ripple_effect
Privacy

What this site knows

There is no account here, no login and no database of ours. This page says what actually happens when you read a page, take a download, or run the app.

Reading a page

Page views are counted by Vercel Web Analytics, which sets no cookie and stores nothing on your device. Visitors are told apart by a hash derived from the request itself, and it is discarded after twenty-four hours — it cannot be reversed, and it cannot be used to recognise you here tomorrow or anywhere else ever.

What a recorded view may contain: the time, the path, the referring page, filtered query parameters, an approximate location down to a city, your operating system and browser and their versions, and whether the device is a phone, a tablet or a desktop. There is nothing in that list that names anybody, and nothing is joined up across sites. Vercel describes it in full in their analytics privacy documentation.

Downloading

The installers live in a private GitHub repository. This site holds a read-only token so it can ask GitHub what the current release is and where its files are; the token stays on the server, never reaches your browser, and can read that one repository and nothing else. It is used to look up a file, not to look at you.

The download itself is a redirect: the button hands you to GitHub and GitHub serves the bytes, so the request for the file is between you and them under their privacy statement. That is also how the download is counted — GitHub keeps a tally per file, which is the only download figure anybody here has.

The address of the thanks page carries an asset number. That identifies which file you asked for, and nothing about who asked.

The coffee button

The floating Buy Me a Coffee button is a script of theirs, and it sets a single first-party cookie named visited which records that it has been shown to you. It is the only cookie this site has, which is why it is the only thing you are asked about. Decline and the script is never requested at all — not loaded and hidden, not loaded.

The button on the thanks page is a different thing: a plain image served by Buy Me a Coffee, so loading that page fetches it from them. It sets nothing here, and following either of them takes you to their site, on their terms.

The waitlist

The paid-tier waitlist is a form hosted by Tally and linked to rather than built as a field of ours. An address you give it is held by them and reaches us through them; there is no database here for it to sit in, which is the reason it was done that way.

The app itself

Ripple Effect works on files on your own disk and needs no network to do it. Two things leave the machine, and both are worth naming. Once per launch it asks this site whether a newer version exists — a plain request for a release number, carrying nothing about you, your projects or what you were doing. And if you open the About box, it fetches the contributor list from api.github.com.

The update check reaches this site the way any other request does, which means an address and a browser-style identifier appear in a server log. Nothing distinguishes one installation from another, because nothing in the request is unique to one.

There is no account, no telemetry, no sync, and nothing you write is sent anywhere.

Fonts, and what is not here

The typefaces are built into the site at compile time and served from it, so reading a page here sends no request to Google Fonts. There are no advertising scripts, no tag manager, no session recorder, no heat map and no embedded video.

Changing your mind

Withdrawing is meant to be exactly as easy as agreeing was, so the choice lives here as well as in the notice that asked for it.

Asking about any of this

Write to williamkarol.dicioccio@gmail.com, or open a thread in Discussions.

Last updated 7 September 2026.