PRIVACY

What this site knows about you

No cookies, no third-party scripts, no ad network, no cross-site tracking. This page states exactly what happens when you load a page here — including the parts that do leave your browser — and how to verify each claim yourself.

Analytics

Page views are counted with Cloudflare Web Analytics. The measurement script is not loaded from Cloudflare: it is downloaded at build time and served from this domain as /scripts/cf-beacon.js. Rendering a page therefore requires no request to any third-party host.

What the script does send is an aggregate page-view event to Cloudflare's analytics endpoint. It sets no cookie, assigns no identifier and builds no profile, so there is nothing that could follow you to another site.

The beacon is wrapped in a guard that disables it on localhost, and it is only injected into production builds. Development and preview runs never report anything.

These numbers exist to tell me which articles are worth keeping up to date. That is their only use.

Cookies

This site sets no cookies at all — not for analytics, not for preferences, not for consent to cookies that do not exist. No response from this domain carries a Set-Cookie header.

Your theme choice (dark or light) is stored in localStorage, on your own device. It is never transmitted and never leaves the browser.

Third-party requests

Fonts, images, stylesheets and scripts are all served from this domain. There are no CDN script tags, no embedded widgets, no social buttons and no externally hosted web fonts on any page.

A Content Security Policy enforces this from the server side rather than relying on discipline: scripts and styles are accepted only from this origin, and only with a per-request nonce.

Server logs

The web server keeps ordinary access logs: timestamp, requested path, response status, user agent and IP address. This site runs an active tarpit and blocklist stack, which cannot work without knowing who is knocking.

Those logs are operational and security data. They are not joined with analytics, not used to build reader profiles and not shared with anyone.

The tools

The interactive tools run in your browser. Hashes, passwords, regular expressions, subnets, certificates you paste in — the computation happens on your machine, and the input is never uploaded.

Two tools are deliberate, visible exceptions, because they cannot work otherwise. The certificate inspector queries public Certificate Transparency logs (Cert Spotter and crt.sh) for the hostname you type. The HTTP header analyzer sends the URL you submit to a small proxy on this same domain, because a browser is not allowed to read another site's response headers.

In both cases the request carries only what you typed, and only when you press the button. Nothing you enter into a tool is stored or associated with you.

No ads, no affiliates

There is no advertising, no affiliate link, no sponsored content and no mailing list here. Nothing on this site is monetized, so there is no incentive to collect anything about you.

Verify it yourself

Open your browser's network panel on any page and read the request list: every entry is same-origin. Open the storage panel: there is no cookie to delete. The source of this site is public, including the build step that downloads the analytics script and the configuration that generates the security headers.

Contact

For anything privacy-related, write to me directly. Security reports have their own channel, with a PGP key and disclosure policy.