PRIVACY

Useful numbers.
No advertising profiles.

We use self-hosted Umami analytics to understand whether the site is useful, measure the test journey and report honest sponsor performance.

01

What analytics measures

Self-hosted Umami records page paths and titles, referring pages without query strings or fragments, browser, operating system, device, screen and language. It can also derive approximate country, region and city from a network address when that information is available. It records allowlisted idea, test, source and sponsor events. Event data is limited to an idea slug, broad acquisition cohort, approved campaign code or fixed placement label. We never send search text, copied or downloaded brief content, email addresses, start dates, response tokens or recovery data to analytics.

02

How attribution works

Approved campaign codes map to owned, matched-direct or permitted-external traffic. Missing or unapproved codes become background traffic. The first attribution stored for a browser tab is kept for that tab, even if a later link carries a different campaign. Query strings and URL fragments are removed before any analytics payload is sent.

03

How visitors are estimated

Umami uses no cookies. Umami 3.3.1 derives an anonymous session ID from the site, IP address, browser user agent and a rotating server salt. We do not add a fingerprint, login or long-lived visitor ID. One person using multiple devices can be counted more than once, and people sharing a device and browser can be counted as one visitor. If a 21-day window crosses the active salt boundary, visitor measurement is marked incomplete.

04

QA and bot traffic

Internal checks marked with qa=1 store a local QA flag and cancel automatic page views and manual events before sending. qa=0 clears that flag. Umami rejects recognised bot user agents unless its server-side bot check is disabled. Visitor numbers enter the decision gate only after that check is verified and declared test probes are excluded.

05

Dated commitments

If you choose a start date, we store the idea, date, cohort and consent version. A salted abuse key is retained for no more than two days. The commitment can be made without an email address. The private commitment record, not the browser event, is the result we count.

06

One-time follow-up

If you explicitly request it, we encrypt your email address and send one message seven days after your start date. This is not marketing consent. Contact details and the private response token are removed after you answer, request deletion, or 30 days after the follow-up is due. The anonymous outcome may remain for the product decision record.

07

Where it stays

Analytics and commitment records stay on private, self-hosted infrastructure. Analytics remains in Umami until it is manually deleted, and we review whether it still earns retention after each 21-day test. Email delivery uses Emailit only for the message you requested. Email tracking is disabled.

08

Your choices

The follow-up page can delete your contact details and token immediately. Email [email protected] for access, correction or deletion questions, or if you no longer have the link.