Legal
What this site records when you read it, when you click through to a provider and when you write to tell us a number is wrong — what the page sends and when, how long each is kept, what we do not do with it, and how to tell us not to count you.
We count our own visits on our own server, we log outbound clicks so we can tell which recommendations people act on, and we keep what you send us through the correction forms for as long as it takes to act on it. We do not sell data, we do not run advertising networks, and there is no third-party tracker on this site: no analytics script, beacon or pixel of anyone else loads here.
The server keeps a record of every page it serves, with your address in full for twelve months, to keep the site secure and to count its readers; after a year the record loses everything that points at you, and after five years it is deleted. Where we ask for consent, the page itself counts nothing until you answer Accept. Everywhere else it counts visits unless you tell it not to — with the control under Visits, or with your browser's Global Privacy Control.
You can report an error without giving a name, an account or an address. The one thing we insist on is a source, and a link to somebody else's page is not personal data about you.
The site counts its own visits. Nothing is sent anywhere but this domain, the day is added up on our server every night, and no analytics service of anyone else is involved. There are three sources, and they are not alike: the server's log of the requests it answers and its record of the pages it serves, which exist for every visit, and events the page itself sends, which exist only where you were not asked for consent or answered Accept — and never once you object. Which applies is decided on the server, from the country the request came from and what you answered; a page cannot claim more than it was given.
| Recorded | Why | Kept |
|---|---|---|
| The server's access log: the page requested, the status, the page you came from, the user agent, the country the edge derived, the request's other headers except cookies, and your IP address with its last octet removed before it is written (the last 80 bits of an IPv6 address) | To see what is read, to tell readers from automated traffic, and to keep the site available and secure | 7 days, then only the day's totals |
Beside the log, the server writes down each page it serves — and, where we ask for consent, each time it shows the request — in a record of its own:
| Recorded | Why | Kept |
|---|---|---|
The page and the time; your IP address in full; the user agent, the client hints a browser sends and the Accept-Language header; the page you came from; the country and network operator derived from the address, and whether it is a datacenter; your answer to the consent request |
To keep the site available and secure — telling readers from scanners and abuse, investigating an incident, checking a disputed click — and to count readers and returning readers | 12 months in full, then without anything that identifies you (below); deleted after 5 years |
| A reader key: a code the server computes from your network (the whole IPv4 address, or the first half of an IPv6 one), your browser and operating system without their versions, and your language, with a secret only the server holds. Nothing is stored on your device for it | To recognise a returning reader without a cookie, for as long as those four stay the same | 12 months, then removed |
After twelve months a record keeps only the page, the time, the country, the network operator, the browser and system families, the kind of device and the language. The address, the reader key, the identifiers below, the full user agent, versions, the device model, the detailed client hints and the address of the page you came from are removed. Such a record cannot be tied back to anyone; it is the statistic, and it is deleted after five years.
Where we ask for consent and you have not answered Accept, this and the log are all there is of your visit: the page sends nothing but your answer, and nothing is written to your device but that answer.
Telling a reader from a scanner needs the whole address, not a masked one: a ban on 1.2.3.0 is a ban on a reader's neighbours. So the server keeps a second, separate stream of the same requests with the full address in it — and that stream is the one thing here that is never written to a disk. It exists in memory for hours, it is never joined to anything on this page, and no part of the site can read it. Only an address that actually trips a rule is kept at all, with the decision that was taken about it, for as long as the block lasts. Nothing about a reader who is not blocked survives that window.
One small request on this site answers a single yes-or-no question — whether you are in the region where we ask for consent — so that the pages themselves can be identical for everybody. It is made at most once per page and not at all once you have answered, and it does not tell the page where you are. When the answer is yes, the showing of the request is written to the record of pages above, so that we know how often it is shown and on which pages.
Under Accept, and for readers outside the region where we ask (below), the page sends events to this domain as you read it:
| Recorded | Why | Kept |
|---|---|---|
| An event when a page is opened and when it is left, and when something on it is used — a filter or sort on the ranking, a section opened, the theme or language switched, a form sent, the interstitial answered, the game opened, played and closed with its score and time, any other link or button by its text; page errors by kind; the page's loading and responsiveness measurements. On them: the page, the language, the time spent on the page and how far it was scrolled | To know which pages and controls are used, and what breaks and what is slow | 12 months in full, then without anything that identifies you; deleted after 5 years |
Two identifiers set as cookies on this domain: a session id (hf-sid, renewed on every event and gone thirty minutes after the last) and a visitor id (hf-vid, twelve months) |
To count visits and returning readers rather than page loads | on the event, 12 months, then removed |
| Your IP address and the reader key described above | The same security checks as on a page, and the country and network when the edge did not say | 12 months, then removed from the event |
The user agent, its parse (browser, operating system, device class), the client hints a browser sends and the Accept-Language header; the country, network operator and datacenter flag, derived from the address at that moment |
To separate readers from automated traffic, and to know which browsers and devices the site has to work on | with the event |
| The full address of the page you came from and any campaign tags in the link; screen and viewport size, time zone, browser language and connection type | To know where readers come from and on what | with the event |
Under Essential only, or before you answer, the page sends one thing: your answer to the consent request and how long the request waited for it, with no address and no identifier.
Four yes-or-no facts are kept beside every event — that the request came through the edge, that the page was actually engaged with, that the network is not a datacenter, and that the consent request was answered — so that we can read the count with the automated traffic subtracted.
What is never recorded, by any of this, and would be a decision to reverse rather than a setting to change: canvas, audio or font fingerprinting, keystrokes, pointer movement, the contents of any form field, and anything on the administration pages.
You can object to being counted at any time, and it takes effect on the page you are on. The button below writes one cookie, hf-nocount; from then on this browser's pages send nothing, the server stores nothing they send, and the two identifiers are removed. The server's record of pages keeps the page and the time of your visits, but no address, no reader key, no identifier and no full user agent. A browser that sends Global Privacy Control gets the same without asking: we read the signal as an objection. Where you gave consent, this is also how you withdraw it.
An objection does not reach the server's log, the record of a click on a provider link or a form's rate limit, which exist to keep the site working and honest rather than to count you.
Every night the previous day's access log, record of pages, events and outbound clicks are added up into one record of totals: pages by address, readers new and returning, visits and where they began and ended, referring sites, arrivals from AI assistants, countries, clicks per provider, how often the interstitial was taken up, how often the consent request was shown and how it was answered, how the game was played, and the loading measurements. The totals contain nothing that identifies a person, and they are kept after the records behind them are deleted.
Two other parties touch parts of this. Cloudflare stands in front of the server: every request to this site passes through its network, which sees your address, tells us the country it belongs to, and keeps the server's own address unpublished. Cloudflare, Inc. is based in the United States; it processes these requests on our behalf under its data processing agreement, and the transfer rests on the EU–US Data Privacy Framework and the European Commission's standard contractual clauses. Telegram carries a nightly message with the day's totals to our own operator chat — counts of pages, referrers, countries and clicks — and never an address, an identifier or anything else from a single visit: totals are not personal data, so nothing about you travels with them.
Every link to a provider goes through /go/<slug>, which records the click and then redirects you. What is recorded:
| Recorded | Why |
|---|---|
| Which provider, and the page you clicked from | To know which recommendations are acted on |
| Timestamp and locale | To read the numbers over time and by market |
| IP address | Resolved to country and network, then used for fraud checks |
| Network operator and datacenter flag | To separate real readers from automated traffic |
| User agent | Same purpose |
The IP address is the only item here that identifies you personally, and it is used to derive country and network operator and to check clicks for fraud. It is retained for 12 months and then deleted; the derived country and network are kept as statistics with no address attached. The clicks are also added, per day and per provider, to the daily totals of the visit count.
There are three forms on this site, all of them on the corrections page: one for correcting a fact on a provider's record, one for a provider replying about its own record, and one for anything else that is broken. This is what each of them takes, and how long it stays.
| Recorded | Why | Kept |
|---|---|---|
| The record and field you are reporting, what you say is wrong, and the value you think it should be | It is the correction. The form carries the field identifier and the version of the model you were looking at so we do not have to ask | Until it is decided, then folded into the editorial record — see below |
| The source you link to | Nothing moves without one. If we act on it, it becomes the record's own citation | As long as the record cites it |
| Your email address, if you choose to give one | To tell you what we did with the report, including when we decide not to act on it | 30 days after we answer, then deleted |
| A provider's work email address, which that form does require | To check it is on the domain we already hold for that service. It is the only identity check we make | 24 months, as business correspondence about a disputed record |
| Your IP address at the moment you press send | Rate limiting only, so the form cannot be used to flood the queue | 7 days |
No cookie is set by any of this, and nothing is stored on your device. A form is only sent when you press the button; nothing is transmitted as you type.
If a report changes a record, the change is published in the change log — the field, what it was, what it became, and when. The log records what moved, never who asked. There is no reporter name, no address and no message text in it, and no way to work backwards from an entry to the person who sent it.
The substance of a correction outlives the submission on purpose: once we have acted, the source you gave is cited on the record and the old value is in the log. What gets deleted is the envelope — your address, your covering note, and the IP the form was sent from.
If you report anonymously we hold nothing that could identify you afterwards beyond the form's IP address, deleted after seven days — which also means we have no way to tell you what happened, so that trade is yours to make.
Mail to an address on this domain is received by Resend, our email provider, and stored on our own server: the message, its headers, and the names and sizes of any attachments. Attachments themselves stay with the provider and are fetched only when one of us opens them. We keep a message for 365 days and then delete it; a reply we send is kept for the same period beside it. If you write to an address that answers automatically, that answer is sent once and says so in its headers. Mail is read only by the people who run this site, over a private connection; nothing in it is used for anything but answering you.
Five at most, all set by this site on its own domain, none sent to anyone else. The site works with every one of them absent.
| Cookie | What it holds | Set when | Lasts |
|---|---|---|---|
hf-consent | Your answer to the consent request, so that it is not asked again | On either answer | 12 months |
hf-theme | Your theme choice | Under Accept only | 12 months |
hf-sid | A random session id for the visit count | While the page sends events | 30 minutes after the last event |
hf-vid | A random visitor id for the visit count | While the page sends events | 12 months |
hf-nocount | Your objection to being counted, so that it holds | When you object under Visits | 12 months |
The two ids are random numbers that mean nothing outside this site. Under Essential only, before you answer, or once you object, neither exists, and one set earlier is removed. Who is asked before any of them is set is under The consent request.
Readers the routing places in the European Union, the EEA or the United Kingdom are asked before the page counts anything or stores anything non-essential; a reader it cannot place is not asked. The request is a bar at the bottom of the page with two answers and a link to the section above — it does not dim the page, does not take the keyboard, and does not stand between you and a single link. Ignoring it is a valid answer for as long as you like; the page sends nothing and writes nothing while it is unanswered, and the server records only that the request was shown.
The two answers differ in one respect, and it is the respect a policy usually leaves vague:
Outside the region where we ask, the page sends its events without a request. The ids are still yours to remove — clear this site's cookies and the next visit is counted from nothing — and the counting is yours to stop, under Visits.
The law asks for a reason behind each of these, and these are ours:
We weighed those interests against yours. Nothing here is used to profile you, sold, or combined with anything from outside this site. A whole address is kept for twelve months at most, which is what investigating abuse and disputed clicks needs (one that trips an abuse rule, for as long as its block lasts), a form's for seven days, and the log's is masked before it is written; after twelve months every record keeps nothing that identifies you, and after five years it is deleted. You can stop the counting at any time.
Some outbound links may earn a commission, and paid placement above the ranking may be sold later. None of it moves a score, a rank or a review, and none of it is switched on today. The full terms — including what money cannot buy and why every provider link is marked nofollow sponsored — are on the affiliate disclosure.
It matters here for one reason only: a commission is paid on a subscription, so nothing about it depends on knowing who you are. No profile is built, and no click record is ever sold or passed on.
Wherever you are, you can ask what we hold about you, ask for it to be deleted, or object to it being processed; where we rely on our legitimate interest, you can object at any time, and for the visit count the control under Visits does it at once. In practice there are only five things we could be holding:
hf-vid cookie.Send the request through the site feedback form with About my data as its kind, and leave an address for the answer, since the form does not require one. We will answer within a month. Asking us to delete a report's contact details does not withdraw the correction itself: once a field has moved, the change is in a published log that has no personal data in it and is not rewritten.
You also have the right to complain to the data protection authority where you live or work, or where you think the problem arose.
When this policy changes materially, the date at the top moves and the change is described here rather than replaced silently. Nothing in it has changed since it was first published.