Skip to content
Likelier

Privacy policy

What we record, and why


What we collect, and when

When you read a page

No analytics or tracking script is loaded on this site, and reading a page writes no row in any database of ours. What does happen is ordinary web serving: Cloudflare delivers the page, and the request reaches its servers carrying the things every HTTP request carries.

  • Your IP address.
  • The address of the page you asked for, and the page you came from if your browser sent a referrer.
  • Your browser and operating system, from the User-Agent header, and your language preferences, from Accept-Language. A link with no language in it, such as a shared /plane-crash, is resolved to one of the built languages using that header.

Cloudflare handles that as our hosting provider and keeps its own request logs on its own schedule. We do not pull page-view analytics out of them. Likelier sets no cookies. There is no advertising, no advertising identifier and no cross-site tracking, and nothing is sold or handed to anyone for marketing. Reading a page builds nothing about you and is not analysed at all. We stop short of extending that into a flat denial of profiling for the whole site, because /calibrate invites you to describe yourself, and that deserves a real answer rather than one word. That answer is below.

When you search

Search runs in three stages in your browser, and the third stage needs a vector that only a model can produce. So when a query settles, the text goes to our server, which forwards it to Google to be turned into that vector, and one row is written to our database. The row holds:

  • A SHA-256 hash of the query, lowercased and whitespace-normalised. The text itself is not stored.
  • How many results came back.
  • Which ranking stages ran, and whether the vector stage was among them.
  • How long the search took, in milliseconds.
  • The path of the page you searched from, for example /en/risks.

That row carries no IP address and no session identifier. Outside the row, though, each accepted search advances a rate-limit counter in Workers KV whose key contains the first eight bytes of an unsalted SHA-256 of your IP address, and that counter expires 24 hours after it is written. Search rows are deleted 90 days after they are written, by a sweep that runs on the back of later traffic rather than on a clock, so a very quiet stretch can leave a row in place somewhat longer. We also will not tell you the hash is anonymous: a short, common query can be recovered by hashing candidate phrases and comparing, so treat these rows as pseudonymous.

When you use /calibrate

Calibrate asks you to describe a situation in your own words, which makes it the one place on the site where you may type something about yourself. That text goes to our server, which passes it to a Cloudflare Worker of ours, the Likelier MCP server, to search the dataset. To search, that Worker sends your text to Google to be turned into a vector. If the page also shows a short generated takeaway, your text goes to Google a second time inside a prompt to a generative model, and the answer that comes back is held in Cloudflare edge cache for 24 hours under a key derived from a hash of your text. We do not keep the text. We keep:

  • A 12-character prefix of a SHA-256 hash of what you typed, the risk we matched to it, whether the request was refused or matched nothing, and the version of the dataset that answered.
  • A random nonce identifying the page session, issued when the page loads and valid for ten minutes. It is what ties a later feedback click back to the calibration it belongs to.
  • A SHA-256 hash of your IP address combined with the date and a secret we hold, used to recognise repeat submissions within a day. When that secret is not configured the field is left empty rather than filled with a weaker value.
  • Your interface language, and, if you click one, which feedback button you pressed or which outside AI provider you picked. Picking a provider opens that company’s own site with your question on your clipboard, and in some cases in the link itself, so from that point the text is theirs to handle under their policy rather than ours.

These rows are deleted 90 days after they are written, on the same traffic-driven sweep as the search rows. The same window and the same handling cover the rating you can leave after an AI assistant answers using our MCP server: following that rating link records your rating, which tool produced the answer, the dataset version, and the same dated IP hash, and nothing else. A short phrase hashes to a value that can be recovered by guessing and re-hashing, exactly as with search, so none of this is anonymous data either. Whether this amounts to profiling is a fair question, because Article 4(4) GDPR reaches automated processing used to evaluate personal aspects of someone and names health and behaviour among them, which is close to what you might type here. What the page does is narrower. Your words select entries that already exist, and the number you see is the published figure for a population rather than a figure computed about you; the model that writes the short takeaway is instructed never to recompute or extrapolate a probability, though it may pick out which of the entry's published factors your description makes worth mentioning. The list of personal factors beside the result is the entry's own list, the same one on its public page and the same for everyone who lands there, and this site sends us no age, no sex and no history to test against it, so every factor on it is marked as not flagged. An AI assistant working through our MCP server can pass along an age band, a sex or a history you stated to it, and then the factors whose wording matches are ticked for that one answer and not recorded. The slider that lets you try those factors on runs entirely in your browser and sends nothing anywhere. Nothing accumulates: we hold no attributes about you and no profile to put them in, each request is answered on its own, and the ten-minute nonce ties a feedback click to one calibration rather than a person to a history. No decision is taken about you, so Article 22 GDPR is not engaged. The honest description is retrieval with a personal question attached, and if you would rather not attach one, the same entries are readable by browsing or searching without describing yourself at all.

Who processes it, and where

Google

Text you type reaches Google, and that is the disclosure on this page most worth reading twice. A search query goes to the embedding model gemini-embedding-2 to be turned into a 768-dimension vector for ranking. A calibrate situation goes to the same embedding model through our MCP Worker. A calibrate situation goes on to a generative model as well, gemini-3.5-flash-lite unless the deployment overrides it, inside a prompt that also carries the retrieved dataset text, whenever the page renders a takeaway. We attach no name, no account, no cookie and no identifier to any of these calls, and because our server makes them, Google sees our infrastructure rather than your IP address. The text, though, is yours, and it does leave our systems. Google processes it under the Google Privacy Policy .

Cloudflare

Cloudflare is not the network in front of the site. It is the site: where the code runs and where nearly everything we keep is kept. Pages serves the HTML, Functions run the API endpoints, D1 holds the tables described above, Workers KV holds the rate-limit counters, Analytics Engine takes one data point per API call recording the endpoint, HTTP status and latency with no IP and no text in it, R2 serves the search index your browser downloads and the dataset snapshot the MCP Worker reads, the edge cache holds generated takeaways, and Workers Logs collects the structured error lines our endpoints emit and keeps them for a few days. The Likelier MCP server is a separate Cloudflare Worker that we operate. All of it runs on Cloudflare as our processor, under the Cloudflare Privacy Policy . Our configuration pins no region, so processing may happen outside the European Economic Area.

What the site stores on your device

  • theme: the colour scheme you picked, written only when you use the toggle.
  • likelier:recent:consent:v1 and likelier:recent:v1: your answer to the reading-history question, and the history itself. Nothing is written to the history until you say yes, saying no deletes anything already there, and neither value is ever sent to a server.
  • likelier-coffee-dismiss, likelier-coffee-supporter and pwa-install-dismissed-at: a note that you dismissed the support prompt or the install prompt, so the site stops asking.
  • Values that live only until you close the tab: a cached copy of the tidbit list, a count of pages read this session, a note that you have chosen a language, and a scroll position carried across a language switch.
  • None of these are cookies, none are read by a server, and none identify you across sites. Clearing site data in your browser removes all of them.

Who is responsible

Likelier is operated from Poland by Krzysztof Gluszczyk, who is the controller of everything described here. Write to contact@creatiwi.ai about anything in this policy.

Legal basis

Search rows, calibrate rows and API metrics are processed under legitimate interest, Article 6(1)(f) GDPR: we need to know which topics readers look for, where the dataset has gaps, and whether the endpoints are being drained. The rate-limit counters and the dated IP hashes rest on the same basis for a narrower interest, which is keeping an unauthenticated and metered API affordable. Sending your text to Google is necessary to perform the search or the calibration you asked for, Article 6(1)(b) and (f). We make no claim that any of this is anonymous. A value derived from your IP address, and a hash of a phrase you typed, are pseudonymous data, and under Recital 26 pseudonymous data is still personal data when someone holds what is needed to reverse it. We hold it.

Storage on your device is a separate question, and cookies are not the test for it. Because we operate from Poland, the operative rule is Article 399 of the Prawo komunikacji elektronicznej, the Polish electronic communications law in force since 10 November 2024, which replaced Article 173 of the old Prawo telekomunikacyjne and is Poland's enactment of Article 5(3) of the ePrivacy Directive. What it turns on is storing information in your terminal equipment, or reading information already stored there, whether or not that information is a cookie and whether or not it is personal data. It also sits alongside the GDPR rather than inside it, so the legitimate interest above does not stand in for consent here, and each item below has to justify itself on its own. Two things here are genuinely necessary for something you asked for and are therefore stored without consent: the colour scheme you selected, and, once you answer it, your answer to the reading-history question, which exists so that the question is not put to you again. The reading history itself is not necessary, since the pages render identically without it, so nothing is written until you agree and refusing deletes what exists. The dismissal records for the support and install prompts are stored without asking, on the reasoning that remembering "stop asking me" serves you rather than us. If you read that differently, clearing site data removes them and the prompts come back.

Your rights

You have the rights in Articles 15 to 22 GDPR: access, rectification, erasure, restriction, portability, and objection to processing that rests on legitimate interest. Exercising them here is awkward rather than impossible, and it is worth saying how. We hold no account and no name for you, so an email address alone does not find your rows. What we can match on is what we do hold: tell us roughly when you searched or used calibrate and what you typed, and we can recompute the hash and delete the rows it matches. If you can tell us the IP address you used and on which day, we can recompute the dated hash and match on that too, for as long as the secret behind it is unchanged. Write to contact@creatiwi.ai and we will answer within one month. You can also complain to a supervisory authority; in Poland that is the President of the Personal Data Protection Office, UODO.

Recently viewed on this device