who is replying to whom, and who is voting on an RFC) is the functional context. Redacting identifiers breaks the mapping of these relationships and fundamentally degrades the utility of the tool.

Accessibility: Making permanent, publicly available open-source data easier to navigate, search, and understand without altering the factual reality of those public records.

This data was originally published by the authors with the knowledge that it would become part of a permanent, public open-source record. We do not expose any private data; we simply provide a better lens through which to view public data. Therefore, we believe our legitimate interests are not overridden by your fundamental rights and freedoms, given that this data is already deliberately public.

Legal Basis for Website Visitors and Analytics

For standard website visitors, we rely on the following legal basis:

Server Security and IP Logging (Legitimate Interest): We process automated technical logs (such as IP addresses) under Legitimate Interest to ensure network security and prevent abuse.

Website Analytics: We deploy full analytics cookies based on your Consent. If you decline cookies, we process anonymous "cookieless" pings under Legitimate Interest to monitor aggregate site traffic.

Data Retention and Security

Because Everything PHP acts as a historical archive and governance transparency tool, we retain aggregated public data for the lifetime of the Everything PHP project under the historical archiving exemptions of the GDPR, to preserve the context of PHP project discussions and voting history.

Visitor Data Retention: Standard web server logs containing IP addresses are automatically deleted after 30 days. Analytics data is retained for a maximum of 14 months.

We implement standard, reasonable technical measures to secure our servers and protect this data against unauthorized tampering or access.

Your Data Rights and Removal Requests

Depending on your location, you have rights regarding your personal data. These include the right to access, correct, or request the deletion (Right to Erasure) of your data. You also have the Right to Object to our processing, the Right to Restrict Processing, and the Right to Data Portability.

Upstream Data and php.net Please note that Everything PHP is an independent interface that mirrors data hosted by the official PHP project. We do not author or originate this data. If you wish to remove your data from the public domain entirely, you must direct your removal request to the official PHP project. If your data is redacted or removed from the official upstream sources (such as php.net or official mailing lists), our systems will reflect those changes upon our next automated synchronization, although due to optimizations some removals may require manual intervention.

How we handle direct removal and objection requests:

If you wish to object to your data being displayed specifically on Everything PHP while leaving it on the official sources, please contact us at privacy@echelith.com.

Identity Verification: To protect the integrity of the archive, we may require you to temporarily verify ownership of the associated email address or GitHub handle before we process a modification or removal request.

Balancing Requests with Historical Integrity: Because Everything PHP maps intricate relationships between mailing list threads, RFC votes, and GitHub commits, redacting specific usernames or removing posts often orphans data, breaks technical context, and misrepresents the factual reality of the public record. In some cases, such as when removal would severely distort the historical accuracy of a public vote or technical discussion, we may rely on archiving exemptions to preserve the record. If we cannot fulfill your request, we will always explain exactly why and outline the legal basis for our decision.

Right to Lodge a Complaint

If you believe our processing of your personal data violates data protection laws, you have the right to lodge a complaint with a supervisory authority responsible for data protection in your country of residence (for example, the Information Commissioner's Office in the UK).

Data Sharing and Third-Party Processors

We do not sell, rent, or monetise your personal data. However, to securely host and operate Everything PHP, we share necessary data with trusted third-party service providers (Data Processors) who provide essential infrastructure. These providers only process data in accordance with our instructions and strict data processing agreements.

Our core infrastructure providers include:

Cloud Hosting Providers: We use secure cloud infrastructure (such as AWS or Google Cloud) to host our application, database, and background synchronisation services.

Content Delivery Networks (CDN): We use CDNs (such as Cloudflare) to securely route traffic, cache public pages, and protect the site against malicious traffic.

International Data Transfers

Because our infrastructure providers operate globally, the data we process—including site visitor logs and public PHP governance data—may be routed through or stored on servers outside of the UK and the European Economic Area (EEA), such as in the United States.

To ensure these automated infrastructure transfers are legal under UK and EU data protection laws, we rely on the standard Data Processing Agreements provided by our infrastructure partners. Our providers legally commit to protecting European and UK data by incorporating recognised transfer mechanisms, such as Standard Contractual Clauses (SCCs) and the UK/EU Data Privacy Framework, into their standard terms of service.

Cookies and Google Analytics

We use cookies to ensure the basic functionality of the site and, with your permission, to analyse our traffic.

Essential Cookies: These are strictly necessary for the site to function securely (such as Cloudflare network routing cookies or cookies that save your privacy preferences). They do not track your behaviour and do not require consent.

Login Cookies: These manage a user account and security. Actions you take on the site will be associated with your user account.

Analytics and Consent Mode: We use Google Analytics 4 to measure how users interact with our site. We have implemented Google Consent Mode to respect your privacy choices:

If you accept cookies: Google Analytics will place first-party cookies on your device to measure user journeys and site interactions over time.

If you decline cookies: No analytics cookies will be placed on your device. Instead, we use "cookieless" tracking, which sends anonymous, temporary data pings to our servers. These pings do not contain unique identifiers or IP addresses, meaning your visit is recorded in our aggregate traffic totals, but you cannot be individually tracked or identified.

Childrens Privacy

This platform is intended for professional developers and adults. We do not knowingly collect or solicit data from anyone under the age of 13 (or 16 in certain EU jurisdictions).

Changes To This Policy

We may update this Privacy Policy from time to time to reflect changes in our technology, data practices, or legal requirements.

Minor Changes: For minor tweaks (such as fixing typos or clarifying existing practices), we will simply update the "Last Updated" date at the top of this page.

Material Changes: If we make significant changes to how we process your personal data (for example, changing our legal bases for processing), we will provide a more prominent notice on Everything PHP or notify registered users directly via email before the changes take effect.

We encourage you to review this policy periodically to stay informed about how we are protecting your data.

Contact Us

If you have any questions about this policy, or if you wish to exercise your data rights, please contact the site maintainer (the Data Controller) at:

Email: privacy@echelith.com

Address: Echelith Ltd, 128 City Road, London EC1V 2NX