Privacy
Analytics, submissions and saved conversations
How Scrutica processes information from its visitors.
Scrutica collects usage information to understand how the site is used and processes the information you submit to its forms and Query Builder.
What is collected
- Usage analytics
- Page views and interactions are measured with PostHog, Google Analytics and Vercel’s Web Analytics and Speed Insights. These services receive information such as the visited page, referring site, browser, device and performance timings. IP addresses support approximate location estimates. Google Signals and ads personalization are disabled.
- Session replay
- PostHog is configured to record sessions without sampling, including page content, clicks, scrolling and console output. Form inputs are masked in replay, and network request bodies are not recorded. Request headers are recorded. This masking applies to replay; information submitted to a form or Query Builder is processed separately as described below.
- Cookies
- Google Analytics and PostHog use first-party cookies that persist between visits to recognize returning browsers. PostHog also stores its identifier in local storage. You can remove these identifiers through your browser’s site-data settings.
- Programmatic-access telemetry
- MCP requests send PostHog the invoked tool, query text and selected arguments, client details, response status and timing. The request IP address is sent for geolocation; a hash of the IP address and user agent identifies repeat requests. Person-profile creation is disabled for these events. Crawler telemetry records the requested path and user agent, grouped by bot family.
- What you submit
- Subscriptions store your email address and notification preferences. Correction suggestions store the proposed change, explanation, source URL and any contact address you supply. These submissions are held in Scrutica’s Supabase database for updates and editorial review.
- Query Builder conversations
- Query Builder sends your question and conversation history to Anthropic, or through OpenRouter to the model provider serving the request. The configured fallback models include OpenAI models. Completed conversations are saved in Supabase and accessible through their public links; private conversations are not currently available.
- Request limits and hosting logs
- Request limits use IP-address-based counters. Vercel hosts the site and processes requests and operational logs; Upstash holds the shared rate-limit counters.
Accounts and advertising
Scrutica has no user accounts or account passwords. Reading preferences are stored in your browser. Scrutica does not run third-party advertising, embed social-media trackers or sell personal data.
Who processes data on our behalf
Vercel provides hosting and performance analytics; Supabase stores submitted records and conversations. PostHog provides analytics and session replay, and Google provides analytics. Upstash handles shared request-limit counters. Anthropic and OpenRouter process Query Builder requests, with the serving model provider receiving conversation content. Map pages request tiles directly from Mapbox.
Retention and your choices
Analytics and request telemetry are sent to the services named above; their retention settings govern how long they are held. Submissions and saved Query Builder conversations are stored separately in Scrutica’s database. Browser tracking protection can limit analytics collection.
For requests to remove a subscription, suggestion or saved conversation, or for questions about this policy: davidgringras@hsph.harvard.edu.
Agents and crawlers
Automated clients are welcome; Scrutica for agents lists the endpoints and request limits. Programmatic access is subject to the MCP and crawler telemetry described above.