What public-page analytics record
When analytics are enabled, a public page can send its path, the hostname of an external referring site when available, and a random identifier created in this browser. Query strings and page fragments are removed. Private admin, member, API, sign-in, sign-up and sign-out routes are excluded.
How the browser identifier is protected
The backend converts the random browser identifier with keyed HMAC-SHA256 before storage. The raw identifier is not retained by the analytics database. IP addresses and user-agent strings are not stored as part of these page-view events.
Why the data is used
Private aggregate reports help evaluate readership, repeat visits, referring sites, research interest and whether readers return to outcome tracking. Individual reader identities are not shown in these reports, and analytics do not determine publication access or subscription entitlement.
Storage and retention
The browser stores the random identifier and your analytics preference in first-party local storage. A short session marker limits duplicate page views for the same path. The service currently retains server-side page-view records for aggregate measurement; a fixed deletion schedule has not yet been implemented. This notice will be updated when that changes.
Loading your browser preference…
Scope of this control
The control above stops new public-page analytics events from this browser. It does not delete earlier aggregate event records, account records you intentionally create, or operational and security records required to run the service. Clearing browser storage can also clear the saved preference.
Changes to this notice
This page will be revised when collection, reader controls or retention behavior materially changes. The explanation is intentionally limited to behavior the current implementation can support.