Anonymity
Privacy without the forms.
We do measure traffic so we know which writing is worth continuing, and this page explains exactly how, in plain words rather than legal ones.
Last updated 7 September 2026
The short version
There is nothing on this site that asks you to identify yourself, and there is no part of it that becomes more useful if you do. Every article is open, every page works without an account, and none of it is priced in contact details. What follows is the long version of that same sentence, written out properly because a policy that only says trust us is not worth publishing.
We measure traffic in aggregate so we can tell which writing is worth continuing. That measurement is the only ongoing collection on this site. Everything else described below happens either because your browser has to make a request for a page to load at all, or because you chose to write to us.
Who this covers
This policy covers this website and the email address published on it. It does not cover work carried out under a signed agreement, which is governed by that agreement instead, and it does not cover any other site you reach from a link here.
Egnworks works with engineering teams in a number of countries. Where local law gives you stronger rights than this policy describes, the local law applies and we will follow it rather than argue about which one is narrower.
What we collect
We do not ask you for anything. There is no login, no comment system, and no newsletter form on this site. What we do collect is aggregate traffic measurement through Google Analytics, which tells us which pages get read and roughly where readers come from.
That measurement includes the pages you view, the site or search that referred you, an approximate location derived from your IP address, and basic device and browser details. We look at it in aggregate to decide what to write next. We do not attempt to identify individual readers and we have no way of doing so.
Aggregate means we see that a page was read a certain number of times last week, which countries those reads came from, and which article sent someone to which other article. We do not see who you are, we do not build a profile of you across visits, and there is no report available to us that would let us try.
What we never collect
We do not collect names, postal addresses, phone numbers, dates of birth, payment details, or any of the categories that data protection law treats as sensitive. We have no account system, so there is no password of yours anywhere in our infrastructure to leak.
We do not buy data about readers, we do not enrich what little we have with anything bought elsewhere, and we do not sell, rent, or trade any of it. There is no advertising on this site and no advertising network has any presence on it, which removes the single largest source of tracking on most of the web.
Cookies
Google Analytics sets cookies in your browser to tell repeat visits apart from new ones. They hold a randomly generated identifier, not your name or address, and they expire on their own. Nothing else on this site sets a cookie.
Blocking or deleting them costs you nothing here. Every page works exactly the same either way.
That is worth stating plainly because it is unusual. On a great many sites the cookie notice exists to protect the site rather than the reader, and refusing quietly degrades what you are allowed to read. Nothing of the sort happens here. Refuse everything and the site behaves identically, because none of the writing was ever conditional on measurement.
How to opt out
Browser settings that block cookies or trackers will stop this measurement. Google also publishes a browser add-on that opts you out of Analytics across every site that uses it. Either approach is fine with us.
Private browsing windows, tracker blocking extensions, and the blocking built into most current browsers all have the same effect. We do not attempt to detect any of them, we do not ask you to disable them, and we do not treat a reader who blocks measurement any differently from one who does not. If our numbers end up lower than reality because of it, that is a cost we accepted when we chose not to gate anything.
Do Not Track and Global Privacy Control
If your browser sends a Do Not Track header or a Global Privacy Control signal, we treat it as a genuine request rather than a suggestion. In practice there is very little for it to switch off here, since we run no advertising, share nothing with data brokers, and have no cross-site profile of you to suppress in the first place.
What your browser requests
Loading a page also pulls fonts and images from a small number of third-party providers, chosen for speed and for not tracking readers. Each of them necessarily sees the network request your browser makes, including your IP address, in the same way any web server does. None of them receives anything from us about you, and we receive nothing from them.
This is the part of web privacy that no site can honestly promise its way out of. A request has to reach a server for anything to appear on your screen, and a server cannot answer a request it has not received. What a site can control is how many separate parties end up seeing that request, and we keep that number as close to one as the work allows.
If you use the search box
The search on this site runs against an index held by a third-party search provider, so the words you type are sent to that provider in order to come back with results. The index contains article titles and paths from this site and nothing about you.
We do not log searches ourselves, we do not tie a search to a reader, and we do not read them back later to see who was looking for what. If you would rather not send a query anywhere, every article is reachable without the search box through the topics page and the category pages.
Access logs
Standard access logs are kept for a short period for operational and security purposes. These record the requested address, a timestamp, and a user agent. We do not mine them for analytics or profiling.
Logs of this kind are what let anyone notice that a site is being scanned, scraped at a rate that costs money, or probed for something that is not there. Given what we do for a living it would be strange to run a site with no ability to see that at all. They are read when something looks wrong and otherwise left alone until they expire.
Where the data goes
Analytics data is processed on servers in several countries. Using this site means accepting that transfer. We hold no copy of it ourselves beyond the reports we are shown.
Where a transfer leaves a jurisdiction that restricts it, it rests on the standard contractual terms the provider publishes for exactly that purpose. We are a small crew and we did not negotiate bespoke terms with anyone. If that arrangement is not acceptable to you, blocking the measurement as described above stops the transfer at your end, which is the more reliable of the two options anyway.
How long we keep things
Aggregate traffic reports are kept for as long as they remain useful for deciding what to write, which in practice is a small number of years. Access logs are kept for a short operational period and then expire on their own. Neither is archived anywhere else.
Email is the exception, and it is kept deliberately. A thread from two years ago is often the only record of what was agreed, what was ruled out, and why. We keep correspondence for as long as it might still be needed for that, and we delete a thread on request unless we are required to keep it for a legal or accounting reason, in which case we will say so plainly rather than ignore the request.
Why we are allowed to hold any of it
For readers in places where processing needs a stated legal basis, ours is legitimate interest. Running a website securely, keeping it online, and understanding in aggregate which writing is read are all ordinary operational interests, and none of them override a reader's rights, because none of them involve identifying a reader.
For email, the basis is the correspondence itself. You wrote to us and a reply is what you were asking for. For anything carried out under a signed agreement, the basis is that contract, and the agreement rather than this page sets out what happens to the data involved.
If you email us
When you write to hello@egnworks.com we keep the correspondence so we can reply and refer back to it later. We do not add you to a mailing list and we do not pass your address on. Ask us to delete the thread and we will.
Whatever you put in that message is held on the same terms, including the signature block, the company you write from, and anything you attach. If you are sending something you would rather not have sitting in a mailbox, say so in the first line and we will agree on a better channel before you send the rest.
Client work
Anything gathered during a paid engagement falls under the agreement signed for that engagement, not under this policy. Nothing from a client environment appears in what we publish.
That last sentence is the one clients care about most, so it is worth being precise. Findings, hostnames, screenshots, log excerpts, and internal names from an engagement never appear in an article. Where a technique we learned on a job is worth writing about, it is rebuilt from nothing in our own lab and written up from that rebuild instead.
If you report a security issue
Reports about this site or our published work are welcome and we would rather hear about a problem than read about it later. A report is treated as correspondence under the section above, kept while it is being fixed, and kept afterwards as a record of what was fixed and when.
Tell us whether you want to be credited. We name reporters who ask to be named, stay quiet about those who do not, and never pass a reporter's details to anyone else.
Links to other sites
Articles here link out constantly, to advisories, vendor documentation, source repositories, and other people's research. Those sites have their own policies and their own trackers, and once you follow a link you are subject to theirs rather than ours. We do not vouch for any of them and we have no visibility into what they do.
Children
This site is written for working engineers and is not directed at children. We do not knowingly collect anything from a child, and since we collect nothing that identifies any reader at all, there is nothing about a young reader for us to hold either.
How this site is kept secure
Pages here are built ahead of time and served as static files, so there is no database of readers behind this site and no login form to attack. That is a deliberate choice as much as a technical one, because the safest record is the one that was never created.
No arrangement is perfect and we will not pretend otherwise. If something does go wrong in a way that affects people, we will say what happened, say what it touched, and say it in plain language rather than issue a statement engineered to sound smaller than it is.
Your rights
You can ask what we hold about you, ask for it to be corrected, or ask for it to be deleted. In practice that only ever concerns email you have sent us, since the analytics data cannot be traced back to a person. Write to the address above and we will handle it.
Depending on where you live, you may also have the right to object to processing, to ask that it be restricted, and to receive a copy of what we hold in a portable form. We do not charge for any of this and we do not require a particular form of words. A plain email describing what you want is enough.
We answer requests as quickly as we can and within thirty days at the outside. The one thing we may ask for is enough detail to be sure we are answering the right person, which in practice means writing from the address the correspondence is about. If we cannot do what you have asked because the law requires us to keep something, we will tell you which obligation is in the way instead of leaving the request unanswered.
If you are not satisfied with how we have handled it, you are entitled to complain to the data protection authority where you live. We would prefer you raised it with us first so we have a chance to fix it, but that preference is not a condition and it does not affect your right to go straight to a regulator.
Changes
If this policy changes, the date at the top of the page changes with it. There is no archive of earlier versions, so the text you are reading is always the one that applies.
Most changes will be small, because the underlying arrangement is small and we are not planning to make it bigger. If we ever start collecting something genuinely new, the change will be described here in the same plain terms as everything else rather than buried in a sentence engineered to be skipped.
Contact
Questions go to hello@egnworks.com. Egnworks works with engineering teams worldwide.