Transparency

Privacy and first-party analytics

What this website records

Source Potato uses first-party, server-side operational analytics. It does not load a third-party analytics script or use browser fingerprinting code. When a dynamic page or portal endpoint runs, the server may record the page and method, a first-party visitor and session cookie, IP address, user agent, referrer, selected request headers, approximate technical request details, response status, and performance information.

We use this information to understand site reliability, investigate errors and abuse, measure which areas are being used, and maintain the service. A browser cookie identifies a browser installation, not a person; shared networks, VPNs, cookie deletion, privacy tools, and automation make attribution uncertain.

Retention: the first-party visitor cookie lasts up to 14 months; the session cookie lasts 30 minutes and is renewed by activity. Detailed first-party analytics records are automatically pruned on a rolling basis after 180 days. Other security and application records may follow the retention terms published for the relevant product.

What is not recorded by this analytics system

The analytics recorder does not store request bodies, uploaded evidence, passwords, authorization headers, cookies, participant codes, access tokens, or submitted form contents. Query-string names that appear sensitive are redacted before analytics storage, and referrer query strings and fragments are not retained. Product-specific systems, such as GDID Usage Discovery, have their own disclosures that describe the data a participant explicitly chooses to submit.

Limits and choices

Operational logging cannot be made risk-free. We restrict access to the internal analytics console and treat the data as operational evidence, not as a profile of a person. You can clear first-party cookies in your browser; standard server logs and security controls may still record connection information necessary to operate and protect the site.