Club AgarthaReturn to the club

Signal policy / 01

Privacy below
the surface.

Club Agartha operates private visitor analytics by default to understand how people discover and use the website. Analytics records are visible only through the password-protected administrator dashboard and are not sold or shared for advertising.

What is collected

Visit and acquisition

Visit time, returning-visitor and browser-session identifiers, landing page, referring site, and campaign tags such as UTM source, medium, campaign, and content.

Network and location

IP address, approximate city/region/country, postal area and rounded coordinates, timezone, network provider, ASN, and probabilistic VPN, proxy, Tor, datacenter, or abuse-list signals. The full IP is sent server-side to the enrichment providers named below.

Device and browser

User agent, browser client hints, platform, language, display and viewport dimensions, pixel ratio, orientation, CPU cores, approximate memory and heap use, touch support, WebGL GPU details, battery, connection quality, plugin names, and history length when exposed.

Preferences and capability

Color scheme, reduced-motion and contrast preferences, storage and cookie availability, data-saver state, Do Not Track, Global Privacy Control, and basic browser capabilities.

Engagement and quality

Sections viewed, labeled link and button activations, scroll milestones, visible time on site, page exits, page-load timing, Core Web Vitals, and sanitized script-error locations.

Never collected

Typed text, passwords, form contents, precise GPS location, microphone or camera data, browsing activity on other sites, rendered canvas or audio fingerprint hashes, or the contents of browser storage.

Protection and retention

The web server necessarily receives an IP address to answer a request. Before the analytics database stores its copy, the address is sealed with a public encryption key; the collection path cannot decrypt it, and decryption is available only inside the authenticated administrator path. Routine Club Agartha access logs omit client IP addresses, URL query strings, and referring URLs. Administrator sessions use secure cookies, CSRF protection, lockouts, and finite lifetimes.

A secure first-party visitor identifier can remain for up to one year, while the page-session identifier expires with the browser session. These random identifiers do not contain a name, email address, or IP address.

Detailed records are automatically deleted after 180 days. Cached IP-enrichment data is removed after 30 days. Approximate location and network enrichment is provided by ipwho.is and ipapi.is; both receive the IP address over HTTPS and apply their own privacy practices. A one-way identifier tombstone may be retained for one year to enforce an opt-out.

Your control

Visitor analytics

Checking this browser's preference...

Disabling analytics immediately records a one-year browser preference and requests deletion of records associated with the current visitor identifier. If deletion cannot be confirmed, the status above will ask you to retry while collection remains disabled locally. Global Privacy Control is honored automatically.

Questions

For privacy questions or deletion requests that cannot be completed from this browser, contact Club Agartha through Instagram or TikTok.