Most privacy policies are long because the site behind them collects a lot. This one is short because coin-glass.app is a set of static pages with no login and no personalisation. Two things still touch your data: the web server that sends the page, and the Google Fonts service supplying the typefaces.
What we collect
Standard server access logs, and nothing else. When your browser requests a page, the server records it as every web server does.
What a log line contains
- IP address
- Where the request came from. Under GDPR this is personal data.
- User agent
- The browser and operating system string your browser sends.
- Referrer
- The page that linked you here, where one is sent.
- Request line
- The URL, the response code and the bytes served.
- Timestamp
- The date and time of the request.
- Retention
- A short rolling window, then automatic deletion.
We use these logs for two things: keeping the site up, and stopping abuse such as scraping floods and intrusion attempts. We build no profiles, we do not try to identify individual readers, and we combine them with nothing else. They are deleted on a short rolling schedule.
If you email us, we hold your message and address for as long as it takes to deal with it and to record any correction made. Nothing else happens to it.
What we do not collect
- No accounts, logins or passwords. There is nothing to register for.
- No user profiles, behavioural tracking or cross-site advertising identifiers.
- No newsletter, mailing list or marketing email.
- No comment system, forum or user-generated content.
- No payment data. We sell nothing here.
- No wallet connections. A reading site has no business touching a wallet.
Cookies, and the Google Fonts question
We set no cookies of our own, so there is no consent banner. Two edges are still worth knowing about, and we would rather spell them out than bury them.
Google Fonts
The typefaces here load from fonts.gstatic.com, operated by Google. Your browser therefore makes a request to a Google server when a page loads, and that request carries your IP address and user agent. Google states the font service sets no cookies, but the request still reaches them and falls under their privacy policy, not ours. A content blocker will stop it, and the site falls back to a system typeface.
Sponsored outbound links
Some outbound links here are sponsored, as disclosed on our disclaimer page. Following one takes you to a third-party site that may set its own cookies, including referral-tracking cookies recording which site sent you. That is governed by the destination's policy, not ours. Nothing is set until you click.
Analytics and advertising
We keep analytics minimal and do not sell or share personal data with data brokers. In practice we look at aggregate traffic to see which pages are read and which are broken, and we run no behavioural advertising, remarketing pixels or identity-resolution services. Nobody buys our reader data because there is none to buy.
Legal bases for processing
For readers in the European Economic Area and the United Kingdom, the GDPR requires a named lawful basis for each processing activity. Ours are short.
- Legitimate interests for server logs, under Article 6(1)(f): keeping the site available and secure. The interest is narrow and retention is short.
- Legitimate interests for correspondence: answering the message you sent us.
- Legal obligation where a law or valid legal request requires retention or disclosure.
We do not rely on consent, because nothing we do requires it.
Your rights, and how to use them
Under the GDPR you may access the personal data we hold about you, have it corrected or erased, restrict or object to processing, and receive it in a portable form. You may also complain to your national data protection authority.
Under the California Consumer Privacy Act you may know what is collected, request deletion, and opt out of the sale or sharing of personal information. On that last point: we do not sell or share personal information, so there is nothing to opt out of. Nobody is penalised for exercising a right.
To exercise any of these, email contact@coin-glass.app. Note that a log entry usually cannot be tied to a named person, so the honest answer to many access requests is that we can find nothing about you. We say so rather than invent a file.
Children
This site is not directed at anyone under 18, and we do not knowingly collect data from children. The subject matter is not appropriate for minors in any case. If you believe a child has sent us personal data, write to us and we will delete it.
International transfers
The site is served from infrastructure that may sit outside your country, and the Google Fonts request above may be handled by servers in the United States. Where personal data crosses borders we rely on our providers' transfer mechanisms, such as the European Commission's standard contractual clauses. The data involved is limited to what a log line contains.
Changes to this policy, and contact
We will update this page if what we do changes, and the "last updated" date will change with it. The current version is dated 27 July 2026. With no mailing list, that date is the notification.
Privacy questions and rights requests go to contact@coin-glass.app. Our terms of use and publishing principles cover everything else.