Privacy
NotWorking collects as little as it can. There are no accounts, no cookies, no analytics or tracking, and no third-party scripts or fonts on these pages.
What we collect
- Failure reports. The access path that failed, what failed, and optionally a self-reported country code, agent type and a short note. Notes are scrubbed of anything that looks like contact details, numbers, IDs or links, and are never shown to anyone. URLs are reduced to listed routes; query strings are never kept.
- Reporter fingerprints. Each report carries a hash of the reporter's network (an IPv4 /24 or IPv6 /48) and a coarse user-agent family, made with a salt that changes daily. Salts are deleted after 2 days, so fingerprints can't be linked across days or turned back into a network. They're used only for rate limits and to require reports from different networks.
- Lookup counts. Daily totals of how often each service is looked up. A lookup for something we don't list is counted under its normalised domain or ID, never the raw input.
What we don't collect
- IP addresses, in the database or in any log.
- Names, emails, accounts or any other personal data. Please don't put personal data in a report.
What we publish
Report counts, statuses and status changes for listed services, on these pages, through the API and in the dataset (CC BY 4.0). Notes and fingerprints are never published.
Where it's kept
The service runs on a server at DigitalOcean, with encrypted backups in Cloudflare R2. Cloudflare provides DNS. Backups are kept for 48 hours.
Questions
Open an issue at github.com/RyanNSJ/notworking/issues. See also the methodology and terms.