Skip to content
Ali Akbari
Menu

ADR-0009 · accepted · 8 October 2026

No analytics scripts or cookies

Context

The job-search plan wants to know whether an application link was opened (/review?ref=<code>). Analytics scripts add a third-party origin to the CSP, add JavaScript to every page, and collect visitor data.

Decision

The site loads no analytics scripts and sets no cookies. ref parameters are accepted and ignored by the application. The nginx and API access logs record client addresses only in truncated form (IPv4 /24, IPv6 /48); logs are rotated by size (5 × 10 MiB per container). Whether an application link was opened can be answered from those logs on the server. Nothing leaves the server.

Consequences

  • Since ADR-0011, requests pass through Cloudflare's CDN, which processes full client addresses under its own policy. The site itself still adds no scripts or cookies, and its own logs stay truncated.
  • The CSP stays 'self'-only.
  • No page-level metrics. If they are ever needed, a cookieless, self-hostable counter is the candidate, with this ADR superseded.

Source: docs/adr/0009-no-tracking.md

← All decisions