Last updated 2 August 2026
This page covers what is specific to this site. It sits under the tr3 Privacy Policy, which governs every tr3 site — this page adds detail and removes nothing promised there.
Hacker News Atlas (atlas.tr3.fyi) is an independently run, ad-free project. It does not assign a visitor or session ID or build person-level profiles. Its product analytics does not identify, profile, or follow individual visitors across visits.
Reading the site
- No cookies or accounts. Reading never requires a login, name, or email.
- No advertising, ad pixels, or cross-site tracking. Visitor data is not sold or shared for advertising.
- No visitor or session tracking. The site does not assign a visitor or session ID, fingerprint a device, or create a person-level visit history.
Cloudflare processes network information such as an IP address to deliver and protect the site under Cloudflare's privacy policy. The project's custom analytics never stores the address. For US page loads only, it may retain Cloudflare's two-letter state code in the separate state-only aggregate described below.
Aggregate product measurement
The site sends three kinds of first-party events: a page load, a fixed key action, and one terminal page summary. Cloudflare records when an accepted event reaches Analytics Engine. Categorical fields are limited to the current Atlas page family; one of four viewport bands; a locally classified arrival category; same-site previous page family; navigation, coarse input, reduced-motion, and service-worker states; fixed action, target, and outcome values; reached-section and feature masks; and broad visible-time and scroll-depth buckets, plus bounded page-load performance, resource, and error totals. The raw inbound referrer, hostname, path, and query never leave the browser. An absent referrer is labeled direct or unavailable, not assumed to be direct traffic.
A terminal summary can include these exact bounded numeric measurements:
- visible time, from 0 to 21,600,000 milliseconds; maximum scroll depth, from 0 to 100 percent; and interaction count, from 0 to 10,000;
- section reach as a bit mask (0–31 on the Paper or 0–15 in analytical Atlas workspaces), feature reach (0–65,535), available-vitals flags (0–31), runtime-capability flags (0–255), and a fixed funnel step (0–4, depending on the page);
- Largest Contentful Paint, Interaction to Next Paint, First Contentful Paint, and Time to First Byte, each from 0 to 120,000 milliseconds; Cumulative Layout Shift from 0 to 10;
- same-origin transfer and decoded size, each from 0 to 262,144 KiB; total long-task time from 0 to 21,600,000 milliseconds; resource and failed-resource counts from 0 to 10,000; and JavaScript error count from 0 to 1,000.
For a browser capability or measurement that is unavailable, the corresponding numeric
field is -1. No resource URL, error message, stack trace, or interaction text is
sent.
For a page-load request Cloudflare locates in the United States, the edge Worker may write one separate state-only row containing the analytics schema, the site name, and a validated two-letter state code; Analytics Engine also assigns the row a receipt timestamp. That row contains no page, content, action, browser, device, IP address, visitor or session identifier, city, metro area, postal code, coordinates, or inferred home or work location. It is reported only in state-level groups of at least 10 page loads and is never joined to product events in the dashboard. A VPN or corporate gateway reads as its exit state, not a home location. No subdivision is stored for traffic outside the United States.
The measurement rejects free-form labels and contains no cookie or browser-storage value, name, email, user or session ID, device fingerprint, raw URL or query, raw referrer, IP address, user-agent string, search term, story ID, note, saved view, imported workspace content, error message, or stack trace. Page-load categories are not linked into a visit history and are not used to identify a person, diagnose an accessibility need, or target content or advertising.
Global Privacy Control and Do Not Track disable measurement before the browser installs an observer or listener. Fixed, privacy-safe edge rate limits protect the write-only endpoint without creating an IP-, visitor-, session-, or device-based key. Cloudflare applies those counters per edge location and describes them as permissive rather than exact. A separate fixed-name daily counter stores only one aggregate integer and stops accepting analytics data points after 90,000 in a UTC day; it stores no request or event details. Cloudflare Analytics Engine retains accepted product-use and state-only rows for up to three months. The public Worker can only write events and exposes no analytics read route.
The maintainer can query aggregate events only through a private password-gated dashboard or a loopback-only process, using an account-scoped Cloudflare read token that is never sent to public browser code. When the local tool's optional ideas view is enabled, it fetches the authenticated suggestion export into memory and sends only aggregate themes, counts, and sanitized topic examples to the local browser; it does not create a second raw suggestion file. No visitor or session identifier or person-level history exists in those reports.
What stays on your device
Atlas does not store notes, workspaces, preferences, or identifiers in local or session storage. Its service worker may keep copies of public pages, scripts, styles, and requested public data in the browser cache so the installed site can reopen offline. Browser settings can remove that cache at any time. A shared-view URL can contain selected display state, but Atlas does not send that URL through product analytics.
The suggestion form
A suggestion stores the idea, optional category, optional detail, and submission time for up to 180 days, without an account, contact field, or network identifier attached. Free-form idea and detail fields can identify you if you write identifying information into them. Do not submit passwords, financial or health information, identity documents, private keys, or other sensitive personal content.
If you add a name or email because you want a reply, those contact fields and the suggestion text are relayed through Resend to the maintainer's inbox. They are not stored in the suggestion database or added to a mailing list, but Resend and the maintainer's email provider process the delivered message under their own policies.
The form uses a honeypot and Cloudflare Turnstile to limit spam. A secret-keyed, one-way HMAC-SHA-256 rate key derived from the network address may be held with an abuse counter for at most one hour. The raw address is not stored by the form relay, and the rate key is not attached to submitted content.
The contact form
The contact form relays your optional name, email address, subject, and message to the maintainer's inbox through Resend so they can reply. It is not published or added to a mailing list. The site's suggestion database does not retain a copy, but Resend and the maintainer's email provider process the delivered message under their own policies. Do not use the form for sensitive personal content.
The published data
The charts are aggregate statistics computed from public Hacker News data (Y Combinator's official API and public datasets). They describe Hacker News activity in aggregate; they are not about site visitors.
Your California privacy rights (CCPA/CPRA)
The project does not sell or share personal information, including for cross-context behavioral advertising. You may ask about access, correction, deletion, or portability by using the contact form. The project will honor rights that apply to records it can reasonably locate. Because aggregate events and stored suggestions contain no account or contact identifier, the maintainer may be unable to connect one of those records to you; the project will not collect extra identity data merely to make that connection. You will not be discriminated against for making a privacy request.
Changes
Material changes are dated here and noted in the changelog before they take effect. Questions: use the contact form.