Method
How we count
Every figure on the statistics page is a count of rows in our own database. Nothing is sampled, estimated or extrapolated, and nothing is measured by anyone but us.
What a visitor is
A visitor is one HMAC-SHA256 hash of the IP address and the browser's user agent together, salted with a secret that only this server holds. Neither the address nor the user agent is written anywhere: they are inputs to a one-way function and are discarded the moment it has run.
The user agent is part of it because an address is not a person. Behind a mobile carrier an entire city can share one address, and counting that as a single visitor would understate the audience by orders of magnitude. Nothing is written to your browser to make this work — no cookie, no local storage, no identifier of any kind.
Unique visitors counts those hashes once a day and adds the days up, which is what every analytics product publishes under that word — the identity behind theirs is rebuilt every twenty-four hours and cannot see across one. Somebody who reads this site in August and again in September is two, on that definition and on ours.
Visits · 7 days counts sittings rather than people: a run of pages by one visitor, ended by thirty minutes of silence. Three entries read in one go are one visit; the same person back in the evening is a second.
The stricter figure — every hash counted once and once only, whatever the gap — is calculated too and is never published. It is the floor the number above is checked against, so the published one cannot drift away from it unnoticed.
What a page view is
One page served to a person, refreshes included. Three things that look like page views are deliberately excluded, because each of them would count a page nobody read:
- Redirects. A link written with a trailing slash produces a redirect and then the real request. That is one page read, not two.
- Prefetches. The browser fetches a page when the pointer settles on a link, so the click that follows is instant. If the click never comes, nobody read it.
- Requests that render nothing. An uptime check asks for the headers and no page.
Known bots and error responses are recorded and then left out of every published figure. They are recorded rather than dropped because "how much of that spike was a crawler" is a question only rows that exist can answer.
What a prompt copy is
One press of a copy button or an open-in-agent link on an entry's page. It counts the action, not the person: somebody who copies a prompt and then opens it in an agent counts twice, because both are things they did.
Sponsor slots
A card impression is a slot that reached the screen, not a page that happened to contain one. A rail below the fold that nobody scrolled to was never seen, and a sponsor billed for it would be billed for nothing. Each frame counts for itself, once per page, so a page where five slots came into view is five impressions and a slot that never arrived is none.
The same is recorded for clicks, and for how long each card was actually on screen — the measure that says whether anybody had time to read it, rather than only that it appeared. All three are counted per slot, so what a particular sponsor's card did is a question with an answer rather than a share of a total.
A sponsorship is measured for the whole of its run and the record is kept afterwards. If a slot is sold, emptied and sold again, the second run starts from zero and the first one's figures never move — even if the same sponsor comes back under the same name.
What is never collected
No raw IP address. No raw user agent. No cookie, no local storage, no browser fingerprint. No third-party analytics script, no advertising pixel, and no request to any other company's server — there is no other company involved. Nothing collected here is shared, sold or sent anywhere.
The country is resolved from a database file sitting on this server — DB-IP's free IP-to-Country Lite, used under CC BY 4.0. No geolocation service is ever contacted, and the address itself is still never stored. Nothing finer than the country is worked out: no region, no city, no coordinates.
One thing here is written by us rather than about you. A link we post somewhere can carry a tag saying where we posted it — utm_source=reddit and the like — and that tag is recorded with the visit, because browsers increasingly send no referrer at all and it is the only way left to know which of our own posts brought somebody here. It describes our link, not you.
Why the numbers can be trusted
The tables these figures come from are append-only, and that is enforced by the database itself: an attempt to change or delete a recorded event fails outright rather than quietly succeeding. A wrong value is corrected by recording a correction, which leaves both the mistake and the fix in the record.
Days are UTC days everywhere, so a figure labelled "today" means the same thing wherever it is read.
What is measured but not published
More is recorded than is shown: which pages are read and for how long, which searches found nothing, which entries have their prompt copied. A signal that is not captured on the first day starts from zero the day somebody thinks to capture it, and a missing year cannot be bought back later.
The statistics page publishes the part that is worth reading today. The rest stays on the server, and more of it appears there as there gets to be enough history to make it mean something.
Two of the published figures are also served as data, at /api/public-stats: the total number of pages this site has served and how the catalogue splits across the three verdicts. Both are already on the home page. Nothing about a reader is in it, and nothing that is not already public will ever be added to it.

