privacy
Privacy
We count which compounds get read. We cannot tell you which compounds you read, because the counts hold nothing that could point at you. Where that guarantee has limits, this page names them rather than rounding up.
The short version
This site sets no cookies, stores nothing in your browser, runs no third-party analytics, and builds no profile of any visitor. What it keeps is a daily tally: how many times each compound page was opened, read to the end, or clicked away from, and which sites those clicks went to.
The tally has no column for who. Not an account, not a session, not an address, not a device. Two people reading the same page and one person reading it twice leave exactly the same mark, and there is no way to tell them apart afterwards, including by us.
Three things stop that being the whole story, and all three are set out below rather than left for you to find: search boxes take typed words, and words somebody types can be anything, including a name; our database provider keeps a short automatic restore history; and on a quiet day a single visitor may be most of what a day's numbers describe. We never ask for your name and nothing here is labelled with one, but the first of those three is the reason we do not simply tell you it is impossible.
Why it is built this way
What someone reads about a peptide is health information about that person. Several states now treat it that way in law, and Washington's My Health My Data Act lets an individual sue over it directly rather than waiting for a regulator. The reliable answer to that is not a policy promising restraint. It is a system that cannot produce the record in the first place.
So the design rule is stricter than the legal one: a per-reader profile is not something we decline to build, it is something the stored data is shaped to be bad at expressing. Almost every value in it is a date, a fixed category, or a compound name this site itself printed on a page, and none of those can point at a person. There is no identifier to store, so there is nothing to leak, nothing to subpoena, nothing to sell, and nothing to lose in a breach.
Two values come from outside that pattern, and pretending otherwise would undo the point of writing any of this down. One is the name of a website a reader clicked through to, and the other is the words typed into a search. Both are described below, both are limited on purpose, and neither is tied to anything else in the data.
What we count
Six kinds of thing, all of them tallies against a compound and a calendar day:
- A compound page was opened.
- A compound page was read to the end, or stayed open long enough to have been.
- A link leaving this site was clicked, and the destination's website name. The address of the page you went to is not recorded, only the site it belongs to, and once a day has seen a hundred different destinations the rest are filed together as "other".
- A search was run on this site, and a scrubbed fragment of what was typed.
- A search returned nothing.
- A comparison page between two compounds was opened.
That is the whole list. The counter that receives these rejects anything else outright.
We keep the numbers to decide what to write next and where the coverage here falls short. It is a coverage question, and a daily total answers it as well as anything finer would.
What we do not collect
| Thing | Status on this site |
|---|---|
| Cookies | None, of any kind, first or third party. There is no cookie banner because there is nothing to consent to. |
| Local storage in your browser | Nothing written. No local storage, no session storage, no database in the browser. |
| A visitor or session identifier | None is created in your browser, and none is stored. To stop one machine flooding the counter, our server does briefly hold a scrambled form of the sending address in memory, which for about a minute groups requests from that address. It is never saved, never sent anywhere, never attached to any count, and it disappears along with the random value that scrambled it when the server process is recycled. |
| Your IP address | Never stored. It is used once, in memory, for the rate limit described above, scrambled with a random value that is thrown away continuously. It is not written to any file or database. |
| Device or browser fingerprinting | None. Your browser version, installed fonts, language and time zone are not read at all, and the build refuses to ship a script here that reads them. Window size reaches the page the way it reaches every website, because the layout has to fit, and none of it is recorded or sent. |
| Your country or region | Not recorded, although our host could supply it for free. On a small site it narrows a reader too far. |
| Which pages you visited in what order | Not recorded. The tally holds nothing finer than a date and nothing that links two counts, so there is no order in it. One limit worth stating rather than hiding: our database provider keeps its own rolling 30-day restore history of the tally, and comparing two points in that history would show which counts moved between them. We do not use it that way, it expires by itself, and it is described below. |
| Third-party analytics | None. No Google Analytics, no advertising pixel, no tag manager, no session replay. |
| Requests to other companies | None. Every font, stylesheet and script on this site is served from this site. Loading a page here contacts nobody else. |
| An account, a newsletter list, or a form | None exists. The only way to contact us is email, and an email to us is just an email. |
Turning it off
If your browser sends Global Privacy Control or Do Not Track, the counter is skipped entirely: nothing is sent, and the part of the site that would have sent it never starts. Both signals are checked in your browser and again at our end, so a cached page cannot ignore them.
Blocking the script, or blocking our counter address, also works and changes nothing about the page. The measurement is not load bearing. If it fails, it fails silently and you get the same site.
The one field you type into
Site search is the only place a reader supplies free text, so it is the one field where the guarantees above rest on scrubbing rather than on the shape of the data. We would rather say that plainly than claim more than the field can carry. Before a query is counted:
- Anything containing an at sign is dropped entirely, which removes email addresses and handles.
- Every digit is removed, which removes phone numbers, order numbers, postcodes and dates.
- Only the first three words survive, each between three and twenty characters. A word is letters, plus any hyphens or plus signs sitting inside it, so a compound name written with a hyphen stays readable.
- Once a day has recorded two hundred different searches, anything further is filed together as "other". The search still counts; only the wording is set aside.
A dropped query still counts as a search. A search is also never filed against the page it was typed on, because a compound and a rare phrase together say more about one person than either does alone. What is kept is a short, digit-free fragment, held as a daily total with nothing beside it.
What that does not do, and we would rather write it down than let you find out: a fragment of ordinary words can still be unusual, and two words that happen to be somebody's name will survive the scrub, because no rule can tell a name from a search term without being told which words are names. That is why search wording is the one thing here that is not kept indefinitely, and why it is stored with nothing attached to it.
Losing the wording of an odd query costs us a line in an internal list. Keeping someone's email address in a file about peptide reading would cost considerably more, and would be ours to have caused.
Where the numbers live, and how long
On our own infrastructure at Cloudflare, who host this site. The counts are not sent to any analytics company, any advertising network, or any other third party, and they are not sold, shared or traded.
The tallies are kept indefinitely, because a daily count of page opens with no identifier in it does not become more sensitive with age, and comparing this year against last year is the reason it is collected. The wording of searches is the exception and is not kept indefinitely: there is a routine that clears search wording older than 90 days while keeping every count, and today it is run by hand rather than on a schedule. When this site has a scheduled job it will run there, and this sentence will change to say so.
Two limits of the same kind, stated because leaving them out would make the rest of this page read better than it deserves. Our database provider keeps an automatic 30-day restore history of the tally that we cannot switch off; it holds the same counts at finer moments in time, and it expires on its own. And Cloudflare, who serve every page here, keep their own operational records of requests under their terms, as every website host does. Neither is something this page can promise away, so neither is left out of it.
Asking us for your data
You are welcome to ask, and the honest answer is that there is almost certainly nothing to give you. A request to see, export or delete your personal information cannot be matched to you, because no field in the data identifies a person, so there is no way to find a row and say it belongs to you. That is a limitation of the design working as intended rather than a refusal.
The one thing that could conceivably be yours is the wording of a search, if you typed something unusual enough to stand out. Tell us the words and the rough date and we will delete the entry. Wording older than ninety days is cleared out as a matter of routine as well, though that routine is run by hand rather than on a timer, so treat it as housekeeping we do and not as a clock you can rely on. That is the whole of what we could ever hold about a person, and we would rather write it down than let the paragraph above imply a cleaner answer than the truth.
If we ever collect something that can be tied to a person, this page will say so before we start, and a real request process will exist alongside it.
Questions about any of this go to [email protected].
If this page is wrong, that is a correction
A privacy statement that does not match the code is worse than none. This one is written against the implementation, and the build helps hold it there: a gate rejects any script on this site that reaches for browser storage, an identifier, a device property, or another company's server. That gate reads the shipped code for the known ways this goes wrong, which makes it a guard against drift rather than a proof, and the honest description of it is the one on this line. If you find a gap between this page and what the site does, write to [email protected] and it goes in the corrections log like any other error of fact.