Privacy Policy
Last updated: 1 January 2026
We write posts about how phishing kits harvest credentials, how trackers follow you across the web, and why “we value your privacy” banners usually mean the opposite. It would be a bad look to then hide our own data practices behind nine paragraphs of legalese.
So here’s the honest version.
The one-minute version
- We don’t sell your data. There’s no arrangement where anyone pays us for information about you. There never will be.
- You can read every article here without giving us a name, an email, or an account.
- Our server keeps standard access logs. Our analytics counts visits. Our newsletter needs an email address. That’s most of it.
- The password generator runs entirely in your browser. Passwords are generated on your device and never sent to us. We couldn’t log them if we wanted to.
- Third parties we use (hosting, analytics, email delivery) see some data too. They’re listed below by name, not as “trusted partners.”
The rest of this page is the detail. Read it if you want to check our work — we’d respect that.
Who’s behind this
The Curious Lab (“we,” “us”) is a tech and security publication at thecuriouslab.org. We’re the data controller for the information described here.
Reach us any time: contact@thecuriouslab.org
What we collect, and why
1. Server logs — automatic, unavoidable
Every web server on earth logs connections, and ours is no exception. When you load a page, our host records:
- Your IP address
- Your browser and operating system (the user-agent string)
- The page you requested and the page that referred you
- The date and time
- Response codes and errors
We don’t use this to build a profile of you. It exists so we can spot a broken link, notice when someone’s hammering the site with a bot, and figure out what went wrong when a page 500s at 3am.
Why we’re allowed to: legitimate interest in keeping the site running and secure (GDPR Art. 6(1)(f)).
How long we keep it: [X days — check with your host; 30 is a common default].
2. Analytics — how many people read the ransomware piece
We use Google Analytics to see which posts get read and which fall flat. It tells us things like “1,400 people opened this article, 60% of them on mobile.”
What it doesn’t tell us: who you are. We’ve configured it to anonymize / not use cookies.
If you’d rather not be counted, a tracker blocker like uBlock Origin will stop it, and we won’t degrade the site to punish you for that.
3. Cookies — the small pile
Cookies aren’t inherently evil; they’re just files that remember things. Ours fall into three groups:
| Type | What it does | Set by |
|---|---|---|
| Essential | Keeps the site working, remembers if you dismissed the cookie notice | The Curious Lab |
| Analytics | Counts visits and page views | [ANALYTICS PROVIDER] |
| Comment | Remembers your name and email if you tick “save my details” so you don’t retype them | WordPress |
If you leave a comment on WordPress without ticking that box, no comment cookie is stored. You can clear or block all of these in your browser settings — the site will still work, minus the conveniences.
Full detail: [link to your cookie policy, if you publish one separately].
4. The newsletter — email address, nothing more
Subscribe to “Join the Lab” and we collect your email address, plus the date you signed up and confirmation that you opted in. We use [EMAIL PROVIDER] to send the emails.
We use it to send you new experiments.
Your provider may show open and click statistics.
Every email has an unsubscribe link. It works immediately, we don’t ask why, and we don’t send a “are you sure you want to leave?” sequence afterwards.
Why we’re allowed to: your consent (GDPR Art. 6(1)(a)), which you can withdraw at any time.
5. Contact form and email
When you write to us, we get whatever you put in the message — usually a name, an email address, and the thing you wanted to say. We keep it as long as the conversation is useful and then delete it. We don’t add you to the newsletter because you emailed us once.
6. Comments
WordPress stores your comment, the name and email you supplied, your IP address, and your browser string. Your email is never published. Your comment and display name are, obviously.
Comments may be checked by Akismet to filter spam, which means that data is shared with that service for that purpose.
Gravatar: if you comment, an anonymized hash of your email may be sent to Gravatar to check whether you have a profile picture. Gravatar’s privacy policy applies to that check.
7. The password generator — this one’s important
The generator at /password-generator/ runs entirely in your browser using JavaScript and your device’s cryptographic random number generator.
Generated passwords are never transmitted to our server. They aren’t logged, stored, cached, or emailed. They exist in your browser tab and vanish when you close it.
Lab note: don’t take our word for it. Open DevTools, go to the Network tab, and generate a password. You should see zero outbound requests. That’s the check we’d tell you to run on anyone else’s generator, so run it on ours.
The standard caveat still applies: a password generated on a machine with malware on it is a compromised password. The tool can’t fix your endpoint.
Who else touches your data
Not a vague “trusted third parties” line. The actual list:
- [HOSTING PROVIDER] — runs the server, holds access logs
- [ANALYTICS PROVIDER] — visit statistics
- [EMAIL PROVIDER] — newsletter delivery
- [CDN / SECURITY PROVIDER, e.g. Cloudflare] — serves the site and filters malicious traffic
- [ANTI-SPAM SERVICE] — comment spam filtering
- Automattic / Gravatar — avatar lookup on comments
Each has its own privacy policy. We picked them for competence, not for how much data they’d give us back.
Embedded content: posts sometimes include embeds from X, Instagram, or YouTube. Those load from the platform’s own servers and can set their own cookies and see your IP, exactly as if you’d visited them directly. We can’t control what they do with that, which is worth remembering the next time you see an embed anywhere.
Affiliate and review links: some posts in Reviews and How-To Guides may contain affiliate links. Clicking one may pass a referral identifier to the merchant so they know the click came from us. It doesn’t tell them who you are, and it doesn’t change what you pay. Where a link is affiliate, we say so on the post.
Legal requests: if a valid legal order compels us to hand something over, we comply — but we’ll only ever have what’s listed on this page, which isn’t much.
What we don’t do
- Sell or rent personal data. Full stop.
- Run cross-site advertising trackers or retargeting pixels.
- Fingerprint your browser.
- Buy email lists or add people to the newsletter without a signup.
- Require an account to read anything.
Your rights
Depending on where you live, you can ask us to:
- Show you what data we hold about you
- Correct it if it’s wrong
- Delete it
- Export it in a portable format
- Stop processing it, or object to processing based on legitimate interest
- Withdraw consent at any time (the newsletter link, or just email us)
Email contact@thecuriouslab.org and we’ll respond within 30 days. We won’t charge you, and we won’t make you fill in a form designed to be annoying.
Practical note: for most readers, we hold nothing that identifies you. If you’ve never subscribed or commented, a deletion request mostly means clearing an IP address from server logs — tell us roughly when you visited and we’ll do what we can.
If you’re in the EU/UK and think we’ve handled this badly, you can complain to your national data protection authority. If you’re in California, you have rights under the CCPA/CPRA, including the right to know and delete — and since we don’t sell data, there’s nothing to opt out of. [Add DPDP Act 2023 language here if you’re operating from India.]
Children
This site isn’t aimed at children under 16, and we don’t knowingly collect their data. If you’re a parent and think your child has signed up for something here, email us and we’ll delete it.
Security
We use HTTPS, keep WordPress and plugins patched, restrict admin access, and follow the same hygiene we tell readers to follow.
We’re also not going to claim the site is unbreakable. We’ve written enough posts about zero-days and supply chain compromises to know how that sentence ages. What we can promise: we hold as little data as possible, so there’s very little to lose — and if a breach does affect your data, we’ll tell you and the relevant authority within 72 hours of finding out. No quiet disclosure buried in a footer update.
Where your data goes
Our infrastructure and service providers may store data in Iceland. Where data leaves the EEA or UK, it’s covered by Standard Contractual Clauses or an equivalent safeguard through the providers listed above.
When this page changes
We’ll update the date at the top and note what changed below. Material changes get announced in the newsletter — we’re not going to rewrite the terms quietly and hope nobody diffs it.
Change log
- 1 -January – 2026 — First published.
Contact
Email: contact@thecuriouslab.org X: @thecuriouslabHQ Instagram: @thecuriouslab_
Questions about this policy are welcome. So are corrections — if you find something here that doesn’t match what the site actually does, that’s a bug, and we’d like to know.