What this site records
This site measures how automated clients read the web, and the measurement is the server record. So it records every request that reaches it — including yours, if you are reading this in a browser.
That is unusual enough to state plainly rather than bury.
What is recorded
For every request: the time, the method and path, the response status and size, how long it took, the connecting address, the country that address resolves to, and the request headers — user agent, accepted languages and encodings, referer.
The connecting address is personal data. It is recorded because it is the only thing that distinguishes one caller from another, and almost every measurement here depends on that distinction — whether one client took many paths, whether many addresses shared one identity, whether an address falls inside a range a vendor publishes for its crawler.
What is not recorded, and what stopped being recorded
This site sets no cookies, runs no analytics, has no login, no form, no newsletter and no list. Nothing here tracks anyone between visits.
It did, however, store request headers exactly as they arrived, and on 28 July 2026 that record was found to contain 520 Cookie values carrying a persistent per-visitor identifier — sent by clients, kept by the capture because it had been written to keep everything. Nothing on this site had ever read one, and no published figure was computed from one.
The capture now replaces the value of Cookie, Set-Cookie, Authorization and Proxy-Authorization with [redacted] before storing. The header name is kept, because which headers a client sends is part of how it behaves and is one of the things this site exists to measure. What the value contains is not ours.
How long it is kept
Indefinitely, and this deserves the same plainness. The record is append-only and is never edited, because a measurement that can be revised afterwards is not a measurement. Findings published months apart are recomputed against the same record, and that only works if the record is still there.
Backups are kept for 30 days.
What is published
Aggregates, and the queries that produced them. Not the log.
As of this writing, one connecting address appears anywhere in a published finding: an address that ran an automated scan against this site. No address belonging to an ordinary visitor has been published, and the addresses listed on the verification page are ranges the vendors publish themselves for their own crawlers.
The operator console, which does show full addresses, runs on the loopback interface and is not routed through the tunnel that serves this site. It is not reachable from the internet.
Requests triggered by a person
When someone asks an assistant to open a page here, the request arrives from that vendor's cloud infrastructure, not from the person. Their address never reaches this server, so there is nothing here to identify them by.
Asking for something to be removed or corrected
Write, and say which. A request to remove an address from the record, a request to correct a figure, and a request to correct a sentence are three different things and get three different answers.
A correction that lands is published as a correction, dated, rather than folded silently into an edit. The findings already carry withdrawn conclusions and rejected ones with the reason kept beside each, and this page carries the cookie mistake for the same reason.
There is no address here yet. Saying so is better than printing one that receives nothing, and a page about what this site records is the wrong place to start being approximate. Until one is published, a removal or correction request has nowhere to go — which is a real gap, stated rather than papered over.
Who runs this
An independent operator in Türkiye, which is the jurisdiction whose data protection law applies here. It is not a company, sells nothing, takes no payment, and runs no advertising.