Report Engine Privacy

This site counts page views. It cannot tell who you are.

The public Report Engine site is a handful of static files — no account, no login, no form, no database. Beyond the ordinary request your browser makes for a page, the only thing it sends about your visit is an anonymous, cookieless page-view count: Cloudflare's beacon, described in full below. This site sets no cookie of its own, writes nothing to browser storage, and keeps no identifier that survives the page. What follows is the whole of it, request handling included.

No cookies, no browser storage

This site sets no cookies. It writes nothing to localStorage or sessionStorage, and it stores no identifier that survives the page. You can check that on any route here: open your browser's developer tools, and the cookie jar and both storage areas stay empty. That is also why no pop-up interrupts you on arrival — nothing on this site would need one.

Cloudflare, which serves the site, may set its own __cf-prefixed cookies for bot mitigation and network security. Those are part of delivering the page, they carry no profile of you, and this project neither reads them nor receives them.

What the analytics beacon counts

Every page loads Cloudflare Web Analytics — static.cloudflareinsights.com/beacon.min.js. What it produces is anonymous, cookieless page statistics: aggregate figures such as the path visited, the referring page, country, browser family and page-load timing. It writes no cookie and no identifier, so it carries no personal data and does no cross-site tracking — it cannot follow you between visits, and it cannot follow you to anyone else's site. It can answer how many people opened the sample report last week. It cannot answer who they were.

No other analytics, advertising or session-recording service is loaded on any page of this site. That is checkable rather than promised: open the network panel and the only third-party request is the beacon's.

What serving a page involves

Like any web server, Cloudflare processes the technical details of a request — the connection's IP address, the user agent, the path — in order to return the file and to keep the site up. That is Cloudflare acting as this site's host under its own privacy terms. Nothing in this project reads those logs or builds anything from them.

Who is responsible, and on what basis

The controller for this site is Obsidian Peaks Technologies AB (org.nr 559581-1455). The processing described above rests on legitimate interest: knowing in aggregate whether the published sample is being read, and keeping the site available and free of abuse. Because the beacon is anonymous and cookieless and the site writes nothing to your browser, that interest is served without holding anything that points back at you — which is why this page is a description rather than a request.

Your rights

The GDPR gives you the right of access to personal data held about you, the right to rectification of anything inaccurate in it, and the right to erasure of it, alongside restriction, objection and data portability. On this site those rights have very little to act on: with no account, no form, no cookie and no stored identifier, there is no record here to hand over, correct or delete. Whatever Cloudflare holds as this site's host — its request logs, for instance — is Cloudflare's to answer for under its own privacy terms.

To exercise any of those rights, or to ask anything about this page, write to info@obsidianpeaks.com — the controller's monitored mailbox. Name the right you are exercising; no particular form of words is needed, and given what is described above the honest answer will usually be that nothing held here points back at you. You can raise a complaint with the Swedish supervisory authority independently of that: Integritetsskyddsmyndigheten (IMY), imy.se.

The published audit contains no client data

The sample report and appendix under /sample come from running the battery against this project's own fixture bot — a deliberately broken support widget that lives in this repository and is seeded on purpose with the flaws it gets caught making. No client, no customer and no real person's data appears in the published run, and the export filter refuses to publish anything sourced from a real engagement.

If this ever changes

The rule this project holds itself to: nothing may be written to your browser, and no visitor identifier may be created, unless the same change ships a blocking gate that asks you first and writes nothing until you have answered. The cookieless default is what makes this page short, and it is what keeps it short.

Static page · rebuilt on every deploy · no cookies · anonymous statistics only