Last updated: April 2026.
PatchLeaks (pwn.az) is a self-hosted security-research site. This page describes what
data we collect, what we don't, and how to contact us with privacy questions.
What we do not collect
- No third-party analytics by default. We do not run Google Analytics, Meta Pixel, or any ad-network tracking script on public pages.
- No cookies for advertising or cross-site tracking.
- No sale of personal data. We do not sell, rent, or share personal data with third parties for marketing purposes.
What we do collect
- Access logs. Our web tier (Cloudflare + the PatchLeaks server) records standard request metadata — IP address, user agent, request path, timestamp, response code — for abuse prevention, capacity planning, and debugging. Logs are retained for up to 30 days and are not shared with third parties.
- Search Console / Webmaster Tools. If you are a verified operator of
pwn.az, Google Search Console or Bing Webmaster Tools may collect aggregated crawl and query data about this site. See the respective providers' policies for details. - Cloudflare. PatchLeaks is served via Cloudflare's reverse proxy. Cloudflare may collect standard edge-traffic metadata. See Cloudflare's privacy policy.
Embedded third-party resources
Public pages fetch web fonts from fonts.googleapis.com /
fonts.gstatic.com. Font requests expose standard HTTP metadata (IP, user agent) to Google.
We plan to self-host fonts in a future release to remove this dependency.
Your rights
If you are in the EU / UK / California and want to request deletion of any access-log entry attributable to you, or otherwise exercise data-subject rights, email [email protected]. We will respond within 30 days.
Changes to this policy
Material changes will be noted in-line with the date above. The current version lives at /privacy.