Advertising and aggregate data policy
Advertising is limited to policy-eligible public resource pages. App, upload, result, account, inquiry, payment, dashboard, admin, medical, incident, security, and private workflow surfaces remain ad-free.
Consent and privacy signals
First-party aggregate measurement is off by default. A browser DNT or Global Privacy Control signal always keeps it off. Google advertising consent is handled through the Google-certified consent platform configured for the publisher account.
What the event API accepts
The API accepts only repository, allowlisted event, public surface, and consent-policy version. It rejects extra fields. A short-lived, date-scoped salted network fingerprint is used only for abuse limiting and is not joined to aggregate reports.
What is never sold
Personal, sensitive, raw, event-level, and re-identifiable data is not sold. Aggregate counts are used to publish benchmark summaries, improve free resources, and prioritize useful content.
Storage
Cloudflare D1 stores daily aggregate counters and expiring abuse-control counters. Firebase Firestore stores only curated public aggregate snapshots under deny-by-default rules. Private inquiries are isolated from telemetry.
Controls
Use the measurement control on any resource page to grant or withdraw first-party aggregate consent. Clearing site storage also removes the browser-local preference and readiness checklist state.