Skip to content

Privacy

FreedomLens collects nothing about you unless you agree to it, and you can take that back at any time from the footer of any page. The single exception is your answer to the question itself, which is counted either way and is described below. This page says what is collected when you do agree, who else touches it, how long it is kept and how to have it deleted.

Last changed 12 August 2026

Your choice

There is no analytics id in this browser, so there is nothing filed under one.

Who is responsible

FreedomLens is run by Simon Pokorny in the Czech Republic, as an independent, non-commercial project, and that is also the controller of the data described below — the decisions on this page are one person’s, and so is the answer if you disagree with them. Write to [email protected] about anything here, including a request to delete what has been collected. There is no data protection officer; the site is nowhere near the size that requires one, and that address reaches the same person.

What is collected, if you agree

One record when the viewer is ready to use, and one per meaningful action — opening a page, choosing a statistic, switching view, selecting countries, sharing, or moving the year. The complete list lives in one source file, src/shared/analytics/events.ts, and nothing outside it is sent. Each record carries:

  • What happened — the name of the action, and what was on screen at the time: which statistic, which view, which region, which year, and how many countries were selected. Which countries a reader looks at says something about the reader, so the count is recorded and the names are not.
  • Which page — the address without its query string. This site keeps the whole state of the viewer in the query string, so trimming it is not cosmetic: it is what keeps a shared link out of the record.
  • What you are reading on — browser and operating system and their versions, device type, screen and window size, language, and time zone. This is what every web server can see; it is recorded because a layout problem on a narrow screen is otherwise invisible.
  • Where you arrived from — the address of the page that linked here, also without its query string, and whether it was a search engine.
  • A random id — generated in your browser, stored there, and attached to the records so that ten actions in one visit read as one visit rather than as ten strangers. It is not derived from anything about you and means nothing outside this site.
  • When — the time of the action.
  • Technical version — the analytics schema number and site release, so changes in measurement can be separated rather than silently mixed into one trend.

What is counted whichever way you answer

One record, when you press one of the two buttons. Whichever way you answer, it holds four things and nothing else:

  • The answer — the word granted or denied.
  • Which control you used — the notice that appears on a first visit, or the button in the footer and on this page that changes an answer already given.
  • Which version of the notice you were shown, and the release of the site you were reading.
  • When — the time you pressed it.

There is no id on it. Every one of these records carries the same fixed label instead of the random id described above, so they cannot be told apart, cannot be counted as people, and cannot be joined to anything else — not to each other, not to a later visit, and not to any of the records in the section above if you did agree. Nothing about your browser, screen, language or location is in it, and nothing is written to or read from your device to produce it. If you said no, this is the only thing that is ever sent, and nothing follows it.

It exists because the alternative is not knowing. Counting only the people who agree gives a number with nothing to compare it against, and the question worth answering — whether the notice above is clear enough for a reader to decide either way — cannot be asked without counting both answers the same way. It is sent to the same processor, kept for the same 12 months, and used for that one purpose.

What is never collected

  • Your name, email address or any account — there are no accounts on this site and nothing here asks who you are.
  • Your IP address as stored data. It reaches the server the way it reaches every website you visit, and is discarded instead of being kept.
  • Your location. Location is not derived from your network address or stored with analytics records.
  • Advertising and click identifiers. If you arrive from a link carrying one — gclid, fbclid and the rest — it is stripped before the record is sent, because it is the one thing in a URL that an ad network can join back to a person.
  • Recordings of your session, your mouse movements, your keystrokes, or the contents of anything you type. PostHog can do all of this and it is switched off in the configuration, not merely left unused.
  • Automatic capture of every click and the text on it. Only the actions in the file named above are sent.
  • Anything that builds a profile or makes a decision about you. Nothing here is sold, shared for advertising, or used to decide what you are shown.

Who else touches it

Three companies, and only one of them has anything to do with analytics. All three are processors: they act on instructions and do not use the data for their own purposes.

  • PostHog — the analytics if you agree, and the record of your answer either way. Those are the only two things it ever receives from this site: decline and it gets one record saying so, described above, and nothing after it. The project runs on PostHog Cloud EU, hosted in Frankfurt, Germany, so the records are stored inside the European Union. Events reach it through v.freedomlens.org, a proxy PostHog operates on a subdomain of this site; it changes the address the request is sent to and nothing about who receives it, what is in it or how long it is kept. PostHog is a US company and publishes its own sub-processors and security practices; where its staff can reach EU data for support, that access is covered by its data processing agreement and the standard contractual clauses in it.
  • Cloudflare — every request for this site reaches Cloudflare first. It answers the domain, holds the HTTPS certificate and passes the request on to the server. That means Cloudflare sees your IP address and which page you asked for, on every visit, whatever you answered about analytics. It is what puts a network between the public and a small server, and it is not optional in the way analytics is: without it there is no site.
  • Hetzner — the server the files sit on, in Germany. It is reached only through Cloudflare; it has no public web address of its own.

Mail sent to the address on this page is handled by Proton Mail, in Switzerland, which the European Commission recognises as providing adequate protection. That is correspondence rather than analytics: if you write in, what you wrote is kept until the matter is dealt with.

Nothing else is contacted, and nothing at all is loaded from another domain. The typefaces are served from this one rather than from a font network, the map and every statistic are files on this server, and there are no advertising, social or embedded video scripts of any kind. Analytics is the one exception, and it does not look like one: it is sent to v.freedomlens.org, which reads as part of this site and is not. It is a proxy PostHog runs on a subdomain pointed at them, and it forwards to PostHog Cloud EU. It is named here because a subdomain of this site is precisely where you would not think to look for somebody else’s collection point, and because a browser extension that blocks analytics by domain will not recognise it. The consent notice is the control that works. If you decline, your browser makes exactly one request to that address — the record of the refusal itself, described above — and none after it, for as long as that answer stands. The analytics library is not downloaded at all.

What is stored in your browser

This site sets no cookies. Up to three entries in local storage, and never more than two at once:

KeyWhat it holdsWhen it is written
fl.consent.analytics.v2Your answer to the notice — the word granted or denied, and nothing else.When you answer. Without it the notice would have to ask again on every page, so it is written whichever way you answer.
ph_…_posthogThe random id described above, and PostHog’s own bookkeeping about the current visit.Only if you agree. Deleted when you turn analytics back off.
__ph_opt_in_out_…A single 0, marking the analytics code itself as switched off.Written in place of the entry above when you withdraw, so that nothing can start again by mistake.

You can clear both yourself at any time through your browser’s site data settings, and turning analytics off above clears the second one for you. An earlier version of this site did set one cookie, through the analytics library’s default settings; it is deleted the next time you load a page here, whether or not you agree to anything.

How long it is kept

Records are deleted after 12 months. Nothing here is worth keeping longer: the question analytics answers on this site is which statistics people actually open, and the answer to that from two years ago does not describe today’s site. Your answer to the consent notice stays in your browser until you change it or clear your site data — it is the record that you were asked, and deleting it would mean asking again.

Why this is allowed

Everything in the first list above rests on consent, and only consent — Article 6(1)(a) of the GDPR, and Article 5(3) of the ePrivacy Directive for the id kept in your browser. That includes the pageview: a count is convenient for us and not necessary for you, so it waits to be asked for. Withdrawing consent does not make what was collected before unlawful, but it does stop anything further and clears the id it was collected under.

The record of your answer is the one thing that does not, because consent cannot be the basis for measuring a refusal — a refusal would then delete itself. It rests on legitimate interest, Article 6(1)(f), and Article 5(3) of the ePrivacy Directive does not apply to it, because nothing is written to your device and nothing is read from it to produce that record: it carries only what you pressed. Relying on that basis means the three questions behind it have to have been asked and the answers written down, so here they are.

  • The purpose — knowing whether the notice above can be understood well enough to be answered either way. Counting only the people who agree gives a numerator with no denominator, and a notice whose refusal rate is unknown cannot be told apart from one nobody can work out how to refuse.
  • Why nothing smaller would do — there is no version of this that consent can carry, and there is no less intrusive record than the one described above: it holds four constants and the button you pressed, with no identifier, and both answers travel by the same one request so that neither is undercounted relative to the other. The only alternative to it is not knowing.
  • What it costs you — as far as we can make it, nothing. The record describes nothing about you, carries no id, cannot be counted as a person, and cannot be joined to anything else, so there is very little on your side of the balance for the purpose above to outweigh. You would not be surprised by it, which is the test that matters, and this section is the reason you would not be.

That assessment is kept in writing rather than asserted here — it is docs/LEGITIMATE_INTEREST_ASSESSMENT.md in this site’s source, and a copy will be sent to anyone who asks at the address below. You can object to the record under Article 21 at that same address, though with no id on it there is nothing to point an objection at afterwards — which is the same consequence, and the same reason, as the deletion section explains. Objecting stops the next one: decline the notice and nothing further is sent for as long as that answer stands.

Charts embedded on other sites

FreedomLens charts can be embedded in an iframe on another site, at /embed. Analytics never runs there. A reader who meets one of these charts inside somebody else’s article did not come here, was never shown the notice, and has no control to withdraw with — so an answer given on this site is not treated as covering that one, and the analytics code is not even loaded. The embed still fetches the statistics it draws from this server, which is what makes it work.

What the server sees anyway

Loading any page means your browser asking a server for files, and that request carries your IP address, the file you asked for and your browser’s identification. This happens whether or not you agree to analytics, on every site there is, and it is how the web works rather than something this project chose. It is also, on this site, the only place your IP address is handled at all — analytics never receives one.

Cloudflare records those requests at its edge as part of running the network and defending it, on its own retention, and its documentation describes what it keeps. That is Cloudflare’s processing on this site’s behalf, and it is the honest answer to “who can see that I came here”. The origin server behind it is configured not to write an access log at all, so requests are served and not recorded there; what it does keep is the operating system’s own record of administrative logins and service restarts, which is about the machine and not about readers, and it rotates within 4 weeks.

None of this is analytics. It is not joined to anything in the sections above, it carries no identifier that could be, and it is never used to work out what anybody looked at. The lawful basis is legitimate interest, Article 6(1)(f): a site that cannot be served and cannot be defended is not a site.

Your rights

If you are in the EU or the UK, the GDPR gives you the right to ask what is held about you, to have it corrected, to have it deleted, to have its use restricted, to object to it, and to receive a copy in a portable form. You can withdraw consent at any time and it is as easy as giving it was — the same button, in the footer of every page. None of it costs anything, and using any of it changes nothing about how the site works for you.

You can also complain to a data protection authority without asking here first. The one supervising this site is the Czech Office for Personal Data Protection, and you may equally go to the authority in the country you live in — the European Data Protection Board lists them all.

Having it deleted

Write to [email protected]. Include the analytics id shown at the top of this page, because it is the only handle there is on your records — nothing collected carries a name, so a request without the id cannot be matched to anything. You will get an answer within one month, which is the limit the GDPR sets, and usually much sooner.

If you have already cleared your browser storage the id is gone and no request can find those records again. That is a consequence of not collecting anything that identifies you, rather than a way of avoiding the question: what is left is a scattering of rows saying somebody opened the press freedom map, with nothing to tie them to a person.

Children

The site is for anybody who wants to compare these statistics, including school-age readers, and it asks nobody their age. Nothing collected here would identify a child any more than it identifies an adult, and there is no profiling, no advertising and no messaging to anybody.

Changes to this page

The date at the top says when it last changed. If what is collected changes in a way this page does not already describe, the notice is shown again and the previous answer is not carried over — consent given to one description is not consent to a different one.

Terms · Where the statistics come from