Check current goblin level
Will Blew

Privacy

The short version. There are no third-party trackers on this site, no advertising, and nothing is sold or shared. Reading it needs no account and asks nothing of you; the only thing you are ever invited to type is a comment. Your IP address is never written to any database here. One cookie exists, on blog post pages only, and it is there so the comment form works.

The long version is below, because “we value your privacy” is not a fact about anything.

What is not here

No Google Analytics. No Meta pixel, no tag manager, no advertising network, no A/B testing service, no session recorder, no heatmap, no chat widget, no embedded fonts, no CDN-hosted scripts.

Every stylesheet, script, image and icon on this site is served from this site. That is enforced rather than promised: the Content-Security-Policy header sends default-src 'self', so a browser will refuse to load a third-party resource from these pages even if one were added by mistake.

Links to YouTube, Ko-fi and X in the menu are ordinary links. They load nothing until you click them, at which point you are on their site under their policy.

Reading a page

Each page view writes one row recording the time, the path, the post id, the host that referred you if any, a two-letter country code, whether the request looked like a phone, a desktop or a crawler, and a visitor hash. Raw hits are deleted after 120 days.

Your IP address is not in that row. Neither is your User-Agent string. The visitor hash is built from both, keyed with a salt derived from the day: it answers “how many different people today, and did they read more than one thing” and then stops working. Tomorrow the same person hashes to something else, so there is no profile to follow anyone across a week, and nothing to join against.

The country code comes from Cloudflare, and only when the request genuinely arrived through Cloudflare. It is the country, never anything finer.

The pixel

At the bottom of each page is a 1×1 transparent image pointing at /px.php on this domain. It is 42 bytes, it sets no cookie, and it carries one short-lived token that refers to the page view it belongs to and to nothing else.

Its only job is to mark that view as having been rendered by something that loads images. This origin takes a great deal of crawler traffic and crawlers usually take the HTML without the picture, so every figure on this site exists in two flavours: served, and confirmed. It is a bot filter, not a beacon.

Comments

If you leave a comment on a post, what is stored is the name you typed, the comment itself, the time, the post it belongs to, and a keyed hash of your IP address. The address itself is not kept. No email address is requested and there is no account.

That hash is not rotated, unlike the one above — it is stable, so repeat abuse from one source can be recognised. It cannot be reversed into an address, but it is the same value for you next month as it is today.

A comment is published content. It stays up with the post until it is removed on request or because it is spam.

The cookie

One, named PHPSESSID, set only on blog post pages. It holds a PHP session, and the session holds a CSRF token for the comment form and the timestamps that enforce its rate limit. It is marked Secure, HttpOnly and SameSite=Lax, it contains no information about you, and it expires when you close your browser.

No cookie is set on the home page, this page, or /radar. Cloudflare may set its own cookies as part of its bot protection; those are theirs, described in their policy, and this site neither sets nor reads them.

Crawler records, and /radar

This site keeps a separate record of automated traffic: the time, the path, the response status, which crawler it appears to be and who operates it, the referring host, the country, and whether the claim survived a reverse-DNS check. Most of it does not — forged Googlebot is the single largest category of traffic here.

Human requests appear in that record too, and are deliberately thinner: the full User-Agent string is kept only for bots. For a person it stores the browser family and nothing more. No IP address is in this record either.

/radar publishes some of this live, under one rule: machines are named, people are only counted. A crawler gets an event with its name, the page and the country. A human request produces no event at all — no path, no timestamp, no referrer — only a number in a total. Country counts below three hits are folded into an “elsewhere” figure rather than drawn on the map, because one dot from a quiet country points at a person while three are a statistic.

Server logs

The web server keeps its own access log, independently of everything above: the connecting address, the time, the request, the status, the referrer and the User-Agent. These rotate daily and are kept for 14 days, then deleted.

The connecting address is usually not yours. This site sits behind Cloudflare, so for normal traffic the log records the Cloudflare machine that forwarded the request. A request made straight to the origin server, bypassing Cloudflare, is logged with its real address.

Cloudflare

Traffic to this site passes through Cloudflare before it reaches the server. They see the full request, including your real IP address, before this site sees anything. What they retain is governed by their own privacy policy, not this one. This is the single largest piece of data handling associated with reading this site that is not under its author's control, which is why it has a heading rather than a footnote.

How long things are kept

  • Server access logs — 14 days.
  • Page view rows — 120 days.
  • Daily and monthly totals — kept; they are counts with nothing in them to identify anyone.
  • Crawler records — kept, for studying how automated traffic changes over time.
  • Comments — kept with the post.

Asking for something to be removed

For a comment, say which one and it will be deleted.

For anything else, there is an honest limitation worth stating: the pseudonymisation above is not decorative, and it works in both directions. There is no IP address stored to search on and no way to turn a hash back into a person, so a request to find and delete “my” page views cannot be fulfilled — not as a refusal, but because the records contain nothing that could be matched to you. They age out on the schedule above regardless.

No data from this site is sold, shared, or handed to an advertising network or a data broker, and none of it is used to build a profile of anyone. Nothing here is directed at children.

Ask, argue, or report a mistake on this page: @willblew.

Changes

This page is written from the code that does the recording, not from a template, so it changes when that does rather than on a review cycle. It was last correct on . The terms covering what you may do with what is published here are at /terms.