Privacy Policy
XOPS360 collects audience intelligence signals to understand who reads this content and whether it reaches the professional communities it's written for. This policy documents exactly what is collected, why, and what it cannot determine.
1. What We Collect
Network-layer signals (Cloudflare infrastructure)
Every request to xops360.com passes through Cloudflare's network before reaching our servers. Cloudflare enriches each request with the following data, which we record:
| Signal | What it tells us |
|---|---|
| Country, region, city, postal code | Geographic audience composition. Derived from IP address — not GPS. |
| Latitude / longitude | IP-derived geographic coordinates. Same signal reported by Google Analytics, Cloudflare Insights, and every major CDN. Used for regional content demand mapping, not individual tracking. |
| Cloudflare datacenter (colo) | The closest Cloudflare point of presence to your location. More reliable than city-level IP geolocation. |
| Autonomous system number and organization | Your ISP or employer's network identifier. Examples: "Comcast Cable", "Booz Allen Hamilton", "Department of Veterans Affairs". Derived from public IP routing tables. Used to understand organizational audience composition — not to identify individuals. |
| Timezone | Used to infer working-hours patterns across audience segments. |
| HTTP protocol, TLS version | Connection quality and security posture signals. |
| EU country flag | Regulatory jurisdiction identifier for GDPR scope. |
Browser environment signals
A script runs in your browser when you visit any page. It collects the following signals and sends them to our analytics endpoint:
| Signal | What it tells us |
|---|---|
| Screen width, height, pixel ratio, color depth | Device class. The combination of 1280×1024 at 1× DPI is a virtual desktop signature. High DPI Retina screens indicate personal devices. |
| Viewport dimensions | Effective reading width — what content the visitor actually sees. |
| CPU core count, device memory | Hardware class. ≤4 cores at ≤2 GB is a virtual/constrained environment signal. |
| Touch points | Distinguishes mobile/tablet from desktop. |
| Browser language, language count | Locale and multilingual profile. |
| Timezone | Browser-reported timezone, compared against IP-derived timezone for proxy detection. |
| Color scheme preference | Light or dark mode — inferred from OS/browser settings. |
| Reduced motion preference | Accessibility signal; also correlates with certain managed device configurations. |
| Connection type, downlink, round-trip time | Network quality. "wifi", "4g", "2g" classifications from the browser's Network Information API. |
| Save-Data flag | Whether the browser has requested reduced data usage. |
| Cookie status, Do Not Track | Browser privacy configuration. DNT is recorded as a signal; this site does not treat it as a mandatory opt-out. |
| Permission states (notifications, geolocation, camera, microphone) | Whether these APIs are in "granted", "denied", or "prompt" state. We query the state — we do not request the permissions or access any data behind them. "Denied" across all APIs with no prompt history indicates a managed enterprise device. |
| Navigation type | Whether the page was reached via navigation, back/forward cache, reload, or prerender. |
| Page load time, DOMContentLoaded time | Site performance measurement. |
Behavioral signals
| Signal | What it tells us |
|---|---|
| Engaged time (milliseconds) | Total time the page was in the foreground and visible. Excludes time spent in other tabs. |
| Scroll depth (percentage) | How far into the page content you scrolled. Used to measure content completion rates. |
| Outbound link clicks | When you click a link to an external site, we record the destination URL and visible link text. We do not track where you go after leaving. |
| Autofill detection | If browser autofill populates a form field, we detect that the event occurred and record the field type (e.g., "email", "name"). The value autofill inserts is never read or transmitted. This confirms a returning browser with saved data, and whether the visitor abandoned a form without submitting. |
| Connection changes | If your network connection type changes during a visit (e.g., wifi to cellular), we record the new connection profile. |
Canvas and WebGL rendering signatures
During a low-priority idle period, we render a test pattern using your browser's Canvas 2D and WebGL APIs. The rendered output varies based on your GPU, graphics driver, and operating system font rendering. We compute a one-way hash of the output and store only that hash. The rendered image is never stored or transmitted. The hash helps identify returning devices when browser storage has been cleared.
Session and visitor identity
We generate a random UUID (universally unique identifier) for each browser and store it in your browser's IndexedDB. A separate session UUID is stored in sessionStorage and resets when you close the browser tab. These identifiers are random strings — they contain no personal information and are generated locally in your browser, not assigned by our servers.
We also compute two fingerprint hashes from stable hardware signals (screen resolution, color depth, CPU count, timezone, language, touch points). These hashes are used to recognize a returning device if IndexedDB has been cleared. The hash is computed locally and cannot be reversed to recover the individual signals.
2. What We Do Not Collect
- Names, email addresses, or any directly identifying personal information
- Autofill field values — only the field type (e.g., "email") is detected, never the content
- The canvas rendering image — only a one-way hash
- Precise GPS location — only IP-derived city and region
- Browsing history outside xops360.com
- Cookies (this site sets no tracking cookies)
- Payment or financial information
- Data from microphone, camera, or clipboard content
3. How This Data Is Used
All collected data is first-party. We do not sell, broker, or share visitor data with third parties. Specific uses:
- Content strategy: Understanding which topics generate depth of engagement vs. surface-level traffic from which audience segments.
- Audience composition: Confirming whether content reaches federal, defense, and technology professionals — the audiences it is written for.
- Site performance: Load time and connection quality measurement.
- Defensive security research: XOps360 analyzes passive signal collection techniques for cleared client assessments. The data collected on this site demonstrates the legitimate version of the same capability. Research outputs are aggregate and never identify individuals.
4. Data Retention
| Data store | Retention |
|---|---|
| Cloudflare Analytics Engine (event-level) | 90 days rolling |
| D1 visitor sessions (aggregate return profile) | 12 months from last visit |
| Google Analytics 4 | Per Google's data retention settings (14 months default) |
5. Third-Party Services
Three external services also collect data when you visit this site:
- Google Analytics 4 — tracks page views and user interactions under Google's own privacy policy. GA4 data is governed separately from our first-party analytics. Google's policy: policies.google.com/privacy.
- Cloudflare — handles all network requests and provides the CF-level signals described above. Cloudflare's policy: cloudflare.com/privacypolicy.
- Giscus (GitHub Discussions) — comment threads on individual blog posts are powered by Giscus, which uses GitHub Discussions as a backend. Giscus only activates when you interact with the comment widget. GitHub's policy: GitHub Privacy Statement.
6. Your Choices
- Browser storage: Clearing IndexedDB removes your visitor UUID, which resets return visitor recognition for this site.
- JavaScript: Disabling JavaScript prevents all client-side tracking. Page content remains accessible. The canvas/WebGL fingerprint and behavioral signals are not collected without JavaScript.
- Canvas/WebGL blocking: Browser extensions that randomize or block canvas fingerprinting prevent the rendering signature from being computed. The hash stored will be the same for all visitors using that extension.
- Permission states: Denying permissions in your browser settings affects the permission state signals we record — not our ability to observe the state itself.
- Network-layer signals: IP-derived location and ASN attribution are inherent to how the internet routes traffic and cannot be opted out of at the application layer.
- EU residents: You may request access to, correction of, or deletion of data associated with your visitor UUID by contacting [email protected]. Because session data is not linked to an email address or name, data subject requests require your visitor UUID from browser IndexedDB.
7. Contact
Questions about this policy or data practices: [email protected]
XOps360 LLC — 808 Carmichael Rd PMB 277, Hudson, WI 54016
This policy reflects collection as of June 28, 2026. Material changes will be noted in the changelog.