No cookies · No accounts · No analytics

Privacy

A museum should not need to know who is standing in the room. This one does not: there is nothing to sign up for, nothing that follows you between visits, and no measurement of who came or what they looked at. What little the museum does keep is set out below, in enough detail that you can check it rather than take it on trust.

Cookies

The museum sets none at all. Not for analytics, not for advertising, not for preferences. There is nothing to consent to, which is why you have not been asked.

The one exception is described under Economic support below, and it does not happen unless you press a button.

What is kept in your browser

Two lists, stored by your own browser and never sent anywhere:

programming-museum:collection
The works you have kept. A list of names like nanoid — nothing else.
programming-museum:admired
The works you have admired, so the museum does not offer you the same button twice. Also just names.

Neither is written until you press the button that creates it, neither contains an identifier of any kind, and neither leaves your machine. Clearing your browser’s data for this site removes both, and nothing is lost but your own collection.

What reaches the museum

Admiration counts. Pressing admire adds one to a number. The whole record is a work’s name and a count — no visitor, no time, nothing to join it to anything else.

Submissions. Fault reports, suggested works and words to the curators are stored as you wrote them, with the date. There is no contact field anywhere in the form, so there is no way to reply to you — which also means that if you put your name or address in the message itself, that is what gets kept. Please do not.

Your IP address

Two things read it and neither stores it. Submitting or admiring uses it as a rate-limiting key, so that one visitor cannot flood the museum; and the anti-spam check described below is told which address a submission came from, because that is how it judges.

It is not written to the museum’s database, and there is no log of who looked at what.

The anti-spam check

The support form is protected by Cloudflare Turnstile, which decides whether a submission came from a person. It loads a script from Cloudflare and receives your IP address and a one-time token. It sets no cookies — you can confirm that in your own developer tools.

Economic support

The tip jar on the support page is Ko-fi’s, and it is the only part of this site that loads anything from anyone else. Their panel sets cookies for Google Analytics and Google Ads and loads PayPal’s code.

So it is not loaded for you. Nothing is fetched from Ko-fi until you press the button that asks for it, and if you never press it, nothing about you ever reaches them. Once you do, Ko-fi’s own privacy policy governs what happens next; the museum never sees your card details either way.

Who runs the servers

The museum is hosted on Cloudflare, and its database is Cloudflare D1. They operate the machines the site runs on and handle the traffic reaching it, under their own terms. The museum keeps no analytics of its own on top of that.

No accounts, no email, no tracking

There is nothing to sign up for. The museum holds no email addresses, sends no messages, has no newsletter, runs no advertising and shares nothing with anyone — because it has nothing to share.

Last reviewed 7 September 2026. If any of the above stops being true, this page changes with it — and if you think something here is already wrong, that is exactly the sort of thing the fault report is for.

← Atrium