Privacy policy
This site collects as little as it can get away with. This page describes exactly what that is.
Last updated
In short: no advertising cookies, no cross-site tracking, no selling of data. If you never click a product link and never subscribe, we hold nothing that identifies you.
What we collect
Affiliate link clicks
When you click a product link, you pass through our own /go redirect. We record the link clicked, which page it was on, the country your request came from (as reported by our CDN at country level only), the time, and a short label naming the site that sent you —reddit, pinterest, and so on. That label comes either from the web address you arrived by or, failing that, from the host name of the page you came from. Only the host is read: the rest of that address — the path, and anything you searched for — is discarded and never stored, and moving from one page of this site to another records no label at all. We do not record your IP address, and we do not set a cookie to do it. These records are not linked to any individual and cannot be traced back to you.
The purpose is to know which recommendations people find useful. It is the only commercial measurement on the site.
Newsletter
There is no newsletter. The signup form was removed in August 2026 and there is nowhere on this site to give us an email address. This section previously described a double opt-in mailing list; that list was never sent anything and no longer exists.
Analytics
We currently run no analytics at all. No page-view tracking, no measurement script, no third-party beacon. This page previously said otherwise; that was inaccurate and this is the correction.
If we add analytics later it will be a privacy-preserving, cookieless product that records aggregate page views without fingerprinting visitors or building profiles — and this section will be updated to say so on the day it goes live, not before.
What we do not collect
- No advertising or third-party tracking cookies
- No user accounts — there is nothing to sign into
- No IP address logging in our own records
- No cross-site or cross-device tracking
- No payment information, ever — we do not sell anything directly
Third parties
When you follow a link to a merchant, you are on their site and their privacy policy applies. Merchants generally set their own cookies to attribute the referral. We have no control over and no access to that.
The site is hosted on Cloudflare and its database is hosted by Supabase. Both process requests on our behalf as service providers.
Your rights
Where the GDPR or UK GDPR applies to you, you have the right to access, correct, export or erase any personal data we hold. In practice we hold none: there is no signup, no account and no IP logging, and the click records described above are not linked to any individual. If you believe we hold something about you, ask us and we will action it.
Retention
Click records contain no personal data and are kept in aggregate. There is nothing else to retain.
Changes
If this policy changes materially, the updated date at the top changes and the change is described here rather than applied silently.
6 September 2026. The label recording which site sent you now falls back to the host name of the referring page when the link you arrived by did not carry one. Before this, that label was recorded only where a link spelled it out, which was almost never. Only the host is read and the rest of the address is discarded; internal navigation records nothing. This widened what is collected, so it is written here rather than left to the diff.
11 September 2026. That same label now also distinguishes a click that arrived with no referring page at all, or with one that is not a usable web address, from one that came from a page on this site. Internal navigation still records nothing, which is unchanged. The only new facts stored are that a request carried no referring page, or carried one that could not be read as an address — the absence of information, recorded as such. Neither says anything about you or where you had been. It is there because an automated crawler working through a list of our outbound links looks exactly like a reader unless we can see that distinction, and a visitor count inflated by a machine is a worse thing to publish than this is to store.