Privacy

Privacy should be understandable.

What this website collects, why it collects it, and how long it is kept.

Last updated 4 September 2026

The short version

This site measures its own traffic, on our own servers, into our own database. There is no Google Analytics here, no advertising trackers, no embedded social media, and nothing on any page that reports to a company other than us. Nothing you submit is sold, rented, or shared with third parties for marketing.

We do that because the alternative is handing a record of your visit to somebody else in exchange for a chart. If you would rather we measured you less precisely, there is a button further down, and it works.

Website measurement

If you just read pages: our web server records the request — the time, the page, the response code, how long the server took to answer, your IP address, your browser's user-agent string, the referring page if your browser sent one, and any campaign tag on the link you followed. That is taken by the server itself, which is why it works whether or not you run JavaScript, and why it also sees the search engine crawlers and AI bots that never run any.

A small script measures what the server cannot. How quickly the page became usable, how long it was actually in front of you rather than sitting in a background tab, how far down you read, whether you tapped a phone number or followed a link off the site, and whether anything on the page broke. It is served from this domain, reports only to this domain, and reaches nobody else. Block it and the traffic figures are unaffected — only those extras go missing.

How a visit is recognised

To tell one visit of four pages from four separate people, we set a cookie. It holds a random identifier with no personal information in it, means nothing on any other website, and is never shared. There are two: one that lasts 30 days so a returning reader is not counted as a stranger, and one that lasts until you close your browser.

If you would rather not have that, we fall back to identifying the visit by a code worked out from your IP address and browser, using a secret that is thrown away and replaced every night. It is less accurate — an office behind one connection reads as one person — and it cannot be traced back the following day.

You get the second version automatically, with no cookie at all, if your browser sends a Global Privacy Control or Do Not Track signal. We honour both. You can also choose it here:

Measurement cookies are on for this browser.

This setting lives in a cookie of its own, so it applies to this browser on this device, and clearing your cookies clears it too.

How long it is kept

Individual requests, IP addresses and all, are deleted after 90 days. Measurements from the script are deleted after 60 days, and the record of a visit after 180 days.

What survives is a daily summary — how many views, how many people, how many were crawlers, how fast the pages were. Those carry no address and describe nobody in particular, which is what makes it reasonable to keep them indefinitely and why the charts can go back further than the raw data does.

We should be straight about one thing: while those individual records exist, they can be looked at individually, and an IP address is close enough to a person that we treat it as one. That is a deliberate trade — it is what lets us tell a real Googlebot from something impersonating one, investigate abuse, and answer a request to delete your data by actually finding it.

Contact form

When you submit the contact form, the name, company, email address, phone number and message you provide are sent to us by email so we can respond. Alongside your message we record the submitting IP address, browser user agent and a timestamp. Those three are used to investigate abuse of the form; they are not used to build a profile of you.

This information is used only to answer your enquiry and for legitimate business follow-up. Submissions are kept in our email system as ordinary business correspondence. Ask us and we will delete one.

Website accounts

If you have an account, we store your email address, your display name, and — if you upload one — your profile picture. Passwords are never stored. What is kept is a one-way hash from which the original password cannot be recovered.

If you register a passkey, we store the public half of the credential and a label for the device. The private half never leaves your device and we never see it. If you turn on two-factor authentication, we store the shared secret your authenticator app needs and your unused recovery codes.

Account security records

Protecting an account means keeping a record of what happens to it. We log sign-ins and failed attempts, lockouts, password changes and resets, and passkey or two-factor changes. Each entry includes the IP address, browser user agent and a timestamp.

This exists so that a compromised account can be investigated and so that repeated guessing can be blocked. Failed sign-in records are kept for 30 days; the wider security log is kept for 400 days. Both are deleted automatically after that.

We also email you when something security-relevant happens to your account — a lockout, a new passkey, a password change, or a sign-in from an address we have not seen before.

Cookies

This site sets no advertising cookies and takes part in no cross-site tracking. It sets these, and only when they are needed:

  • Measurement cookies. Two random identifiers, described above, used only to tell one visit from another on this site. Not set at all if you have opted out or your browser asks us not to.
  • Opt-out cookie. Set only if you press the button above, so we can remember that you did.
  • Sign-in cookie. Set when you sign in, so you stay signed in as you move between pages. It expires after eight hours of inactivity, or when you sign out. Choosing “keep me signed in” extends it.
  • Anti-forgery cookie. Set when a page contains a form. It ensures a form submission genuinely came from this site rather than being forged by another one. It is discarded when you close your browser.

None of these track you across other websites, and none are shared with anyone.

Server logs

Our web server also keeps standard request logs, separate from the measurement described above, which may include IP address, requested URL, referring page, user agent and timestamp. These are used for security, troubleshooting and capacity planning.

Where the information lives

Accounts, security records and website measurements are held in our own databases on servers we operate, not with a third-party provider. Email is delivered through our own mail system. Traffic to this site is encrypted in transit, and access to submitted information is restricted to CyberLogix personnel who need it in order to do their job.

Approximate location — country, region and network operator — is worked out from your IP address using a database held on our own server. Your address is not sent anywhere to do it.

Your choices

You can ask us what we hold about you, correct it, or have it deleted. You can remove your profile picture or a registered passkey at any time from your account pages, and you can turn off measurement cookies with the button above. To close an account entirely, to ask for the measurement records associated with your address to be removed, or to ask about anything on this page, get in touch.

Changes to this notice

If this site later adds chat, embedded media or other third-party services, this page will be updated to describe them before they go live, along with any consent controls required where you live.

Contact

Privacy questions can go to postmaster@cyberlogix.net, by phone on (623) 582-0807, or through our contact form.