boxscore/security

Privacy

Short version: reading this site is anonymous. If you later subscribe or declare a stack, we store the minimum needed and never sell or share it. This policy describes both today's behavior and what changes when those features go live.

Who is responsible

boxscore/security is a personal project operated by Ron Diver. For any privacy question or request, email rondiver@gmail.com.

Reading the site

We carry no advertising trackers, set no cookies, and never build profiles of individual readers. We measure readership in two ways, both cookieless:

First-party pixel. Each page loads a 1x1 image that records the page path and a daily-rotating anonymous identifier derived from your IP address and user-agent. That identifier is used transiently, in memory, to estimate unique visitors for the day and is never itself stored — we keep only daily aggregate counts (views, estimated visitors, page paths), which are public at /api/stats/. Counters live in a managed Redis store (Upstash) on Vercel's infrastructure.

Vercel Web Analytics. Each page also loads one small script from Vercel, our host, served from this site's own domain. For each view it records the page and any filtered query parameters, the referring page, approximate location derived from your IP address (country, region, city), and your browser, operating system, and device type. It uses no cookies; Vercel distinguishes visitors with a hash of the incoming request that is discarded after 24 hours, and we see only aggregate numbers in Vercel's dashboard. The site works fully without JavaScript; if you disable it or block the script, this measurement simply doesn't happen. See Vercel's Web Analytics privacy policy.

As with any website, Vercel also processes standard technical request data such as IP address and user-agent to serve pages and protect the service.

Email subscriptions (not yet active)

When email is enabled: subscribing is double opt-in — we email you a confirmation link and send nothing until you confirm. We store your email address and a random token used to sign your unsubscribe and preference links; there are no passwords. Every email carries a one-click unsubscribe. You can delete your subscription at any time, which hard-deletes your row.

Follow your stack (not yet active)

If you tell us which software you run, we store package, vendor, and product names only — never version numbers, because versions would make a breach materially more dangerous and are not needed to match disclosures. Uploaded lockfiles or SBOMs are parsed in memory and discarded immediately; the files themselves are never written to disk or retained. Your stack is never shared, sold, or exposed to anyone. One click deletes your entire stack and account.

Third parties

Hosting and Web Analytics are provided by Vercel; email delivery, when enabled, by Postmark. The public data sources this site reports on (NIST/NVD, CISA, FIRST, the CVE Program, OSV) are sources we read from — we never send your personal data to them or to anyone else.

Your choices

You can ask what we hold about you, correct it, or have it deleted by emailing rondiver@gmail.com. The site is not directed at children. If this policy changes, the updated version is posted here. Last updated 29 September 2026.