PRIVACY & ANALYTICS

Privacy & Analytics

This notice explains what the website collects, why it is collected, how long it is retained, and how you can opt this browser out or allow analytics again.

YOUR PREFERENCE

Your analytics preference

Global Privacy Control (GPC) or Do Not Track (DNT) opts you out before we read or create an anonymous identifier. You can also opt out manually; doing so removes the visitor and session identifiers owned by this website.

The current page stops creating analytics events immediately. Other same-origin pages make a best effort to inherit the choice through website-owned storage, a named opt-out cookie and real-time synchronization. The opt-out cookie stores only the value 1. A 256-bit random revocation credential remains only in this website's localStorage marker; the server stores only a digest produced with a separate key.

To re-enable analytics, the browser first preserves and registers the credential, then asks the server to revoke it. The local marker and opt-out cookie are cleared only after server confirmation. If the browser is offline or the service is unavailable, opt-out remains in effect and the control shows a retry state. GPC and DNT always take priority, and other open pages are never remotely switched to active collection.

This browser's analytics preference is unavailable; analytics sending remains off

COLLECTION

What we collect

We process only the information below, all of which the browser or request can provide without additional permissions.

01

Page visits and acquisition

Anonymous visitor and session identifiers, page path and title, previous page, landing page, referrer, UTM parameters, client time, and clock offset. Sensitive query values are replaced in the browser before anything is sent.

02

Devices and browsers

Browser and client hints, language and platform, screen and viewport, network estimates, privacy signals, device capabilities, results from a fixed font list, and browser-provided battery and storage capacity estimates. Standard fields also include the masked WebGL vendor, renderer, and capability limits.

03

Sensitive browser fields behind governance gates

The unmasked WebGL vendor/renderer, canvas hash, and combined fingerprint can be enabled only when the accountable owner has signed the governance ACK and the identifier injected by a clean build exactly matches that record. These fields are disabled in the current production configuration, so they are neither collected nor stored.

04

Performance

Navigation and resource timings, TTFB, FCP, LCP, CLS, INP, long-task summaries, and memory summaries where the browser supports them. These measurements help us diagnose page speed and stability.

05

Download entry clicks

Clicks on download entry points are recorded with the product, platform, channel, and version. A TestFlight invitation click means only that someone opened the invitation entry point; it does not prove an install, activation, or continued use.

06

Request and security information

Server receipt time, sanitized request information, request ID, bot classification, and IP data confirmed by a trusted proxy. The raw IP is stored encrypted, while the IP digest is handled separately from the ciphertext.

PURPOSE

Why we process it

Analytics supports website operations and product-entry trends. It is not used for advertising profiles, and personal information is not sold.

01

Improve the website

Understand whether pages are easy to use and acquisition sources are clear, then improve the information architecture and published content.

02

Protect reliability

Measure loading and interaction performance, and find anomalies, failed requests, and compatibility problems.

03

Understand beta interest

Compare entry-click trends by product and platform without treating a click as an install or an active user.

04

Limit abuse

Use the IP digest for rate limiting, opt-out matching, security investigations, and de-identified trend summaries.

PROTECTION & ACCESS

Encryption, access, and audit

Raw IP addresses are encrypted with versioned keys. During the raw-event retention period, only authenticated administrators with a business need may receive short, controlled access. The IP digest is generated with a separate key for rate limiting, opt-out matching, and security trends, not to identify people publicly.

Authentication and permissions restrict administrator access. Sensitive views, exports, deletions, and governance changes are written to audit records.

180 daysRaw analytics events, performance records, and download entry clicks
365 daysAdministrator access and action audit records
IndefinitelyVerified daily aggregates that contain no raw event content

Server-side revocation credential claims and opt-out markers are retained for up to 365 days and refreshed on a controlled schedule. Expired claims are removed first; a parent opt-out marker is removed only when no other valid claim remains for the same IP digest. Claims from multiple browsers behind a shared NAT remain independent. Only a browser holding its original credential and still in its original network context can revoke its own claim.

Visitors inactive for more than 180 days, expired sessions, and unreferenced device profiles and acquisition fields are removed by restricted maintenance tasks. A task returns deletion counts only; a failure leaves maintenance in a failed state and triggers an operational alert. Administrator audits are retained for 365 days, raw events for 180 days, and verified aggregates indefinitely.

Local retention is as follows: the visitor cookie is retained for up to 180 days; the manual opt-out cookie is retained for up to 365 days; sessionStorage lasts until the browser session ends; the versioned manual opt-out marker in localStorage remains until the user clears it or the server confirms revocation. The visitor identifier is deleted on opt-out and otherwise remains until the browser or user clears it.

EXCLUDED

What we explicitly exclude

We do not request precise location or read permission states, the clipboard, camera, microphone, contacts, Bluetooth, USB, serial devices, or HID devices. We do not collect form contents, keystrokes, authentication tokens, arbitrary request bodies, unrelated DOM content, raw canvas pixels, or audio samples.

The client analytics code accesses only its own three storage keys and never reads or parses the full browser cookie string. It writes only its own visitor and opt-out cookies, and does not enumerate other localStorage, sessionStorage, IndexedDB, or cache contents. When the server receives a request, it matches only the owned opt-out marker and does not parse other cookies.

Raw events, performance data, and download clicks are retained for 180 days; audit and opt-out lifecycle records for 365 days; verified aggregates indefinitely. Manual opt-out stops the current page immediately. Re-enabling completes only after the server confirms revocation of the current credential, and network failure never restarts collection. Sensitive production fields remain behind the hard gates of a genuine governance ACK and the Task 12 clean-build manifest.