Privacy
This site writes one row about every request it serves — the time, your IP address and a salted hash of it, the page you asked for, your country and your browser’s user agent — keeps it for 30 days, then deletes it. The sections below set out exactly what that means, including the parts of the picture I do not control.
Last updated 18 September 2026
1. What this site records
One row per request, written by this site into a database only I can reach. It is how I know how many people come here and which pages they read, without loading anything from anybody else and without putting anything on your machine. The row holds this, and nothing else:
- a random identifier for the row, made when the row is written and derived from nothing about you;
- the time of the request, to the second;
- your IP address, as my host hands it to me;
- a salted SHA-256 hash of that address, which is what a visitor count is counted on, so that six pages read in one sitting are one visitor rather than six;
- the country the request came from, as my host reports it — the country, never a city, a street or a map pin;
- the path you asked for, including any query string on it, and the referring page if your browser sent one;
- your browser’s user agent string, and a marker recording whether that string looked like a crawler rather than a person;
- the time the row becomes eligible for deletion, which is thirty days after it was written.
Every row is kept for 30 days, then deleted automatically — address, hash, path and all — by a scheduled job rather than by hand. What outlives it is the counting it fed — daily totals — and not the row: once it goes, your address and the hash of it go with it.
Two things in that list I would rather say plainly than let you assume. The first is the hash: it is pseudonymous, not anonymous. It is a one-way function of your address and a secret salt, so without the salt it cannot be turned back into an address — but I hold the salt, and anyone holding it can hash an address they already suspect and see whether it matches — and an IPv4 address is one of only four billion, a list a computer can simply work through end to end. The salt is also never changed, so the hash of an address today is the hash it will still have next year. The second is the path: it is stored exactly as your browser asked for it, query string included, so whatever a link you followed happened to carry in its URL is in the row too.
What that row is never used for: it is not sold, not shared and not sent anywhere. There is no analytics service here, hosted or self-hosted, and no third party receives any part of it — the count is mine, made on my own server, and it stays there. You are not scored, segmented or advertised to, and nothing here follows you to another site.
The rest of what this site does not do is unchanged, and most of it you can check rather than take on trust:
- Cookies are never set — not by the pages, not by the stylesheet or the script, and not by either of the two server-side routes described in section 2.
- The site stores nothing in
localStorage,sessionStorageor IndexedDB, and no script on these pages takes any part in the row above: it is written on my server, out of the request itself. - Nothing on these pages attempts fingerprinting, advertising or marketing measurement.
- The site contains no contact form and no input field of any sort, so there is nothing for you to fill in and nothing to submit.
- Accounts, logins and profiles do not exist here, so none of this is attached to a name. What does tie one request to another is the hash above, and only inside the thirty days before the rows are deleted.
- Every asset is served from this domain. Stylesheet, script, images and the one typeface all come from here, so loading a page tells nobody else that you did. Links to other sites are ordinary links, and reach those sites only when you click them.
The browser half of that is yours to check, from the network and storage panels and from the page source, which is plain static HTML: no cookies, no stored values, no host but this one. The row is the half you cannot see from there, which is why it is written out above in full rather than summarised.
2. What the host necessarily sees
The site is hosted on Cloudflare Pages. Like any web host, Cloudflare handles the connection itself, which means it processes your IP address, the page you asked for, your user agent and the time, in order to deliver the page and protect the service from attack. This is a technical necessity of the web rather than a choice I made, and it happens whether or not I want the data.
Cloudflare’s own logs are Cloudflare’s. They are kept under its policy and its retention rather than mine, and the row in section 1 is not taken from them — it is built from the request as it reaches my code. Cloudflare acts as the hosting provider and its handling of that data is governed by its own privacy documentation.
The same is true of dl.wh1ter0se.dev, which serves the download files.
What I hold myself from your visit is the row in section 1, in my own database, and I do look at it: there is a private page on my side showing counts, countries and paths, and nobody else can reach it. That is the whole reason the row exists, and pretending otherwise would be the easy sentence to write and the wrong one.
The two server-side routes
There are two now, and neither sets a cookie or loads anything from a third party.
/api/build fetches a small text document from dl.wh1ter0se.dev so
the page can show the current build number instead of a hard-coded one that would silently
go stale; it sends nothing about you and reads nothing from your browser. The second runs
on every request this site serves and writes the row described in section 1. It runs after
your page has already been sent, so it cannot slow the page down, and if the database is
unavailable the row is simply lost rather than the page failing.
3. If you email me
The only way to send me anything from this site is to click an email address, which opens your own mail client. Nothing is transmitted until you press send.
If you do email me, I receive your address, whatever you wrote, and whatever your mail client attaches. That arrives in a Proton Mail mailbox. I keep enquiries only as long as needed to deal with them, and correspondence attached to paid work for as long as that engagement and any legal or tax obligation requires. I do not sell it, share it, or add you to any mailing list, of which there are none to add you to.
Ask me to delete a thread and I will, and I will tell you when it is done.
4. Downloads and signing in
Downloading a file is a normal HTTP request to dl.wh1ter0se.dev, with the same
host-level handling described above. The downloaded software is separate from this website
— what the launcher or the game does on your machine is described on the
download page and governed by
the terms, not by this policy.
Signing in is different, because it is not confined to your machine. When you sign in from the game through the GeneralsX sign-in page, the one that asks you to choose how to sign in, I keep your Discord username, display name and avatar so admins can recognise you. If an older build of the game sends you straight to Discord without that page, I keep none of them.
5. Your rights
I am an individual, not a company. Data protection law generally gives you rights of access, correction and objection in respect of personal data held about you, and requires me to tell you what I collect and what I do with it — which is the purpose of this page. I honour those rights regardless of where you or I happen to be.
If you are in the EU or UK and consider that data protection law there applies to you in this context, you are welcome to exercise the equivalent rights: access, rectification, erasure, restriction, objection and portability. I will not argue about jurisdiction with someone asking a reasonable question about their own data.
In practice, for a visitor who has not emailed me or signed in from the game, what I hold about you is at most thirty days of the rows in section 1, and the way to find them is your IP address. Tell me the address and roughly when you visited and I will show you what is there and delete it. After thirty days it goes on its own, without anyone having to ask. If you have emailed me, I hold that correspondence as well, and can show it to you or delete it, whichever you would prefer.
There is no automated decision-making and no profiling anywhere in any of this. The rows are counted and nothing more: nothing is inferred about you, nothing is scored, and no decision about anybody is taken from them.
6. Children
This is not a service aimed at children, and nothing here asks anyone, of any age, to provide anything. The row in section 1 is written for every visitor alike and deleted on the same thirty-day clock for everyone.
7. Changes
If this ever stops being accurate — if I add anything that collects anything — this page changes first, and the date at the top changes with it, so that nothing is ever collected behind a policy still claiming otherwise.
The 16 September 2026 update was that promise being kept. Until it was published this page said the site collected nothing, which was true; the row in section 1 is recorded from the deploy that follows it, and not before.
8. Contact
Questions about any of this, or a request about your own data, go to wh1ter0seliveson@protonmail.com. See Contact for who is behind the site.