---
title: "Privacy · The Pixel"
description: "Everything The Pixel holds about you: the display name you type at checkout, which is public; your IP address, for a few minutes, to rate-limit; a repaint handle your own browser keeps; and your Stripe session. No email, no account, no cookies."
source_url: "https://thepixel.lol/privacy"
markdown_url: "https://thepixel.lol/privacy.md"
site: "The Pixel"
mcp_endpoint: "https://api.openboss.lol/mcp"
---
# Privacy

> No account. No email. No trackers. One public name, and an address we forget
> in a minute.

Last updated 22 August 2026.

## 01 — Everything we hold, in one list

This is the complete inventory. There is nothing kept back for a longer clause
further down.

- **The display name you type at checkout.** It is public, and that is the entire
  point of it.
- **Your IP address**, used for one thing — rate limiting — and deleted when the
  window it was counted in closes.
- **A repaint handle your own browser keeps**, in this site's `localStorage`.
  It is what lets an owner change the pixel's colour.
- **Your Stripe session** — its id, the amount, the colour you chose, and whether
  the bid won.

That is all of it. No email address — Stripe collects one in order to send its
own receipt, and §05 explains why it never reaches us. No account, no password,
no profile, no phone number, no postal address. No cookies at all. Page views are
counted by Vercel Web Analytics, which is cookieless and stores nothing on your
device — see §06. Beyond that there are no third-party trackers of any kind.

The list is short for a structural reason worth stating plainly: **money only
ever moves one way here. There are no prizes, no winnings and no payouts of any
kind, to anyone, ever.** Nothing of value is ever won. So there is no payout to
route, no identity to verify and no bank detail to hold — and none of those
things appear anywhere in this document because none of them exist.
[The terms](/terms.md) say the same thing at length.

## 02 — Your display name is public and it is meant to be

When you buy the pixel, Stripe's checkout page asks you for a name or handle. It
is a required field, capped at 24 characters. That string is the product: it is
what gets shown.

Before it is stored we flatten its whitespace, strip control characters, cap its
length and run it through a mechanical profanity filter. Then it appears, in
public, in three places: on the home page under the pixel, in the sale history,
and in the share image that unfurls when somebody pastes a link to this site.

The sale history keeps the 50 most recent sales; the table on
the home page lists twenty of them and counts the rest. A sale older than that
drops off the list. Separately — and this is the part people do not expect — the
settlement record behind your own payment keeps the name that was on it, and that
record does not expire. It is what your receipt link reads, years later, when you
open it again.

**Do not type anything into that field that you would mind seeing on the internet
permanently.** Not your full legal name if you would rather not, not your email,
not anybody else's anything. It is a handle. Treat it like one.

## 03 — Your IP address, for about a minute

Every request to our API is counted against a sliding window keyed on the address
it came from, so that one machine cannot hammer the bid form, the live stream or
the colour endpoint. That is the only thing your address is used for.

- The counter lives in a sorted set that expires with its own window: **one
  minute** for bidding, repainting and reading the state, **five minutes** for a
  connection to the live stream. Nothing here is kept longer than five minutes.
- It is never written against a purchase, and never joined to a display name.
- It is not used to profile you, to guess where you are, to price anything
  differently, or to decide anything about you.

Separately from that, the web servers in front of this site write ordinary access
logs, which is what web servers do — the pages are served by Vercel and the API
runs behind a reverse proxy on a rented server. Those logs contain IP addresses.
They are operational records for keeping the site up and working out why it fell
over, they are not read for anything else, and they are not joined to a purchase.

## 04 — What your browser keeps, and no cookies

This site sets **no cookies**. It stores three values in your browser's own
`localStorage`, all under a `vm.pixel.` prefix, and they never leave your
device except when you use them:

- **The repaint handle**, plus the price and name of the sale it came from, so
  the page knows whether to draw the repaint control.
- **The last Stripe session id**, so the receipt page can find your purchase after
  the redirect back from Stripe.
- **The last amount you bid**, to prefill the "bid again" box.

The handle is worth being precise about, because it is a credential. It is a
signed string derived from your Stripe session id — it is not the session id and
cannot be turned back into one. It authorises exactly one thing: changing the
colour of the pixel, while its holder is the current owner. The moment somebody
outbids you it stops authorising anything at all.

Clear your site data and the handle is gone. You can get it back: **reopen your
receipt link and the server derives it again** — that link works forever and is
the reason to keep it. **If you have lost both the handle and the receipt link,
we cannot restore them, because we have no way of knowing who you are.** There is
no account here and no email address on file. That is the trade: nothing to log
into, and nothing to recover you by either.

You can delete all three at any time by clearing this site's data in your
browser. Nothing on the page breaks if you do — a browser that refuses storage
entirely still renders and still works.

## 05 — Payments go through Stripe

Stripe processes every payment on its own hosted checkout page. **Your card
number never reaches our servers and we never see it.** What Stripe collects in
order to take a payment — including an email address for its own receipt — is
governed by Stripe's privacy policy, not this one.

That email address never enters our systems. The code that reads a completed
session leaves it alone on purpose, so it is not stored here, not logged here and
not returned by any page on this site — a Stripe session id cannot be turned into
somebody's inbox. It does exist inside Stripe, where whoever operates this site
can see it beside the payment, the same way any merchant can; that is Stripe's
system and Stripe's policy, not ours.

What we keep from a payment is the session id, the amount, the colour you chose,
the name you typed, whether the bid won, and when it settled. Those records are
kept indefinitely, and §08 explains why.

We hold no bank details and no payout account, because there are no payouts. If
we ever do refund a payment — which [the terms](/terms.md) are clear is a choice we
make one payment at a time and not a right you have — it goes back through Stripe
to the card that paid, and we never learn anything new about you in the process.

## 06 — What this site does not do

All of the following are verifiable in the source, not promises:

- **One analytics tool, and it is cookieless.** Vercel Web Analytics records
  which page was opened, roughly where in the world from, and what kind of
  browser. It sets no cookies, writes nothing to your device, stores no IP
  address, and identifies a visit by a hash of the request that is discarded
  after 24 hours — so it cannot recognise you tomorrow and cannot follow you off
  this site. The receipt page carries your Stripe session id in its address; that
  is stripped before the page view is sent, so your purchase id never reaches an
  analytics provider. No product analytics, no session recording, no heatmaps, no
  A/B testing tool.
- **No third-party trackers or advertising pixels.** No ad network, no
  retargeting, no social embeds.
- **No fonts fetched from anybody else.** The two typefaces are downloaded at
  build time and served from this site, so your browser never asks a font CDN for
  anything.
- **No profiling and no automated decision-making.** Nothing about you is scored,
  segmented or decided by a machine.
- **No AI processing of anything you type.** The name you enter is not sent to a
  language model, and neither is anything else about you.
- **We do not sell, rent, or share personal data with anyone for their own
  purposes.** Not now, and there is no business here that would be improved by
  it.

## 07 — Who else touches any of it

Three, and this is the complete list:

- **Stripe** — takes the payment and holds the card data we never see.
- **Vercel** — serves these pages, keeps ordinary server logs while doing it, and
  runs the cookieless page-view counter described in §06.
- **Our own server** — a rented machine running the API and its database, behind
  a reverse proxy that also keeps ordinary access logs.

Beyond those, data leaves only when the law requires it — a valid legal request,
or a payment dispute where the evidence is the record of what was sold and what
the buyer was told before they paid.

## 08 — How long any of it lasts

- **The current owner's name, price and colour** — until somebody outbids them,
  at which point it moves into the sale history.
- **The public sale history** — the 50 most recent sales.
  Older ones fall off the end of the list.
- **The settlement record for one payment** — the session id, the name at the
  time, the amount, the outcome and the colour. Kept indefinitely.
- **Rate-limit counters** — deleted when their window closes, five minutes at the
  outside.

The settlement record is the one that does not expire, and the reason is not
laziness. It is the record that a payment was settled, and it has to outlive every
consequence of that payment. Your receipt link is a URL that sits in a bookmark
forever; when you open it, that record is what answers. A version of this system
that expired those records after a week refunded a winner who reopened their own
receipt eight days later. It is a few hundred bytes per sale and it stays.

There is no other store. No customer database, no profile, no mailing list, no
data warehouse, nothing waiting to be joined up later.

## 09 — Your rights, and what erasure actually reaches

If you are in the UK or the EEA you have the rights the GDPR gives you: to know
what we hold, to have it corrected, to have it erased, to restrict or object to
how it is used, and to receive a copy. You can exercise any of them by writing to
ziga@flisko.si.

**Include the date and the amount of your payment, and the name you typed.** That
is not bureaucracy — it is genuinely the only way we can find you. There is no
account to look you up by and no email address on file.

Erasure is worth being exact about, because a vague promise here would be one we
could not keep. **We can take your display name off the site: everywhere it is
shown — the pixel, the sale history — it is replaced with `[removed]`. There is
a tool for exactly that and it takes seconds.** What stays is the sale itself: the
amount, the time, and the settlement record behind that payment's own receipt
link, which still carries the name that was on it. That is the record of money
changing hands, we keep it for accounting and for defending a payment dispute, and
[the terms](/terms.md) say the same thing.

The legal bases, for completeness. Showing the name you bought and settling your
payment is performance of a contract. Rate limiting, keeping the site standing and
holding evidence for a chargeback are legitimate interests. Keeping records of a
sale is a legal obligation. We do not rely on consent for any of it, which is why
there is no cookie banner — there are no cookies to consent to.

If you think we have handled something badly, write to us first; if that gets you
nowhere, you can complain to the data protection authority where you live.

## 10 — Age

You must be old enough to enter into a binding contract where you live, which is
the same requirement [the terms](/terms.md) set. This site is not for children, is
not aimed at them, and we do not knowingly take payments from them. If a child has
bought the pixel, write to us and we will take the name down.

## 11 — Changes to this page

When this changes, the date at the top changes with it, and anything material gets
said in plain words rather than absorbed into a paragraph. There is no mailing
list to notify you on, because there is no mailing list.

## 12 — Who is responsible for all this

The data controller is Flisko — Informacijske storitve, Žiga Flis s.p., in Slovenia. Write to ziga@flisko.si
about anything on this page — a request, a correction, or a sentence here that
turns out not to match what the site actually does. A person reads it.

---

## This document

This is the `text/markdown` representation of a page on https://thepixel.lol. Every HTML
page here has one: append `.md` to its path, or send
`Accept: text/markdown`. The HTML page is the canonical one and says the same
things.

- [`/index.md`](https://thepixel.lol/index.md) — the pixel: who owns it right now, and what they paid
- [`/about.md`](https://thepixel.lol/about.md) — what this is, why it exists, and who runs it
- [`/rules.md`](https://thepixel.lol/rules.md) — the mechanics, in bullets, with nothing around them
- [`/pricing.md`](https://thepixel.lol/pricing.md) — what it costs right now, live, and why a cached copy is stale
- [`/terms.md`](https://thepixel.lol/terms.md) — what you are buying; the authoritative document
- [`/privacy.md`](https://thepixel.lol/privacy.md) — everything stored, why, and for how long
- [`/contact.md`](https://thepixel.lol/contact.md) — one email address, and what to put in it
- [`/llms.txt`](https://thepixel.lol/llms.txt) — the site map written for agents, including the read-only public API.

**There are no prizes and no payouts of any kind, ever.** Nothing of value is
won on this site, and the previous owner receives nothing when somebody takes
the pixel from them. Money moves in one direction only. It is an entertainment
purchase, not gambling and not an investment.
