What we collect
Our web server writes a standard request log for every page it serves: the requesting IP address, the timestamp, the path, the HTTP status, the referrer, and the user-agent string. That log exists to keep the site running and to investigate abuse or outages. It is not joined to any profile, not sold, and not shared with advertisers. There is nothing else: no account system for readers, no newsletter sign-up, no contact form storing submissions, no session replay, no fingerprinting, and no advertising or analytics SDK of any kind.
Cookies and local storage
Reading this site sets no cookies. A signed session cookie is issued only to
staff who sign in to the editorial back office, and it is used for nothing but
keeping that person signed in. Your light/dark preference is stored in your
browser’s own local storage under the key gr-theme; it never
leaves your device and is never sent to our server. Clearing site data removes it.
Third parties
- Google Fonts — typefaces are loaded from
fonts.googleapis.comandfonts.gstatic.com, so Google receives your IP address and user-agent when a page loads. No cookie is set by that request. - Vendor websites — outbound links to the products we review are ordinary links. Once you click one, that vendor’s own privacy policy applies. We use no affiliate redirect or click-tracking layer.
- Product logos — some product images are served from the vendor’s own domain, which means that vendor can see the request.
Where data is held, and for how long
The site runs on dedicated servers inside the European Union. Request logs are kept only as long as they are useful for operations and security and are then rotated out. We do not export logs to third-party processors.
Legal basis and your rights
Server logging rests on our legitimate interest in operating a secure, working website (GDPR Art. 6(1)(f)). If you are in the EU, UK, or a jurisdiction with comparable rules, you may request access to, correction of, or deletion of anything we hold about you, and you may object to that processing. Because the only reader data we hold is a raw request log, an access request is best made quickly and with the approximate time and IP address you used.
Send any request to [email protected]. We answer within 30 days.
Automated clients
Crawlers and AI agents are welcome. Requests from bots are logged the same way as requests from browsers. See llms.txt and robots.txt for what is fair game.
Changes
If this policy changes materially, the date at the top of this page changes with it. Questions go to [email protected].