Privacy
Privacy
This page says, in plain words, what this site keeps, what leaves your browser when you use one of our tools, and what never does. It is written by the people who built them.
What this site stores
The pages of this site are read by your browser like any other page. Your choice of the light or the dark theme is kept in your browser and nowhere else.
The contact form ("Talk to us") sends what you typed to us by email. It stores nothing here: no copy of your message is kept on this site, and your address is used only to reply.
A claimed page is published by its subject. A person or an organization proves who they are at the claim desk on pxl8.io, reviews the facts, and chooses to publish. What is on a claimed page is what the subject saw and chose to publish, with the source of every fact beside it. The claim desk records each act on a claim, as its terms say.
The report form on a claimed page ("Is this page wrong about you?") stores what you typed, the address you gave for a reply, and the time it was sent. A person reads every report. Nothing on the page changes until they have.
The claim desk is on pxl8.io and uses a pxl8.io account. What that account holds, and the identity check the desk can lead to, are covered by the privacy policy of pxl8.io. Read pxl8.io's privacy policy.
The lookup
A lookup asks our records service whether a name or a handle has a published page, and what its record status is. It sends one of two things: a handle, which is the address of a page, or the first five characters of a hash of a name. The name itself is not sent.
The lookup tier that needs no key is limited per network address; past the limit the answer says so and how long to wait. Keyed access has higher limits and is governed by the terms that come with the key.
A hash of a name is not anonymity. A name can be guessed and hashed by anyone who holds the same list, and a five-character prefix names a small group of names rather than one. What the prefix does is keep the name itself off the wire: the answer is a list, and our tools match it in your browser or in your spreadsheet.
The browser extension
The extension reads the page in your browser to find names: on search results and in the answers of assistants, on the sites it is built for and on no other.
For each name it finds, it sends our records service at api.pxl8.io the first five characters of a hash of that name, in batches. It never sends the page address, the page text, your question or the answer. It sends the search engine or the assistant nothing at all.
It has no account, no analytics, no error reporting and no remote code: everything it runs is in the package you installed. There is a switch for each site and one switch for everything, and a site that is switched off is not read.
The switches and the list of your own names are kept in the browser's own extension storage and nowhere else. A status read from our service is kept in memory for one minute and then dropped. The options page keeps counts and a version for each site, never a name.
"Claim or correct this" opens our claim desk with the page address in the link, on your click and never before. The desk reads the address once, keeps only the host name as a hint you can drop, and stores no address.
The plain sentence again: a hash of a name is not anonymity. The extension never sends a name in clear, and the prefix keeps the name off the wire, but a name can be guessed and hashed.
The spreadsheet add-ons
The Google Sheets add-on and the Excel add-in read the names or handles in the range you choose and ask our records service about them, as hash prefixes or handles, in batches. A cell written as person:HANDLE or org:HANDLE is looked up by that handle; every other cell is looked up as a name. Nothing else in your spreadsheet is read, and nothing is written back to us.
A key you paste is kept in your own account properties (Sheets) or in your own browser (Excel), never in a cell, and it travels only in the request header. Without a key the add-ons use the lookup tier that needs no key.
The answer is written into the columns beside your range: the record status in words, the page address, and the time of the check. An outage is written as "Could not check", never as an absence.
Contact
Questions about this page go to the form on the front page. A person reads it and replies by email.