Hacker News Insights

Privacy Policy

Last updated 25 July 2026

Hacker News Insights is an independently run, ad-free project. It does not identify, profile, or follow individual visitors.

Reading the site

Cloudflare processes network information such as an IP address to deliver and protect the site under Cloudflare's privacy policy. The project's custom analytics does not copy that information into its product-usage dataset.

Aggregate product measurement

The site uses first-party aggregate product measurement to learn which content and tools are useful, where readers encounter friction, and how the experience performs. The contract permits only fixed, low-cardinality categories: page family; an approved research-topic slug or calendar year; broad viewport; a locally classified arrival category; same-site previous page family; navigation, coarse input, reduced-motion, and service-worker states; section and feature reach; fixed action outcomes; broad visible-time and scroll-depth buckets; and bounded page-load performance, resource, and error totals. The raw inbound referrer, hostname, path, and query never leave the browser. An absent referrer is labeled direct or unavailable, not assumed to be direct traffic.

The measurement rejects free-form labels and contains no cookie or browser-storage value, name, email, user or session ID, device fingerprint, raw URL or query, raw referrer, IP address, user-agent string, search term, story ID, note, saved view, imported workspace content, error message, or stack trace. Page-load categories are not linked into a visit history and are not used to identify a person, diagnose an accessibility need, or target content or advertising.

Global Privacy Control and Do Not Track disable measurement before the browser installs an observer or listener. Fixed, privacy-safe edge rate limits protect the write-only endpoint without creating an IP-, visitor-, session-, or device-based key. Cloudflare applies those counters per edge location and describes them as permissive rather than exact. A separate fixed-name daily counter stores only one aggregate integer and stops accepting product events after 90,000 in a UTC day; it stores no request or event details. Cloudflare Analytics Engine retains accepted product-use events for up to three months. The public Worker can only write events and exposes no analytics read route. The maintainer can generate aggregate reports only by running a local report with an account-scoped Cloudflare read token; that token is never sent to public browser code. No visitor or session identifier or person-level history exists in those reports.

What stays on your device

The dashboard uses browser storage for device-only conveniences: last-seen and dismissed-alert markers, display density and accessibility preferences, saved views, comparison pins, private card notes, and a one-tab shortcut that moves focus to Explorer search. These values remain on your device and are not sent to the site. A saved workspace leaves the device only when you explicitly export it as a file. Browser settings can clear them at any time.

The suggestion form

A suggestion stores the idea, optional category, and optional detail anonymously for up to 180 days. No name, email, or raw IP address is attached to that stored suggestion. If you add a name or email because you want a reply, it is relayed to the maintainer's inbox and is not stored with the suggestion or added to a mailing list.

The form uses a honeypot and Cloudflare Turnstile to limit spam. A one-way SHA-256 network-address digest may be held with an abuse counter for at most one hour; the raw address is not stored by the form relay and the digest is not attached to submitted content.

The contact form

The contact form relays your optional name, email address, subject, and message to the maintainer's inbox so they can reply. It is not published, added to a mailing list, or used for another purpose. The site does not retain a separate copy after relay; the delivered message remains in the maintainer's email provider under that provider's policy.

The published data

The charts are aggregate statistics computed from public Hacker News data (Y Combinator's official API and public datasets). They describe Hacker News activity in aggregate; they are not about site visitors.

Your California privacy rights (CCPA/CPRA)

The project does not sell or share personal information, including for cross-context behavioral advertising. Personal information is limited to what you voluntarily submit in a form, plus the short-lived one-way abuse-control digest described above. You may request access, correction, deletion, or portability without discrimination by using the contact form. Aggregate product categories contain no personal identifier and are not used to create an individual profile.

Changes

Material changes are dated here and noted in the changelog before they take effect. Questions: use the contact form.