Privacy
Dhamma data is designed to work without an account. There is no advertising, behavioural analytics, tracking pixel, persistent visitor identifier, user profiling, or geolocation. A small first-party counter records anonymous engagement milestones so the maintainer can learn whether the site is useful. Public corpus search, REST, and MCP access do not require an API key.
Dhamma data does not retain public search queries, prompts, retrieved passages, or response content as a user history. Minimal operational processing remains necessary to serve and protect the site.
Open interactive privacy notice →Information processed
- Public reading and search: the requested route or input and ordinary network metadata are processed to answer the request. Query text is not intentionally persisted in application logs or stored as a history.
- Public API and MCP: requests and results are processed transiently. Coarse error type and duration may be recorded without query text or persistent full IP addresses.
- Anonymous engagement: after a trusted click or keystroke, the browser may report only that a page session searched, opened a result, copied a citation, saved a bookmark, wrote a note, or answered the usefulness prompt, plus the source category direct, search, social, or other. The engagement payload does not include a route, query, passage, referrer, IP address, or user agent, and none of those are stored with engagement milestones.
- Optional account: if you sign in, Dhamma data stores your email, account and login timestamps, a secure session cookie, and bookmarks, notes, or private research dossiers you choose to save.
- Contact form: a message stores its subject and body, a supplied reply address, and its submission time.
How information is used
Information is not sold, rented, used to build advertising profiles, or used to train a language model. Dhamma data does not use a third-party analytics service or attach engagement data to an account, person, query, passage, or browsing history.
- To deliver requested pages, searches, dictionary entries, passages, and API or MCP results.
- To sign users in and synchronize collections they deliberately save.
- To answer messages and correct source, licence, translation, or catalogue records.
- To apply short-window rate limits, diagnose coarse failures, prevent abuse, and keep the service available.
- To count aggregate engaged and useful sessions and improve the public reading and search experience.
Cookies and local storage
Signed-in accounts use a secure session cookie. Local browser storage holds preferences and signed-out features such as theme, search mode, bookmarks, notes, or research dossiers. It stays in the browser unless you sign in and choose to synchronize a supported collection. Clearing site data removes the local copy and signs the browser out.
The anonymous engagement session identifier exists in page memory only and disappears on reload or close; it is not written to a cookie or browser storage. A stored opt-out preference, Global Privacy Control, or Do Not Track disables engagement measurement.
Service providers and connected assistants
Hosting and database infrastructure process requests on Dhamma data’s behalf. When enabled, an email provider processes sign-in links and contact notifications. The site loads typefaces from Google Fonts. Providers receive ordinary connection metadata under their own terms, not a Dhamma data search history for advertising.
If you connect Dhamma data to an assistant, that provider receives prompts you give it and tool results it requests under your settings and its privacy terms. Dhamma data does not control or receive the rest of that conversation.
Retention and control
Transient request and rate-limit state is kept only as needed for operation and abuse prevention. Anonymous session milestones are kept for today and yesterday, then rolled into daily totals and deleted. Daily totals contain no session identifier and may be kept to measure improvement. Coarse operational records may remain long enough to diagnose reliability. Account and saved-collection data remains while an account is used or until deletion is completed; contact messages remain as reasonably needed to answer and maintain a correction record.
You may use the public service signed out, clear local site data, sign out, or request deletion or a copy of account and contact information by email. Requests may need verification from the account email address.
Security and scope
Reasonable safeguards include expiring single-use sign-in links and protected session cookies. No internet service can promise absolute security. Public API and MCP tools are deliberately isolated from personal collections, private translations, and unpublished administrative research.
Questions or requests
Email Keenan@boothcheck.com for access, correction, deletion, or privacy questions. Changes to this notice will be dated at the top of the page.