Short version: we do not place tracking cookies, run ad networks, or share data with third parties for marketing. We use limited first-party, server-side measurements to understand page readership, search quality and whether search results are useful. There is no cross-day visitor identity and no third-party analytics script. If you click an outbound link to a sponsor or another site, that site's own rules apply from the moment you leave ours.

This page is written to be accurate and verifiable. If anything here stops being true, we'll update it.

What we don't do

  • No third-party analytics. No Google Analytics, no Plausible, no Mixpanel, no equivalent.
  • No tracking pixels. No Meta/Facebook pixel, no X/Twitter pixel, no LinkedIn Insight Tag.
  • No advertising network. We don't run AdSense, Media.net, Taboola, or any programmatic ads.
  • No third-party scripts loaded in your browser. Open the browser developer tools — there are no <script> tags loading from other domains.
  • No affiliate links with tracking cookies on our pages. Sponsor links go to the sponsor's own site; what they do there is between you and them.
  • No data sold or shared with third parties for marketing purposes. Full stop.
  • No email newsletter yet. If we add one, it will be opt-in and we'll update this page.

What we do

Server-side, privacy-friendly page-view counting

We count GET page views ourselves, on our own server, to see what content people read. The collection is intentionally narrow:

  • No cookies are set on your browser to make this work — nothing about it is stored on your device.
  • No third-party request is made when you load a page; all aggregation happens on our PHP backend.
  • No persistent visitor ID. "Unique visitor" counts are computed from a SHA-256 hash of (your IP + your User-Agent + a server-side salt + today's date). Because the hash inputs include the date, the same visitor on two consecutive days produces two different hashes, so we cannot follow you across days.
  • The hash is one-way and salted. We never store your raw IP in the analytics dataset, only the truncated/hashed form. The salt lives outside the webroot.
  • Daily measurements. We keep total views, unique-hash counts, per-page views, referrer category (for example "google" or "reddit", not the full referring URL), device class, browser family and country code.
  • Country code comes from Cloudflare's CF-IPCountry header that Cloudflare already attaches in front of our origin. We do not call a geo-lookup API.
  • Bots and crawlers are excluded by User-Agent before any data is recorded.
  • Admin and API routes are excluded.

Search-quality and result-usefulness measurement

When you use search, our own server may record:

  • the normalized words you searched for, the result count, and whether the search returned no results;
  • a broad, allowlisted journey origin (for example homepage, navigation or a topic page), an optional topic slug and the result count;
  • result impressions and interactions, including the selected result's internal document ID or URL, position and tab, plus coarse dwell time and rapid-return ("pogo") signals.

These records are used to find missing coverage and improve search quality. They are not used for advertising or personalized rankings. Search engagement does not change result ranking unless a separately controlled ranking experiment is explicitly enabled; it is currently measurement-only.

Because search text can itself contain personal information, do not enter secrets or sensitive personal data into the search box. We do not need that information to provide search results.

Search events use a one-way, salted, day-scoped session hash rather than a cookie or persistent account ID. Raw search-engagement events are retained for up to 30 days. Daily readership/search summaries and aggregated query-result quality statistics are retained for up to 90 days, after which the automated retention job removes them.

If you'd rather we didn't count your visits at all, blocking the site's own domain in your browser's tracking-protection list (for example uBlock Origin) is sufficient — there is no separate analytics vendor to opt out from. Blocking JavaScript will also prevent optional search-interaction beacons, while search itself still works.

Sponsors (direct, no tracking)

We accept direct sponsorship placements — a static image plus an outbound link — rendered from our own servers. Sponsor creatives are hosted on this domain; no third-party scripts or pixels are included on the page when an ad is shown. If you click through, you're going to the sponsor's site under its own policies.

Donations

If you choose to support us via a link to a third-party donation platform (for example Buy Me a Coffee), that platform will handle your payment and apply its own privacy policy. We never see your payment details.

Server access logs

Our web server records standard access logs — IP address, request path, user-agent and timestamp — to defend against abuse and keep the site up. Entries are retained for roughly 30 days, then rotated out. Logs are never shared with third parties. They aren't linked to any other information about you.

Cloudflare (sub-processor)

This site is served through Cloudflare for DDoS mitigation and caching. Cloudflare sees your IP address and request metadata as part of delivering the response, and adds the CF-IPCountry header we use for country aggregation. Cloudflare's own privacy practices are documented at cloudflare.com/privacypolicy. We cannot opt you out of this without taking the site offline.

When someone logs into the admin area, a session cookie is set. This only applies to site administrators — regular readers never receive a login cookie from us.

Contact email

If you email us, we keep the email in order to reply. We don't add it to any list.

When you click a link that leaves this site — whether to a news source we cite, a sponsor, a donation page, or anywhere else — you are no longer on our property, and any tracking after that click is governed by that destination's own policy. We don't add tracking parameters to those links for our own use. We disclose sponsored links with rel="sponsored" as required by search engines.

We don't show one because we don't set non-essential cookies on your device. The only cookie we issue is the admin session cookie, which is strictly necessary for administrators. The first-party measurements described above do not use cookies.

Your GDPR rights

Even with minimal data collection, EU/UK residents have the right to:

  • Know what data we hold about them (server log entries from roughly the last 30 days; recent daily measurements and search events that include only a day-scoped hash rather than a persistent identity)
  • Request a copy of that data
  • Request its deletion
  • Complain to a supervisory authority

Contact us at the address below to exercise any of these rights. Because we don't tie hashes to a persistent identifier, we may need to ask you to narrow the date range and approximate IP/User-Agent for a lookup.

Children

We don't knowingly collect information from anyone under 16.

Changes

When anything on this page materially changes — for example, if we add an opt-in newsletter or broaden data collection — we'll update this page and change the "Last updated" date at the top. We won't quietly broaden the policy.

Contact

  • Email: contact@ttek2.com
  • Website: https://ttek2.com

This policy describes the current state of the site. It is not a promise about every future feature — if a future change would broaden data collection, this page will be updated first, not afterwards.