Privacy Policy
What we collect
and what you can do about it.
Last updated: May 2026. This site is not ad-supported and does not sell data. Here is an honest account of every piece of data we store.
What we collect
Account profile (users/{uid})
- email — from your Google sign-in
- displayName — from your Google account, editable
- role — member / contributor / admin (set by site admin)
- createdAt / updatedAt — timestamps
Stored only for accounts with a role. Anonymous visitors have no profile doc.
Page views (pageviews collection)
- path — which page you visited (e.g. /tax-rates)
- timestamp — when
- role — your role at time of visit, or "anonymous"
- uid — your Firebase UID if signed in, null if anonymous
- visitorId — a random UUID stored in your browser's localStorage, used to count unique visitors anonymously
- referrer — the page you came from (if your browser sends it)
- utmSource / utmMedium — URL campaign parameters, if present
- userAgent — your browser's user-agent string (browser, operating system, and device type), used to understand which devices our readers use
Pageviews are only recorded after you accept the cookie banner. Only site admins can read these records, and they are used exclusively for understanding which content performs well — never shared, never sold.
Aggregate traffic counts (analyticsDaily collection)
- per-day and per-hour totals — page views and an approximate unique-visitor count
- per-page counts — how many views each page got
- traffic source — a coarse channel bucket (e.g. Bluesky, Google, Direct), never the full referring URL
This is a cookieless counter that runs for every visitor and needs no consent, because nothing is stored on your device and no personal data is kept. Your IP address and browser are read only momentarily to approximate unique visitors via a hash that changes every day — they are never stored, and the hash cannot identify you or link your visits across days. Only aggregate totals are saved.
Vercel Analytics
This site uses Vercel Analytics for aggregate traffic metrics. Vercel collects performance data (page load times, Web Vitals) independently — it is not tied to your account here. See Vercel's privacy policy.
Google Analytics for Firebase
This site uses Google Analytics for Firebase (GA4) for aggregate audience metrics, and it only loads after you accept the cookie banner. When enabled, Google collects standard analytics events along with approximate location (derived from IP, which Google does not store) and device, browser, and operating-system information. This data is processed by Google and is not joined to your account here. See Firebase's privacy and security documentation and Google's privacy policy.
How long we keep it
Account profiles are kept as long as your account is active. Pageview records are automatically purged after 90 days by a weekly cleanup job (Sundays, 3am PT). If you delete your account (below), all pageview records tied to your UID are deleted immediately.
The visitorId in localStorage persists until you clear your browser data. It is not linked to your account profile — we cannot connect an anonymous visitor ID to a name or email.
Your rights (GDPR / CCPA)
If you are in the EU (GDPR) or California (CCPA), you have the right to access your data, correct it, and request deletion. We honor these rights for all users regardless of location.
- Access (export): Download a JSON file of everything we store about you.
- Deletion: Delete your account, profile, and all associated pageview records. Irreversible.
- Correction: Update your display name in your account settings, or contact us to correct other fields.
- Cookie consent: Analytics and pageview tracking only run if you accept the cookie banner. You can change your choice at any time with the button below.
- Self-exclusion (admins): Open browser DevTools → Application → Local Storage → set crd_exclude_self to true to keep your own visits out of the stats even after accepting.
Self-service data tools
Sign in to use these tools.
Export my data
Downloads a JSON file containing your profile and all pageview records tied to your account.
Delete my account
Permanently deletes your account from Firebase Auth, your Firestore profile, and all pageview records tied to your UID. This cannot be undone.
Contact
Questions about your data? File an issue at github.com/edazzle/connectrealdots.