Privacy Policy

What We Collect

When you submit content through our forms (writings, listings, boost messages), we collect the name, email address, and Lightning address you provide. That data is stored until reviewed by the crew and is used solely for managing submissions and tipping authors.

Your theme preference (light/dark mode) and any playback state are saved in your browser’s localStorage. None of that data leaves your device.

Counting Pages, Not People

We count how many times each page is read, and which sites send people here. That is the whole of it.

When you open a page, our own web server notes two things about the request it just answered: the path of the page, and the hostname of the site you came from, if any. It adds one to a counter and forgets the request. No third party is involved, and no script runs in your browser to do it. The counter is code we wrote, running on the same machine as the site.

We do not store your IP address. It is used at the moment your page loads, for two things, and then discarded: to work out which country the view came from, and to make a daily code so we can tell 500 pages read by 50 people from 500 read by one. That code is your address and browser scrambled together with a secret that changes every day and is deleted two days later. Once it is gone, the code cannot be traced back to you, tested against an address, or matched with the next day’s.

Because the secret changes daily, we cannot follow you from one day to the next. Visit on Monday and again on Friday and we count two visitors. We have no way of knowing it was the same person, and we would rather have a rougher number than the ability to find out.

Your country is worked out on our own server from an offline list of address ranges. Your address is never sent to a geolocation service, or anywhere else.

The counter never sees the query string or the fragment of the page you are on, and the referring link is reduced to the site’s name before it leaves the web server. The rest of the link is never written down.

Do Not Track and Global Privacy Control

We count these visits, and we think you should know exactly why rather than find out from a changelog.

Both signals are browser-wide defaults. Brave sends Global Privacy Control on every site you visit, whoever runs it. So the signal says something about your browser, not about us, and treating it as a decision about this site would mean guessing at an intention nobody expressed here.

What it would suppress is also nothing about you. The whole record of your visit is a path, the name of the site you came from, and a key made from a network prefix thousands of people share, which stops being computable in two days. There is no profile to build, nothing to sell, and nothing anyone could ask us to hand over.

So a visit from a browser sending either signal is counted the same as any other, and we count separately how many did — because on a site like this one that is a genuinely interesting number, not a shortfall.

If you would rather not be counted here

That is a decision about this site, and we do honour it. Set a cookie named ugmf_analytics to 0 on this domain and nothing is recorded at all: no page view, no country, no visitor key, no tally. The request is dropped at the web server before any of it exists.

No Cookies, No Tracking Scripts, No Fingerprinting

This site sets no cookies. We use localStorage and sessionStorage for client-side preferences only, and those never leave your device.

We run no third-party analytics, no advertising or tracking pixels, and no fingerprinting. Counting happens on our web server, so no analytics script runs in your browser at all. Every script on this site is served from this domain. We do not measure how long you stayed, how far you scrolled, or what you moved your mouse over. We do not track you across other sites, because we hold nothing that could identify you on one.

When you search this site, the words you type are sent to our server, because the search runs there against our transcripts. They are used to run that search and are not stored, not written to our logs, and not associated with you.

Things Your Browser Talks To

Some parts of this site connect your browser to services other than ours. We would rather say so plainly than leave you to find out from your network tab.

Nostr relays. The home page shows a live Nostr feed, which your browser fetches directly from the public relays relay.damus.io, relay.primal.net, nos.lol and relay.nostr.band. Those relays see your IP address, as they would if you opened any Nostr client. No other page on this site connects to them.

BTCPay Server. The donate and boost widgets load a payment modal from btcpay.ungovernablemisfits.com, which is our own server, self-hosted by us. It is loaded only on pages with a payment widget.

Episode audio. Press play on an episode here and the audio is fetched through the same chain of addresses our RSS feed uses: OP3, then Podtrac and Podhome, who host and serve the file. Each of them sees your IP address for that request, exactly as they would if you played the episode in a podcast app. Nothing is fetched until you press play, and a play on this site is counted as a download the same way an app’s would be.

Nostr Data

Any Nostr content displayed on this site is public data pulled from public relays. We don’t store it, modify it, or associate it with your identity.

Podcast Downloads

Our RSS feed is prefixed with OP3, an open-source and publicly auditable download analytics service. When your podcast app fetches an episode, OP3 counts the request and passes it on to the file. We read those counts back as totals per episode, along with the app, device type and country. OP3 also makes an audience identifier and a hashed IP address available; we store neither, and we never join download numbers to anything else on this site. OP3 publishes how it counts.

Payments

Bitcoin and Lightning payments are processed through BTCPay Server. We never see or store your payment credentials. BTCPay Server is self-hosted and does not share transaction data with third parties.

Server Logs

We do not log successful page requests. Our web server records an IP address only when a request goes wrong — a page that does not exist, a malformed request, a bot probing for something — in an error log that rotates and is overwritten. We do not read it for anything but faults, and nothing is derived from it.

Data Retention

Form submissions are stored until reviewed and either published or deleted.

Page view counts are totals with nothing personal in them, and we keep them. The daily codes described above are deleted after two days, along with the secrets that made them. We do not sell, share, or hand over your data to anyone. Period.

Contact

Got questions? Reach out via Nostr or X / Twitter.

Attribution: IP-to-country data by DB-IP, used offline under CC BY 4.0.

Last updated: August 2026