Markets InSecurityPrivacy Policy
Privacy policy

We count visitors. That's it.

Last updated: [DATE] · Operated by [LEGAL ENTITY] (heretics.io)
Template — not legal advice. This reflects a site that runs Google Analytics and nothing else. Have qualified counsel confirm it against your final analytics configuration and the privacy laws that apply to your audience (e.g. GDPR/UK GDPR, CCPA/CPRA) before publishing. Complete the bracketed fields.
The short version

01 Who we are

Markets InSecurity (the "Site") is operated by [LEGAL ENTITY], doing business as heretics.io ("we," "us"). This policy explains what the Site collects and why. Questions: nick@heretics.io.

02 What we collect

We collect only analytics data, through Google Analytics. We do not run user accounts, logins, advertising pixels, retargeting, or third-party trackers beyond Google Analytics. We do not knowingly collect sensitive personal information.

Through Google Analytics, the following is collected automatically when you visit:

  • Pages viewed, time on page, referring links, and on-site navigation
  • Approximate geographic location (typically city/region level, derived from IP — Google truncates the IP and does not log or store the full address in standard GA4)
  • Device, browser, operating system, and screen size
  • A randomly generated identifier (cookie or similar) used to distinguish repeat visits

If you email us, we receive and retain your message and address solely to respond. We don't add you to any list.

03 Cookies & similar technologies

Google Analytics sets cookies (or uses similar identifiers) to measure traffic. These are analytics cookies, not advertising cookies. You can refuse or delete them in your browser settings, decline them in any cookie banner we present, or install Google's opt-out browser add-on. Blocking them does not affect your ability to read the Site.

04 Why we collect it

To understand which teardowns and pages people find useful, how visitors arrive, and how to improve the Site. Our basis for this is our legitimate interest in operating and improving the Site (and, where required by law, your consent — see the cookie controls above). We do not use this data to make decisions about individuals.

05 How it's shared

Analytics data is processed by Google as our analytics provider; see Google's Privacy Policy and Analytics terms. Google may process this data on servers outside your country, including the United States. We do not sell or rent your personal information, and we don't share it with advertisers. We may disclose information if required by law.

06 Retention

Analytics data is retained according to our Google Analytics settings (configurable, commonly 2–14 months) and then aggregated or deleted. Emails you send are kept only as long as needed to handle your inquiry.

07 Your rights

Depending on where you live, you may have rights to access, correct, delete, or restrict processing of your personal data, to object to processing, or to opt out of "sale"/"sharing" (we do neither). To exercise any right, email nick@heretics.io. You can also control analytics directly through your browser and Google's opt-out tool. [Counsel: confirm GDPR/CCPA-specific disclosures and any "Do Not Sell" link requirements for your audience.]

08 Children

The Site is intended for cybersecurity professionals and is not directed to children under 16. We do not knowingly collect data from children.

09 External links

The Site links to other sites (vendors and the reference desks we cite). We are not responsible for their privacy practices; review their policies separately.

10 Changes & contact

We may update this policy; the "last updated" date will change. If we ever add anything beyond Google Analytics, we'll update this page first. Questions or requests: nick@heretics.io.