Privacy
Pixeloom is a picture you look at. There is no account, no cookie and no advertising network in it, and the little we do record is written down below in full.
The short version. Looking at the mosaic sets no cookies and needs no account. We count views and clicks so the board has honest numbers, and we store a one-way hash of your IP address rather than the address itself. Those rows are deleted after 90 days; only per-day totals for each advertiser outlive them. If you register a website, we keep what you typed into the form — name, address, category, your logo and an email if you gave one — for as long as your listing exists.
What we record when you look at the mosaic
When the artwork finishes loading, your browser sends us one short message saying it did. It sends a second one if you click a tile. Each message writes a single row, which holds:
- whether it was a view or a click, and which day's artwork it belongs to;
- for a click, which advertiser's tile was clicked;
- a coarse region — one of about a dozen groups such as WEST_EUROPE or EAST_ASIA, worked out from your browser's language header. It is not a city, a country or a coordinate;
- a SHA-256 hash of the IP address the request came from.
We do not claim that hash is anonymous. An IP address is short enough that anyone holding both a hash and a candidate address can test one against the other, so a hash is a pseudonym, not a disguise. It means we cannot read an address back out of our own database, and that we never store the address in the analytics table — nothing stronger than that. We treat these rows as personal data and describe them here for that reason.
We also keep one counter per day and region in our cache, so the ticker under the artwork can say how many people looked at it. To count people rather than page loads, your browser makes up a random number for the tab you are in and includes it with that message. It is kept in session storage, which means it is gone when you close the tab, it is never sent to us on its own the way a cookie would be, and it has nothing whatsoever attached to it — no name, no history, no link to any other day. The counter itself keeps no list of those numbers, only a tally, and expires after seven days.
We also drop these messages when they come from something that identifies itself as a bot or a crawler, and one address can only add so many clicks to one tile in a day. That is there to keep an advertiser's numbers honest, not to identify anybody.
Abuse counters
To stop one person flooding the board with junk listings, we count requests per address: how many times a form has been submitted in the last hour, and how many sites have been registered from that address today. These counters live in our cache, are keyed on the same SHA-256 hash described above rather than on the address itself, and expire on their own — within the hour for the first, within a day for the second. They hold a number and nothing else: no record of what was submitted, and no way to list what an address has done.
No cookies, no accounts, no third-party trackers
The public pages set no cookies at all, so there is no consent banner to click away. The per-tab number described above is the only thing we put on your device, and it does not survive the tab being closed. We run no analytics product, no advertising pixel and no session recorder — the counting is ours, it stays on our own servers, and nothing follows you from this site to another one.
Two things that do leave our server
- Fonts. The typefaces are loaded from Google Fonts, which means your browser makes a request to fonts.googleapis.com and fonts.gstatic.com. Google receives your IP address and user-agent in the ordinary way any web request discloses them. If that matters to you, a font-blocking extension leaves the site fully usable — it falls back to your system typeface.
- Web server logs. Our server writes ordinary request logs, and those do contain the raw IP address for a short period. They exist to debug faults and to spot abuse, they are not joined to the analytics table, and they are not used to build any profile.
Clicking a tile opens that advertiser's own website in a new tab, directly, with no ad network and no redirect in between. What that site then does is governed by its own privacy policy, not this one.
What we store if you register a website
Registration is a form, and we keep what the form asks for:
- the site's name, address and category;
- your logo image, if you upload one — trimmed and re-encoded, then stored by us;
- an email address, if you give one — it is optional, and it is how we reach you about your listing;
- the tier and duration you chose, and the dates your listing runs;
- counts of views and clicks on your own tile.
Those counts are shown back to you on a private report page, at a link we send when your listing is approved. The link itself is the only key to it — there is no password — so anyone you forward it to can read the same numbers. It shows how many people saw each day's artwork your tile was in, and how many clicked through to your site. It never shows who they were, because we do not know.
The name, the link, the category and the logo are published — that is the point of a listing, and they appear on the tile and in its tooltip. Your email address is not published and is not shown to other advertisers. It goes to our mail provider when we write to you, and it appears in the private notice we get when you register, described below.
We use it for one thing: writing to you about your own listing — that it was approved or declined, that it is about to expire, or to answer something you asked us. There is no newsletter and no marketing list.
How long we keep things
- Your listing — for as long as it runs, and afterwards as part of the record of which mosaics it appeared in. Ask us and we will delete it.
- View and click rows — 90 days, then deleted automatically by a nightly job. They carry no name and no email; the hash is the only identifier in them, and deleting the row deletes the hash with it.
- Per-day totals for each advertiser — kept indefinitely, because they are what makes an old mosaic's numbers true after the rows behind them are gone. They are counts and nothing else: a date, an advertiser, and how many times each thing happened. There is no identifier of any kind in them.
- The viewer counter — seven days, then it expires by itself.
- Abuse counters — an hour, or a day, then they expire by themselves.
- Server logs — rotated in the ordinary way and not retained long-term.
Where it lives, and who can see it
Everything sits in our own PostgreSQL database and Redis cache, on servers we run. There is no third-party data warehouse and no analytics vendor. Access is limited to the people operating Pixeloom.
When we email you, the message passes through whichever mail provider we have configured for outbound SMTP; they handle it to deliver it, in the same way any mail provider does. We do not sell, rent or trade personal data — not the advertiser table, and not the event table.
Registering, and every later change to your listing's status, also posts a short notice to the private chat the people running Pixeloom use to keep track of submissions. It carries the site's name, address, category and plan — the same details that appear on your tile once the listing is approved — and, if you gave one, your email address, so we can reply to you about the listing. The notice travels through Telegram, which handles it to deliver it. It goes to us and nobody else; it is not a public channel.
We will hand over data if we are legally required to. If that ever happens and we are permitted to tell you, we will.
What you can ask for
Write to [email protected] and we will act on any of these:
- a copy of what we hold about your listing;
- a correction — a wrong link, a stale logo, a changed category;
- deletion of your listing and its details;
- deletion of event rows: tell us the IP address you used and roughly when, and we can find and remove the matching rows — we cannot search by hash alone without the address to hash. Anything older than 90 days has already gone by itself.
We do not require you to prove an identity you never gave us in the first place. For a listing, a request from the email on file, or from an address at the domain itself, is what we act on.
Children
Pixeloom is not directed at children, and registering a website is something a business or a site owner does. We do not knowingly collect anything from a child.
Changes
If what we collect changes, this page changes with it and the date below moves. Material changes — new categories of data, a new recipient — will be said plainly here rather than buried in a revision.
Contact
Privacy questions go to [email protected], the same address as everything else. The contact page says what else that inbox is for, and the terms cover the rules of a listing.