Privacy
Privacy Policy
This page explains what this website measures, what it stores, and what it does not do. If anything does not match what you see, please tell us. The contact address is at the bottom.
1. Information we collect
This page keeps five counts, and nothing else:
- Unique readers — how many browsers have opened this page.
- Unique downloads — how many browsers have downloaded the white paper PDF. Downloading it five times counts once.
- Shares — how many times a share action was taken, and which one it was (LinkedIn, Facebook, X, Bluesky, Reddit, WhatsApp, Telegram, Threads, Substack, email, copy link, copying one of the five statistics, or copying the email to a medical educator). This one is a count of actions, not of people, and it is labelled that way on the page. It records that a statistic was copied, never which statistic; and copying the educator email records only that it was copied — we do not see who you send it to, because you address and send it yourself from your own email account.
- Unique listens — how many browsers have played at least 30 seconds of the audio briefing.
- Unique share-kit downloads — how many browsers have saved at least one of the eight Instagram graphics. Saving all eight counts once.
To keep those counts from double-counting the same browser, each visit sends our server a random identifier your own browser generated (described in section 3), plus the type of thing that happened and, for a share, which button was used. Each of those events is stored as a row with a timestamp. That is the entire contents of our database.
Some things on this page are not counted at all, and it is worth naming
them so the list above can be taken literally. Copying the citation is not recorded.
Choosing APA, AMA or MLA is not recorded. The press and
add your organization buttons are ordinary mailto: links
— pressing one opens your own email application and tells us nothing; we only learn
anything if you choose to write to us, at which point we simply have your email.
We also record a single campaign source label when you arrive from one of our own
tagged links — for example, arriving from the LinkedIn post records the word
linkedin against that one anonymous reader row. The label is checked against a
short fixed list of our own channels; anything not on that list is discarded before it
reaches the database, so an arbitrary string in a URL can never be stored. Any
utm_ parameters are then removed from the address bar.
The Take action section is not counted at all. Its buttons either open a
message in your own email application using a plain mailto: link, or copy text
to your clipboard. There is no form on this page, nothing you type is transmitted to us,
and we are not told whether you pressed any of those buttons. If you do send one of those
emails, it arrives in an ordinary inbox and is handled as ordinary correspondence, not as
website data.
That includes the three files in that section — the committee brief, the slide deck, and the single summary slide. They are ordinary download links with no counting attached, so we have no idea how often they are taken. Only the white paper itself and the Instagram graphics are counted, as described above.
2. Information we do not collect
We do not collect, and our database has no column for:
- Names, email addresses, or any other contact details.
- Stored or logged IP addresses (see the note below — this deserves a precise answer).
- GPS or precise location. We do not do any geolocation lookup at all, not even country level.
- Device fingerprints. We do not read your user agent, screen size, timezone, language, installed fonts, or canvas rendering, and the identifier we use is not derived from any of them.
- Advertising identifiers of any kind.
- Behavioural profiles. We do not measure scroll depth, time on page, mouse movement, or which sections you read — an earlier version of this page measured scroll depth and time on page, and that was deliberately removed.
- Cross-site tracking data. Nothing we store can be connected to your activity on any other website, because nothing we store exists anywhere but here.
A precise note about IP addresses
We are not going to tell you we never see your IP address, because that would not be true. Every web server on the internet receives the visitor's IP address — it is how the response gets back to you. What matters is what is done with it. Here:
- Our database never stores an IP address. There is no column for one in any table.
- Our application writes no access log. We deliberately run no request-logging middleware, precisely because standard access logs capture IP addresses.
- The one place the IP is used is a basic anti-abuse rate limit, to stop someone hammering the counters. It is immediately turned into a salted, truncated cryptographic hash, held only in memory for a few minutes, and then discarded. It is never written to disk, never written to the database, and never written to a log. The salt is regenerated every time the server restarts, so the hashes are not even comparable across restarts.
- We never use an IP address to identify, locate, or profile anyone.
- Our hosting provider keeps its own operational server logs, which is standard for every website everywhere and is outside our control. Those logs are the hosting provider's, governed by their policies, and are not something we query or analyse.
3. How the analytics work
In plain English: the first time you open this page, your browser generates a random identifier for itself — the equivalent of drawing a very long number out of a hat. It saves that number locally, on your device. When you read, download, share, or listen, your browser sends that number to our server so we can tell "this is the same browser as before" and avoid counting you twice.
The number is purely random. It is not calculated from anything about you or your device, so it reveals nothing. On its own it is meaningless, and we have deliberately given ourselves nothing to link it to — no name, no email, no IP address, no device details. Its only job is to be different from everyone else's number.
All of this runs on our own server and into our own database. There is no analytics service involved. We do not use Google Analytics, Google Tag Manager, Meta Pixel, the LinkedIn Insight Tag, Microsoft Clarity, Hotjar, or any comparable product.
4. Cookies and local storage
We set no cookies. Not analytics cookies, not "essential" cookies, not any cookies. That is why you did not get a cookie banner: there was nothing to ask you about.
We use exactly one entry in your browser's local storage. Its name is
clcc_visitor_id and its value is the random identifier described above. That is the
only thing this website writes to your device.
If you clear your site data, that entry disappears — and the next time you visit, your browser will generate a fresh random number and be counted as a new reader. If you block storage entirely (private browsing modes sometimes do this), the page detects it and simply does not record your visit. Everything still works: the paper, the reader, the audio, the share buttons, and the current totals all display normally. You just are not counted.
We would rather under-count than track you. We will not fall back to a device fingerprint or an IP-derived hash to recover a count we lost.
5. Third-party services
No third party receives anything for analytics or advertising purposes. There are no third-party analytics scripts, advertising scripts, or tracking pixels on this page. Every file the page loads — the fonts, the PDF reader, the audio, the images, the stylesheets, the JavaScript — is served from this website's own domain. Nothing loads from Google Fonts or from a content delivery network, specifically because those requests would expose your IP address to companies that have nothing to do with this white paper.
To be complete and accurate, these parties are genuinely involved:
- Our hosting provider (Vercel) serves this website. As noted above, they keep their own operational server logs, as every host does. This is infrastructure, not analytics.
- Supabase hosts the database that holds the five counts. They are a processor acting on our behalf — the data they hold is only what is described in section 1, which contains nothing personal. They do not use it and we do not send them anything else.
The share buttons are ordinary links. They do not load any code from LinkedIn, Facebook, X, Threads, Substack, or anyone else, and none of those platforms knows you were here unless you press one. If you do press one, you are taken to that platform in a new tab, and from that point their own privacy policy governs what happens — as it would with any link.
6. Data security
The strongest security measure here is that there is nothing sensitive to protect. We hold no names, no email addresses, no IP addresses, and no personal data of any kind, so there is no personal data here to be stolen.
Beyond that: the site and its API are served over HTTPS, so traffic between your browser and our server is encrypted in transit. Your browser never talks to the database directly and is never given a database credential — it can only call our own API, which returns the totals and accepts only the small, fixed set of values described in section 1, rejecting anything else.
To be precise rather than reassuring: the credential our server uses can add a row and read
rows, but cannot change or delete anything. So we are not claiming those rows are
cryptographically sealed away — we are pointing out that a row consists of a random
number, a timestamp, and at most a word like share, linkedin, stat_copy or
listen. Reading every row in our database would tell you how many browsers
visited and nothing whatsoever about who they were.
We make no claim to any formal security certification, because we do not hold one.
7. Your privacy rights
Privacy laws generally give you the right to see, correct, export, or delete the personal data an organisation holds about you. Here, the honest answer is that we have nothing to show you, because we hold nothing about you. A request to look up "your" data would fail, not out of unwillingness, but because there is no identifier in our database that could ever be matched to a person — including by us.
The complete opt-out is in your hands and takes a moment: clear this site's data in your browser, and the one stored identifier is gone. Block storage for this site, and nothing is ever recorded in the first place. Either way the white paper stays fully readable, downloadable, and listenable. Nothing on this page is gated behind being counted.
8. Contact
If you have a question about this notice, or you think any statement on this page does not match how the site behaves, please write to admin@abighealth.com. We would genuinely rather hear about it than have it stand uncorrected.