Privacy Policy
Our Site
Rather than a policy about how we're going to protect the data
we gather about you, we've got a simpler plan: We'll try as
hard as we can to <em>not</em> gather data about you.
We'd also like to help you defuse and poison other tracking
services.
Log Data
We log HTTP requests in order to help maintain our site - fix
broken links, block spammers, and so on. These logs look like
- - [03/Sep/2014:13:45:06 +0000] "GET /heroik/heroik.html HTTP/1.1" 200 1616 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:32.0) Gecko/20100101 Firefox/32.0"
They contain your IP, the URL you visited, when you visited
it, what browser you were using, and (sometimes) where you
came from. Your browser sends this to every site you visit. If
you think it's too much information, most browsers have some
way to send less - for example, in Firefox you can
set <code>network.http.sendRefererHeader</code> to
<code>false</code> and install <a href="">User Agent Switcher</a>.
Mail
We host our own email service. Email sent to
<a href="">does not go through GMail on our end</a>.
We don't use cookies or anything like cookies to track you.
56 </p>
We use cookies to prevent request forgery. These don't contain
any identifying information. These <a href="">double-submit cookies</a>,
are random cookies that reset each time you visit the page.
This prevents another site from tricking you into submitting
data to our site, because they can't read the random value in
the cookie.
64 </p>
For long-term data storage we use HTML5
<a href="">localStorage</a>
and other similar <em>client-side storage</em>. This gives you
the benefits of cookies, but your data is never sent to the
server, so there's nothing to secure.
71 </p>
We don't track any personal data via this site, so we have no
special databases to secure.
76 </p>
Our primary site, which you are reading now, is served
exclusively via HTTPS. We would like to offer HTTPS for all
our subdomains, but the CA racket means we can't afford it. In
the future we hope CAs are replaced by something like
<a href="">Convergence</a> so cheap
security is available for everyone, but right now it doesn't
work reliably.
85 </p>
Because this is the web, we link to other sites. Some of our
games are only available from other sites, because trading
money for games requires handling at least a little personal
data. We'd rather that be done by people good at doing it.
92 </p>
Most of these sites don't care about your privacy. Sometimes
at least they'll be providing you a useful service in exchange
for surveilling you, but usually they're willing to sell you
out to a dozen firms via Google in exchange for a pretty bar
graph.
99 </p>
We think it's awful, too. Sorry.
102 </p>
To protect yourself on these sites, we recommend you use tools
to help you browse the web safely and securely. One easy and
reliable one is
<a href="">Disconnect</a>.
<a href="">PRISM Break has more suggestions</a>,
though it's unfortunately-named because this problem <a href="">neither
begins nor ends with the PRISM program or state surveillance</a>.
111 </p>
Other Stuff We Don't Do That You Should Push Other Sites To
Also Not Do
We don't run Google Analytics or Cloudfront Analytics or
Cloudflare Clicky or any of that garbage. Even if a site
needs to collect data for its own operation, these services
also feed that data into even larger and more troubling
corporate databases.
We don't use Google's fonts; we host them ourselves. <a href="">Most
Wordpress sites are helping Google track their readers and
they don't even know it.</a> At
the very least, demand a cut of Google's revenue if you're
going to work for them.
We don't put stock "share" buttons on our site. Aside from
being useless eyesores <a href="">these
buttons are used by social media companies to track you on
other sites</a>. Tools like <a href="">EFF's Privacy Badger</a> and <a href="">Disconnect</a> can
help block these on other sites.
We don't minify or obfuscate most files &mdash; HTML, CSS,
or JavaScript &mdash; we serve. This means it's easy for you
to check what we're doing with just your browser.
We may update this Privacy Policy from time to time. Since
this document is <a href=";a=history;f=privacy.html">stored in our site's Git repository</a>, you can easily track these changes.
148 </p>
