Skip to content
hideouts

Type to search every app and research write-up.

Privacy

This site collects nothing.

No cookies, no analytics, no trackers, no fingerprinting, no third-party requests. That’s the whole policy; the rest of this page explains how it’s enforced.

Last updated

WhatStored or sent
CookiesNone. The site sets no cookies, so there’s no consent banner.
Local storageOnly if you pick the light theme. One key, theme, set to light. It’s deleted when you switch back to dark, and it never leaves your device.
Session storage, IndexedDB, cache storageNone. Not used.
Analytics, tracking pixels, fingerprintingNone. No tracking scripts of any kind, first- or third-party.
Requests to other sitesNone. Scripts, styles, fonts, images, diagrams, and the search index all load from hideouts.io. README images are copied here at build time.
Search queriesStay in your browser. Search runs locally against a static index. What you type is never sent anywhere.
ReferrerNot sent. Sites you follow a link to aren’t told you came from here.
Server logsKept by GitHub, not by hideouts. GitHub Pages processes your IP address to deliver the page. See the hosting provider.
Accounts, forms, email sign-upsNone. There’s nothing to sign in to or submit.

You don’t have to take this page’s word for it. Any browser’s developer tools can show you:

  1. Open the developer tools. In Safari, first turn on Settings → Advanced → Show features for web developers, then choose Develop → Show Web Inspector. In Chrome or Edge, choose View → Developer → Developer Tools. In Firefox, choose Tools → Browser Tools → Web Developer Tools.
  2. Open the Network tab and reload the page. Every request goes to hideouts.io. Try a search: the only requests are for files under /pagefind/, and none of them contains what you typed.
  3. Open the Storage tab (Safari, Firefox) or Application tab (Chrome, Edge). Cookies are empty. Local storage is empty, or holds only theme if you’ve switched to light.
  4. To see the rules the browser enforces, view the page source and find the Content-Security-Policy tag near the top.
  • A strict Content Security Policy only allows scripts, styles, images, and connections from this origin, and scripts only by hash.
  • Referrer-Policy: no-referrer means sites you follow a link to aren’t told you came from here.
  • Every build fails if a page references anything outside the published project list.

The site is static files served by GitHub Pages. Like any web host, GitHub processes your IP address to deliver the page and may keep standard server logs under GitHub’s privacy statement. hideouts doesn’t receive or look at those logs.

Download and source links go to GitHub. Once you follow one, GitHub’s own privacy practices apply.

Any change to what the site stores or sends is listed here. The full history is in the site’s repository.

  • : Added the table of what the site stores or sends, and how to check it yourself.
  • : hideouts.io launched with this policy.