INSTITUTE DOCUMENT · 03
Privacy
Voting requires no account, no name and no email address. It does not require nothing at all, and this page describes the difference precisely.
Position
Would You Goon? is designed to collect as little as the research permits. It would be convenient to state that the site collects no data whatsoever. That claim would be false: assessments, reactions, anonymous identifiers and basic security information are all data.
What is true is narrower, and is set out below.
No account is required
- No public account is required to participate.
- No name is required to vote.
- No email address is required to vote.
- There is no public identity, profile, username or follower system.
- There are no comments and no free-text submissions.
The anonymous session identifier
On first visit the server issues an opaque, randomly generated identifier and stores it in a first-party cookie named wyg_session. The cookie is HttpOnly, SameSite Lax, Secure, and expires after one year.
The identifier contains no personal information. It exists so that one visitor holds one current assessment per subject and can revise it, which is a requirement of the statistics rather than a means of recognising anyone.
Clearing browser storage discards the identifier. Assessments already recorded remain in the dataset, and the browser begins a new anonymous identity. This limitation is accepted deliberately.
What is recorded
Against an anonymous session identifier, the Institute stores:
- the assessment score for a subject, and the time it was given or revised;
- emoji reactions added to a subject;
- subjects skipped;
- the fact that a share action occurred, and through which channel.
The Institute's database records no IP address, no user-agent string and no browser fingerprint against assessments or sessions.
That statement concerns this application's own records. It is not a claim that no such information exists anywhere: hosting and content-delivery infrastructure necessarily processes connection metadata, including IP addresses, in order to serve requests and resist abuse, as all web infrastructure does. Such processing is transient and operational. Measurement is a separate matter, and is set out immediately below.
Measurement
Traffic to this site is counted using Cloudflare Web Analytics. It sets no cookie, writes nothing to browser storage and does not fingerprint visitors, so nothing it does requires consent. Cookies set by the hosting platform are a separate matter, and are described below.
What it reports is limited to:
- which page was loaded, and the site that referred the visit;
- country, browser, operating system and device type;
- how long the page took to load;
- whether a request appears automated, so that bot traffic can be excluded.
No identifier is created for a visitor, so one visit cannot be linked to another, and none of it can be joined to an assessment. A visit is counted as a page view arriving from somewhere else, rather than by recognising who arrived — which is the whole reason the measurement can be this uninformative about you.
What the hosting platform adds
This site is built and served through a hosting platform, which injects a measurement script of its own and sets cookies that are not part of this application's source code. They are set out here because a privacy notice covering only the parts its author chose is not a description of the site.
- session-id — a randomly generated identifier the platform's analytics uses to group page views within a single visit. It expires after thirty minutes and is written by script rather than by the server, so it is not HttpOnly.
- __dpl — set by the platform's delivery network, to keep a visitor on one deployment of the site.
- __cf_bm — a bot-management cookie set by Cloudflare, which sits in front of the platform. It expires after thirty minutes and exists to tell automated traffic from human traffic.
The platform's script records page views and page-loading performance, and reads the browser's user-agent string and the referring address. It reports to this site's own domain rather than to a third one, and it replaces the values of a list of sensitive field names — passwords, tokens, email addresses, payment and order details among them — with asterisks before transmitting anything. Whether it can be switched off is being taken up with the platform.
What is not done
- Personal data is not sold, and is not shared for advertising purposes.
- There is no behavioural advertising system.
- There is no cross-site tracking.
- No aggressive browser fingerprinting is performed.
- No attempt is made to identify a visitor across devices.
What is published
Only aggregates are published: averages, medians, distributions, counts, dispersion and movement over time. An individual assessment is never publicly attributable to a visitor, because the Institute holds nothing capable of making that attribution.
Sharing a result may include your own score in the text you send. That text is composed on your device and shared by you; it creates no public record here.
Requests and corrections
Concerns regarding a subject, an image, attribution or personal likeness are handled through the rights and content requests channel.