We collect almost nothing. We don't require accounts. We don't track you across the web. If you use our APIs, we log usage for rate limiting. That's it.
What We Collect
- IP addresses — Used for rate limiting only. Automatically purged after 24 hours.
- API usage metrics — Anonymized request counts per endpoint. No personal identifiers attached.
- Cookie preferences — If you dismiss a banner or set a preference, we remember that choice.
If you opt into the showcase and submit a project, we store the project name, description, and links you provide. You control this data and can remove it at any time.
What We Don't Collect
- Personal identity (no accounts required for most features)
- Browsing history
- Keystroke data
- Device fingerprints
- Location data
- Contact lists or social graph information
Cookies
We use a session cookie only if you are actively using tools that require state. No analytics cookies. No tracking cookies. No third-party cookies of any kind.
For the full cookie breakdown across the ecosystem, see the EWEPIP Cookie Policy. KNUCKLEDRAGGER is minimal by design.
Third Parties
Cloudflare provides CDN, DDoS protection, and tunnel routing for this site. Cloudflare may set minimal security cookies as part of their service. That's it.
We do not use analytics services. We do not use ad networks. We do not embed social media widgets. We do not use tracking pixels.
Cross-Domain
If you use the OMNIA widget to navigate to ewepip.net or other domains in the ecosystem, those domains have their own privacy policies. We do not share KNUCKLEDRAGGER data with other domains unless you explicitly connect accounts through the OMNIA identity system.
The shared navigation bar is a convenience feature. It does not transmit data between domains on its own.
Data Retention
- API logs: 7 days, then automatically deleted
- Session data: Deleted when you close your browser
- Showcase submissions: Retained until you remove them
- Rate limiting records: 24 hours maximum
Your Rights
You can request deletion of any data we hold by emailing [email protected]. Since we barely collect anything, there's usually nothing to delete. But we'll confirm either way.
If you are in the EU (GDPR) or California (CCPA), your rights under those regulations are respected. Since we collect minimal data, compliance is straightforward.
Security
- All traffic encrypted via TLS (HTTPS enforced)
- Rate limiting on all API endpoints
- No persistent storage of sensitive data
- Cloudflare WAF for DDoS and bot protection
- No user database to breach (for most features)
Contact
Questions about privacy? Email [email protected].