<marquee><h2>"We care about your privacy." — Abraham Lincoln</h2></marquee>
<p>We don't <strong>make an effort</strong> to collect any data from you.<p>
<p>What we <strong>do</strong> have is automatic server logs (<em>which most sites can't be bothered to de-identify anyway</em>).</p>
<p>Server logs look like this: (<em>Hover for details</em>)</p>
<?phpforeach($HIGHLIGHTED_FIELDSas$field):?>
<inputtype="checkbox"id="show-<?=$field?>">
<?phpendforeach;?>
<pre><labelfor="show-ip"title="De-identified IP address">155.71.106.0</label> - - <labelfor="show-datetime"title="Time of visit">[27/Jan/2041:14:05:22 +0000]</label><labelfor="show-resource"title="Requested resource and method">"GET / HTTP/2.0"</label><labelfor="show-status"title="Status returned by the server">200</label><labelfor="show-bytes"title="Size of server response">41322</label><labelfor="show-referer"title="Site which referred the user to us">"https://duckduckgo.com/"</label><labelfor="show-user-agent"title="User Agent Header">"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36"</label></pre>
We also collect and retain error logs for 3 days, including a full IP address.
These are generated when our server has a wonderful day and shoots itself in the foot, and are not used for analytics.
</p>
<h2>Who has access to your data</h2>
<p>
Only <atarget="_blank"href="https://codeberg.org/gravel/gravel">@gravel</a>, <atarget="_blank"href="https://github.com/mdPlusPlus/">@SomeGuy</a> and the server provider have access to the server logs.
</p>
<p>
Whenever we feel like it (<em>legal terminology</em>), we share aggregate visitor data over a non-identifying time period with interested parties. Examples of aggregate visitor data: Total site visits, distribution of operating systems and browsers used to access our site, distribution of referer sites, and common failed requests (such as for unsupported standards).
</p>
<h2>What requested resources tell us about you</h2>
<p>
Normally, using requests for Community icons and QR codes,
we could track each time a user opened a Community details modal for the first time (in a given cache period)
and deanonymize users joining Communities.
However, we blind ourselves to this information by requesting all Community icons and QR codes when the page loads.
These resources are then cached in your browser and don't trigger additional requests when you view a Community's details.
</p>
<p>
We refresh the cache periodically to ensure that this protection does not expire following the 1 hour cache period.
Unfortunately, this also means we get a ping for each hour you leave the site open.
</p>
<p>
<strong>If you've disabled JavaScript</strong>, protections against opening modals are not needed;
however, we log requests to QR codes when they are opened in a new tab.
</p>
<h2>Cookies</h2>
<p>We don't use 'em. <ahref="./donate.html"style="text-decoration: inherit; color: inherit;">🍪</a></p>
<hr>
<h2>So, you scrolled all the way down here.</h2>
<p>The cookie emoji will take you to the donation page. Try it!</p>