Plain-language privacy note
Small measurements. No visitor profiles.
What KML measures
KML keeps hourly aggregate counts of searches, zero-result searches, reaction opens, image and reaction-link copies, saves, shares, Surprise Me uses, related-reaction clicks, and Browse clicks. Each row may contain the UTC hour, an approved event type, an optional KML reaction ID, the part of the site where the action happened, a result count where applicable, and the aggregate event count.
Sharing counts distinguish successful image copies, direct reaction-link copies, link-copy fallbacks from Share Reaction, image-download control activations, and successfully resolved native page or image shares. A download activation does not confirm a completed download, and native sharing does not confirm delivery to a recipient. KML does not record clipboard contents, recipients, destination apps, or messages.
What KML does not keep
KML's ordinary usage analytics do not store search text. Neither usage analytics nor search feedback stores IP addresses, user agents, cookies, visitor or session IDs, fingerprints, locations, advertising profiles, cross-site tracking information, or individual browsing or search histories. KML does not create visitor accounts.
Search-quality feedback
When you edit the search box and stop typing for about two seconds, KML automatically retains the settled search phrase only if normal search and its rescue step both return no results. Pressing Enter or Search can submit that final-zero phrase sooner. These two paths do not collect the same unchanged search interaction twice. Continuing to type restarts the timer; clearing the search or leaving before it settles cancels pending collection. Page loads, unedited URL-loaded searches, suggestions, Emergency searches, and intensity-filter-only changes do not automatically submit phrases. Successful and successfully rescued search phrases are not automatically retained.
You can also choose “Report this search” for unhelpful or irrelevant results. Opening the form sends nothing; submitting sends the displayed phrase and your selected category. No account, email address, or explanation is required.
KML uses this feedback to improve search quality. A separate Cloudflare D1 table aggregates counts by lowercased search phrase with surrounding spaces removed and repeated spaces collapsed, with separate counts for automatic final-zero searches and each voluntary report category. Entries include maintenance and duplicate-suppression timestamps, not visitor identifiers or individual histories. Rapid repeated submissions may be limited without identifying visitors.
Search text may itself contain information you enter. KML screens recognizable email addresses, URLs, phone or payment-card-like numbers, and other obvious sensitive patterns before storage, and rejects overly long or inappropriate input. Screening is not perfect and cannot detect every piece of personal or sensitive information. Please avoid including such information in searches and reports.
Search-feedback entries are removed after 60 days without a new accepted failure or report. Automatic cleanup runs every five minutes; deletion is not instantaneous at the expiry second. Only private maintenance access can retrieve accumulated feedback. Ordinary aggregate usage counts remain separate and contain no search text.
Cookies and browser storage
KML does not set analytics cookies. During a browser tab’s session, it uses session storage to avoid immediately repeating the same discovery suggestions and to restore the previous homepage state after pressing Back. That session information stays in the browser and is not sent with analytics events.
Hosting and third parties
The site runs on Cloudflare Workers, and its aggregate analytics are stored in Cloudflare D1. Cloudflare necessarily processes ordinary network and request information to deliver, secure, and maintain the site, but the KML application does not write that operational metadata into its analytics database. KML does not use a third-party analytics provider.
Email, forms, and payments
KML has no account system, contact form, advertising system, or payment system. If you email contact@kiffmemelibrary.com, your address, message, and normal email metadata are processed by Cloudflare Email Routing and forwarded to a private Gmail mailbox. That email processing is separate from website analytics; the private destination address is not published.
Retention and changes
Aggregate analytics rows currently have no application-level automatic deletion schedule. Cloudflare D1 also maintains infrastructure-level recovery history through Time Travel; that is database recovery, not a KML visitor-tracking system. This page will be updated before KML changes what it collects or adds a new analytics, account, or payment service.