Search privacy

Worlds to search
SET YOUR COURSEone world · or several

[ field guide → ]

Privacy policy / the public observatory

Updated September 16, 2026.

The public observatory lets anyone explore and download observations of braigetori's public small-world index and privacy-limited aggregate search signals. It describes what our crawlers have observed, not individual visitors or the size of a community.

Public index observations

We retain counts of indexed URLs, distinct content hashes, duplicate copies, server addresses, fetch failures and recently fetched/changed resources. Daily server histories, bounded title-word samples and sampled published connections help show how indexed coverage changes. Server addresses and sampled words come from indexed public resources. These observations are publicly accessible through the console, its report API and exports.

Hourly world observations are retained for 90 days. Last-observed daily world summaries are retained for 730 days. Daily server, title-word and sampled-link records are retained for 90 days. Historical observations begin when collected; earlier history is not invented. Current-day index snapshots can be updated as new observations arrive. The analytics store has a 512 MiB budget and collection can pause when its storage or processing limits are reached.

Aggregate search signals

Search analytics receive selected worlds, HTTPS or Gemini, coarse result outcome and daily counts from a limited reviewed vocabulary (for example music, art or programming). Complete search phrases, unknown words, URLs, email addresses, numeric input and search filters are not retained. A search with no reviewed word can contribute only a private aggregate request count.

The public console publishes reviewed-word cells only after the UTC day has finished and at least five events were received for that word, world selection, channel and result outcome. Completed days are published once and do not expose running counts. Private request totals and small cells are not included in public reports. Five events do not mean five different people. Bots and repeated requests may contribute. Suppression is not differential privacy or a guarantee of anonymity; this is best-effort aggregate measurement, not a traffic census.

Search aggregates, including published cells, expire from our store after 30 days. Public visitors can download or retain their own copies; their copies are not controlled by our retention schedule.

No visitor IPs, cookies, user agents, client certificates, locations or reader form input enter search analytics. There are no visitor profiles, unique-user counts, click histories or fingerprints in this collection. HTTPS honours DNT: 1 and Sec-GPC: 1 for these analytics. Native Gemini has no equivalent request headers. Search works when the optional collector is unavailable. No search demand is automatically sent to AI agents.

Organizing public search results

Useful first separates likely placeholders, thin files, routine logs, opaque source-history files and repeated copies from other matches. More matches and All matches keep those files accessible. Labels are estimates, not judgments about an author or viewpoint. Old references, short answers and creative writing can be useful.

A scheduled reviewer sends small batches of already indexed public document titles and text excerpts to OpenAI Codex or Anthropic Claude through the operator's installed subscription tools. It receives no visitor search phrases, locations, reader inputs, email or private files. The reviewer has no browsing or file tools. Cached classifications are tied to the content version and are reused until it changes; low-confidence judgments do not suppress results. Searches themselves make no model requests. Provider handling of those public excerpts is governed by the operator's provider account terms and settings.

Embedded Gemini reader

With JavaScript enabled, a Gemini client runs in your browser using OpenSSL compiled to WebAssembly. A restricted WebSocket transport carries Gemini TLS between your tab and the capsule. The transport sees the destination hostname, port, network addresses, timing and encrypted traffic sizes, but does not terminate Gemini TLS or record page URLs, page content, entered answers or client keys. The capsule sees the transport server's address. The website supplies the client code; the website and your browser remain part of the trust boundary.

Gemini server public-key fingerprints and optional temporary client identities stay in the current tab's memory. Temporary identities expire after one hour or on page reload/closure. They are not recoverable permanent accounts. Back history holds bounded completed pages in tab memory, and is cleared when the reader closes. Private input is masked and is not retained in the reader address or Back/Reload history. The destination can retain what you send or echo it in its own response. Downloaded files are saved by your browser only when requested; temporary download objects are released when their reader history is discarded. Use Forget in Connection details to discard the tab's identities and remembered server keys.

The separate script-free Gemini relay and the Gopher, Spartan and Nex readers process remote requests on the server. Their ordinary input passes through that relay. They respect applicable capsule relay policies. Search analytics do not receive either reader's content or inputs. Hashed connection-rate keys and concurrency limits use bounded, short-lived server memory; no reader traffic is written to an index or request log by the application.

Console settings and other site features

Chart calculations, saved views and display preferences run in your browser. Saved views and themes use local browser storage; you can delete saved views in the console or clear the site's browser data. A shared view link contains selected variables and filters in its fragment. Reports requested from the server include dataset filters such as world, time window and public server/word selection. The console adds no visitor-tracking or advertising analytics and does not run an AI model.

Weather location lookup and local display/art preferences are separate from search analytics. Automatic regional weather uses your connection address to estimate a region; the weather source and approximate location are shown. Weather providers receive rounded coordinates rather than your address. A bundled global land-cover map is consulted locally without sending coordinates to NASA. Successful public map features are cached in rounded regional buckets for up to 90 days, without an IP, visitor ID or visit history. Calendar decorations use the selected region and its local date; the local/worldwide/off preference stays in your browser. No weather visit invokes a model. The site uses a random artwork-session cookie to keep your ASCII composition stable; it is not a search-analytics identifier. Normal network handling of addresses and security controls is separate from the observatory's aggregate records. See the field guide for details.

GEMSPACE READER

Gemini capsule