Privacy
appliedbits.com is a personal site offered as a free resource. This page describes what it collects and why, in plain language. It may be updated; the date above reflects the last change.
The short version
The site has no ads, no advertising trackers, and no cross-site tracking or profiling — and nothing you do here is sold or shared for advertising. What the site does measure — privacy-first, cookieless page analytics and the interactive tools — is described below. Today there is nothing to sign in to and no account to create. If that changes in the future — accounts, saved preferences, or other features that need to remember you — it will be to make the site more useful, done with the same restraint, and this page will be updated to spell out what is collected and why.
The interactive tools
The tools under /library/tools/ fall into two groups. The decoders and validators — the PASSporT & Identity Header decoder, the Certificate & TNAuthList decoder, and the STI-CA validator — do their decoding and validation in your browser. To understand how the tools are used and to diagnose problems (especially inputs that fail to decode), the site records each submission to these: the value you submit (the PASSporT, header, or certificate), whether it decoded successfully, and your IP address, along with basic request details such as a timestamp, country, and browser user-agent. The built-in examples are not recorded. The carrier directory lookup (the RMD × 499 carrier directory) works differently: it downloads a directory file and searches it entirely in your browser, so what you type there is not sent to or recorded by the site.
This recording exists for one purpose: to gauge interest in the tools and to fix and improve them. It is not sold, shared, or used for advertising. As the tools change, the site may record submissions to any of them — including tools that today run entirely in your browser — for that same purpose and no other, and this page will be kept accurate about what each tool does. PASSporTs and certificates can contain telephone numbers and organization identifiers, so please do not paste anything you would not be comfortable sending to the site.
When you ask a tool to fetch a certificate by its x5u URL, that request is
made by a small proxy on this site (browsers block the direct cross-origin
request); the certificate retrieved that way is public.
Site analytics
To understand which writing lands and where readers arrive from, the site measures page views — cookielessly, and in two ways.
The main measurement is first-party, on this domain. For each page view it records the page path, the referring site and any campaign (UTM) tags, your country, and a coarse device / browser / operating system derived from your request, along with rough engagement (time on the page and how far you scrolled). To count unique visitors without a cookie, it also stores a daily-rotating visitor hash: a secret salt is generated fresh each day and discarded at the end of it, and that salt is combined with your IP address and browser to make the hash. The raw IP is never stored, and because the salt is thrown away daily, views cannot be tied back to you or linked across days.
The site currently also loads Cloudflare Web Analytics, a cookieless, privacy-focused measurement provided by the hosting platform.
Neither uses cookies, sets a persistent identifier, or tracks you across other websites, so no consent banner is required. Both are used only in aggregate — view counts, popular pages, referrers, and rough engagement — to understand the audience and improve the writing. None of it is sold, shared, or used for advertising.
If you would rather not be counted at all, add ?count=off to any page’s URL —
that sets a single flag on your device and the site stops recording your visits
(and any tool submissions); ?count=on turns it back on. It is also how I keep
my own visits out of the numbers.
Hosting and standard logs
The site is hosted on Cloudflare Pages. Like any web host, Cloudflare processes requests in order to serve the site and may keep standard operational logs. See Cloudflare’s own privacy documentation for how it handles that data.
Retention and contact
Logs are kept only as long as they are useful for the purposes above and may be pruned periodically. Questions — or a request to remove something you submitted — can go to chris@appliedbits.com.