Privacy · last updated 25 August 2026

What we collect, and what we do not.

Falsify OÜ (reg. 17574308, Narva mnt 5, Tallinn, Estonia) is the controller for this site. This page describes what actually happens, not what a template says should happen.

The short version

No cookies are set by us. No IP address is stored. No identifier is assigned to you, so nothing on this site can be linked back to a person or across visits. Page counts are kept for thirty days and then deleted automatically.

Our own measurement

Each page loads a one-pixel image from registry.falsify.dev/_t. The request records five fields:

That is the whole record. The IP address is not written down. The user-agent string is read once to discard obvious crawlers and is not stored. Records carry a thirty-day time-to-live and are removed by the store itself, not by us remembering to do it. Requests from hosts other than our own are ignored.

We use it to see whether anything we publish is being read. Two honest consequences: a referrer can tell us that a link was shared inside an organisation, and a sequence of paths can look like someone doing due diligence. We treat that as a signal about our own work, we do not attribute visits to named people or companies, and it never appears in anything we send anyone.

Analytics

We also use Plausible, which is cookieless, stores no personal data, and is hosted in the EU. It gives us aggregate counts only.

If you email us

Mail to our published addresses is delivered through Cloudflare Email Routing and read in Google Workspace. Mail we send goes through Resend. We keep correspondence for as long as the conversation is live and for our accounting obligations afterwards. If you would rather we deleted a thread, ask and we will.

The registry is permanent, on purpose

Anything submitted to registry.falsify.dev is a public, append-only record. That is the point of it: a receipt that could be withdrawn would not be a receipt. The registry refuses submissions whose handle looks like personal data before storing anything, because permanence and personal data do not belong together. Do not submit personal data to it; we cannot remove it afterwards.

Who else sees data

The full list is on the subprocessors page.

Your rights

Under the GDPR you may ask what we hold about you, ask for it to be corrected or erased, and complain to a supervisory authority. Ours is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). In practice we hold almost nothing: if you have only read the site, there is no record tied to you to retrieve or erase. Write to [email protected].

Changes

If this page changes materially we will say so here with a date rather than update it silently.