Hacker News Atlas

Privacy Policy

Last updated 26 July 2026

Hacker News Atlas (atlas.tr3.fyi) is an independently run, ad-free project. It does not assign a visitor or session ID or build person-level profiles. Its product analytics does not identify, profile, or follow individual visitors across visits.

Reading the site

Cloudflare processes network information such as an IP address to deliver and protect the site under Cloudflare's privacy policy. The project's custom analytics does not copy that information into its product-usage dataset.

Aggregate product measurement

The site sends three kinds of first-party events: a page load, a fixed key action, and one terminal page summary. Cloudflare records when an accepted event reaches Analytics Engine. Categorical fields are limited to page family; an approved research-topic slug or calendar year; one of four viewport bands; a locally classified arrival category; same-site previous page family; navigation, coarse input, reduced-motion, and service-worker states; fixed action, target, and outcome values; reached-section and feature masks; and broad visible-time and scroll-depth buckets, plus bounded page-load performance, resource, and error totals. The raw inbound referrer, hostname, path, and query never leave the browser. An absent referrer is labeled direct or unavailable, not assumed to be direct traffic.

A terminal summary can include these exact bounded numeric measurements:

For a browser capability or measurement that is unavailable, the corresponding numeric field is -1. No resource URL, error message, stack trace, or interaction text is sent.

The measurement rejects free-form labels and contains no cookie or browser-storage value, name, email, user or session ID, device fingerprint, raw URL or query, raw referrer, IP address, user-agent string, search term, story ID, note, saved view, imported workspace content, error message, or stack trace. Page-load categories are not linked into a visit history and are not used to identify a person, diagnose an accessibility need, or target content or advertising.

Global Privacy Control and Do Not Track disable measurement before the browser installs an observer or listener. Fixed, privacy-safe edge rate limits protect the write-only endpoint without creating an IP-, visitor-, session-, or device-based key. Cloudflare applies those counters per edge location and describes them as permissive rather than exact. A separate fixed-name daily counter stores only one aggregate integer and stops accepting product events after 90,000 in a UTC day; it stores no request or event details. Cloudflare Analytics Engine retains accepted product-use events for up to three months. The public Worker can only write events and exposes no analytics read route.

The maintainer can query aggregate events only from a private process on their own computer, using an account-scoped Cloudflare read token that is never sent to public browser code. The live operator dashboard binds only to 127.0.0.1. When its optional ideas view is enabled, that local process fetches the authenticated suggestion export into memory and sends only aggregate themes, counts, and sanitized topic examples to the local browser; it does not create a second raw suggestion file. No visitor or session identifier or person-level history exists in those reports.

What stays on your device

The dashboard uses browser storage for device-only conveniences: last-seen and dismissed-alert markers, display density and accessibility preferences, saved views, comparison pins, private card notes, and a one-tab shortcut that moves focus to Explorer search. These values remain on your device and are not sent to the site. A saved workspace leaves the device only when you explicitly export it as a file. Browser settings can clear them at any time.

The suggestion form

A suggestion stores the idea, optional category, optional detail, and submission time for up to 180 days, without an account, contact field, or network identifier attached. Free-form idea and detail fields can identify you if you write identifying information into them. Do not submit passwords, financial or health information, identity documents, private keys, or other sensitive personal content.

If you add a name or email because you want a reply, those contact fields and the suggestion text are relayed through Resend to the maintainer's inbox. They are not stored in the suggestion database or added to a mailing list, but Resend and the maintainer's email provider process the delivered message under their own policies.

The form uses a honeypot and Cloudflare Turnstile to limit spam. A secret-keyed, one-way HMAC-SHA-256 rate key derived from the network address may be held with an abuse counter for at most one hour. The raw address is not stored by the form relay, and the rate key is not attached to submitted content.

The contact form

The contact form relays your optional name, email address, subject, and message to the maintainer's inbox through Resend so they can reply. It is not published or added to a mailing list. The site's suggestion database does not retain a copy, but Resend and the maintainer's email provider process the delivered message under their own policies. Do not use the form for sensitive personal content.

The published data

The charts are aggregate statistics computed from public Hacker News data (Y Combinator's official API and public datasets). They describe Hacker News activity in aggregate; they are not about site visitors.

Your California privacy rights (CCPA/CPRA)

The project does not sell or share personal information, including for cross-context behavioral advertising. You may ask about access, correction, deletion, or portability by using the contact form. The project will honor rights that apply to records it can reasonably locate. Because aggregate events and stored suggestions contain no account or contact identifier, the maintainer may be unable to connect one of those records to you; the project will not collect extra identity data merely to make that connection. You will not be discriminated against for making a privacy request.

Changes

Material changes are dated here and noted in the changelog before they take effect. Questions: use the contact form.