What we collect, and what we do not.
Falsify OÜ (reg. 17574308, Narva mnt 5, Tallinn, Estonia) is the controller for this site. This page describes what actually happens, not what a template says should happen.
The short version
No cookies are set by us. No IP address is stored. No identifier is assigned to you, so nothing on this site can be linked back to a person or across visits. Page counts are kept for thirty days and then deleted automatically.
Our own measurement
Each page loads a one-pixel image from registry.falsify.dev/_t. The request
records five fields:
- the host and path you visited
- the referring URL, if your browser sent one
- a two-letter country, derived by our CDN from the network connection
- a timestamp
That is the whole record. The IP address is not written down. The user-agent string is read once to discard obvious crawlers and is not stored. Records carry a thirty-day time-to-live and are removed by the store itself, not by us remembering to do it. Requests from hosts other than our own are ignored.
We use it to see whether anything we publish is being read. Two honest consequences: a referrer can tell us that a link was shared inside an organisation, and a sequence of paths can look like someone doing due diligence. We treat that as a signal about our own work, we do not attribute visits to named people or companies, and it never appears in anything we send anyone.
Analytics
We also use Plausible, which is cookieless, stores no personal data, and is hosted in the EU. It gives us aggregate counts only.
If you email us
Mail to our published addresses is delivered through Cloudflare Email Routing and read in Google Workspace. Mail we send goes through Resend. We keep correspondence for as long as the conversation is live and for our accounting obligations afterwards. If you would rather we deleted a thread, ask and we will.
The registry is permanent, on purpose
Anything submitted to registry.falsify.dev is a public, append-only record. That is the point of it: a receipt that could be withdrawn would not be a receipt. The registry refuses submissions whose handle looks like personal data before storing anything, because permanence and personal data do not belong together. Do not submit personal data to it; we cannot remove it afterwards.
Who else sees data
The full list is on the subprocessors page.
Your rights
Under the GDPR you may ask what we hold about you, ask for it to be corrected or erased, and complain to a supervisory authority. Ours is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). In practice we hold almost nothing: if you have only read the site, there is no record tied to you to retrieve or erase. Write to [email protected].
Changes
If this page changes materially we will say so here with a date rather than update it silently.