Privacy

What this site collects, and what it does not. Last updated 27 August 2026.

What we do not take

No payment details — nothing on this site is for sale and there is no checkout. No personal information: no name, email address, password, wallet connection or exchange API key is asked for anywhere. There are no accounts today, so there is nothing to register for and nothing to sign into. If that changes, this page changes with it.

Analytics

Two counters run here: Cloudflare Web Analytics and Google Analytics 4. Cloudflare's has been permitted since 27 August 2026; Google's was installed between 17 and 19 August 2026, removed, and restored on 27 August 2026. They answer different questions, which is the only reason both are here: Cloudflare's says whether anybody loaded a page, cheaply and without a cookie, and stops there. Google's says which page a reader went to next and how long they stayed — the number that decides which of the fifty contract pages is worth writing more about. Each is described below, separately, including what each one costs you.

Cloudflare Web Analytics

A script Cloudflare injects into this site's pages at its edge. It was blocked by this site's Content-Security-Policy until 27 August 2026 and is now allowed by it.

What it sends: the page's origin and path, the referring page if your browser supplies one, and page-load timings taken from the browser's own Performance API. Cloudflare states that it "does not collect or use your visitors' personal data" and that it "does not track individual end users across our customers' Internet properties" — their documentation.

Those are their words. These are measurements, made on 27 August 2026 and repeatable by anyone:

ClaimHow it was checked, and how you can
It sets no cookie and no browser storage The beacon's source contains no document.cookie, no localStorage, no sessionStorage and no indexedDB — fetch the script named in this page's markup and search it. Loaded on a live site running the same beacon, the page ended with zero cookies and zero storage keys.
It does not send the query string The beacon reads location.pathname and location.origin and rebuilds the URL from those two. It never reads location.href or location.search; neither string appears in the file at all. This is the reason the calculators below are unaffected by it.
It does not fingerprint No canvas, no audio context, no device enumeration in the source. What it reads is the Performance API, which reports how long the page took to load and nothing about you.
The data goes to this domain, not a third one The measurement is posted to /cdn-cgi/rum on this origin, so this counter sends nothing to a third party. The site's connect-src is no longer 'self' alone: it also names Google's analytics hosts, because the second counter does. That difference is set out below.

Two hosts are permitted to serve a script here: static.cloudflareinsights.com and www.googletagmanager.com. There is no third — you can read the whole policy in this page's response headers.

Google Analytics 4

This page said, until 27 August 2026, that Google Analytics was gone and was not coming back. It is back, by the site owner's decision on that date, and the sentence is replaced rather than quietly deleted — a privacy page that revises its promises without saying so is worth less than one that never made them.

What that costs you, stated plainly. GA4 sets cookies — _ga and _ga_5Y4ZENWMQJ, both named in the table below — and it sends data to Google, a third party, which the Cloudflare counter does not. Google's own terms and processing govern what happens to it after that; nothing on this page can promise otherwise, so nothing on this page does.

What is switched off, and it is checkable in this page's own markup: Google signals is off, ad personalisation is off, and IP anonymisation is on. Those are the advertising features of GA4 — the part that follows a reader between sites — and this site has no ad account, sells nothing and remarkets to nobody, so they are turned off in the configuration call rather than merely unused. Search for allow_google_signals in the source of this page.

There is no consent banner here, and that is a position rather than an oversight. A strict reading of the ePrivacy Directive requires asked-for consent before an analytics cookie is set, and this site does not ask. If you would rather it did not, blocking www.googletagmanager.com stops it completely — every browser-level tracker blocker already does, and nothing else on this site depends on that host. The Cloudflare counter is unaffected either way, and this page will say so if that changes.

The script is loaded after the page has finished — on the first scroll, tap or key you make, or when the browser goes idle, or three seconds in, whichever comes first. That is not a privacy measure; it is a speed one. Measured on this site in August, gtag.js added 145.8 KB over the wire and about 419 KB of JavaScript to parse, on pages whose own budget is under 70 KB. Deferring it keeps the page fast and still counts the visit.

Cookies and local storage

NameKindPurposeExpires
rail Cookie Whether you collapsed the sidebar. Two possible values; not an identifier 1 year
coinliqui.pinned Local storage The coins you pinned on your watchlist. Never sent anywhere Until you clear it
_ga Cookie · Google Analytics A random identifier for your browser, so a second visit is counted as the same browser rather than a new one. Set by gtag.js on this domain 2 years
_ga_5Y4ZENWMQJ Cookie · Google Analytics Session state for this specific property — when the current visit started and how many there have been. Named after the measurement ID, so it changes if that does 2 years

Four entries. The first two are this site's own and hold no identifier; the last two are Google Analytics and do — blocking www.googletagmanager.com prevents both, and the Cloudflare counter still sets nothing either way. Clearing your browser data removes all four and the site behaves the same without them.

The calculators

The calculators compute in the page and store nothing. Their forms submit as GET, so the values you enter appear in the page's own URL — which is what makes a result shareable, and also means those numbers reach ordinary web-server request logs. Nothing links them to you, but if you would rather a real account balance did not appear in a log line, use a representative figure.

Those request logs are the only place the values go. Both counters rebuild the URL from the origin and the path, so a figure typed into a field named capital is not part of what either one sends. That is a measurement of the two requests, not an assurance.

It has not always been true, and this page said it had stopped when it had not. The Google tag sends the full URL of every page view — query string included — unless it is told otherwise, and it was not told otherwise. That was the case from the day the tag first went in, through its removal on 19 August 2026, and again from its restoration on 27 August; the paragraph here described it in the past tense throughout those last four days, saying the sending had ended when the tag came out. It had not: the tag came back. Measured on 31 August 2026, loading the position-size calculator with figures in its URL produced a request to Google carrying that whole URL, those figures included. On the same day the tag was configured with page_location set to the origin and the path — the rule the Cloudflare beacon already followed — and re-measured. Nothing about the request logs above changed; what changed is that Google no longer receives the query string.

Hosting

This site runs on Cloudflare. Serving a page means Cloudflare handles the request itself — your IP address, the page asked for, the browser string, the response status — and keeps aggregate traffic and security metrics from it. That much is true of any web host and is not optional for a site that is served at all.

The measurement script described above is Cloudflare's too, and it is injected by the host rather than written into this site's source: it appears in the HTML after this site's code has finished with the response, and it does so whenever a client asks for the page the way a browser asks for it. It was blocked here until 27 August 2026 and is permitted now. Nothing else off-origin can serve a script, receive a fetch, or load an image on any page here.

Contact

Questions about any of this, including a request to delete data associated with your visits: hello@coinliqui.com.

Where to go next