Skip to main content

Privacy

This page describes how SSWI handles personal data on the public site. It applies to visitors and signed-in users.

What we collect

  • First-party analytics (optional module). When analytics is enabled, we record page views and Core Web Vitals (for example LCP, INP, CLS). Events are sent to our own servers. We do not set an analytics cookie. When a visitor salt is configured, IP addresses are hashed for the UTC day and are not stored in raw form with the event.
  • Authentication. If you create an account or sign in, we store session cookies required to keep you logged in (Secure / HttpOnly where applicable) and account data you provide (such as email and display name).
  • Transactional email. Password reset and similar mail use your email address only for that purpose.

What we do not do

  • We do not sell personal information.
  • We do not load third-party ad trackers on the public site by default.
  • We do not use accessibility overlay widgets that claim to remake the site accessible at runtime.

Global Privacy Control (GPC)

If your browser sends the Global Privacy Control signal (Sec-GPC: 1 or navigator.globalPrivacyControl), we treat that as an opt-out: first-party analytics collection is skipped in the browser and rejected on the collect endpoint.

Cookies

Essential cookies are used for authentication and security. Analytics, when enabled, does not rely on a tracking cookie. You can clear cookies in your browser at any time; signing out ends the session cookie.

Your choices

  • Enable GPC in a supporting browser to opt out of analytics collection.
  • Use password reset to change credentials associated with your account.
  • Security researchers: see security.txt.

Contact

For privacy questions, use the contact published in /.well-known/security.txt, or the site operator's published contact channels.