Effective August 16, 2026
What this site collects
Almost nothing, by design. Cybersecurity Alphabet Soup has no user accounts and no advertising trackers. The site sets no cookies at all. It measures aggregate page traffic, described under Analytics below, and it stores the one thing you can explicitly hand it: an optional ransomware alert subscription, described under Ransomware watch alerts below.
Interactive features (quiz progress, self-assessment answers and notes, roadmap plans, and everything you type into the tools, including company details and team names) are stored in your browser's localStorage on your own device. That data is never transmitted to this site, to the analytics provider, or to anyone else, and clearing your browser storage removes it completely. You can see exactly what is stored, download a copy, or erase all of it on your saved progress page.
Analytics
This site uses Cloudflare Web Analytics to count page views. It is a privacy-focused, cookie-free analytics service: it sets no cookies, stores nothing on your device, does not fingerprint you, does not track you across sites or sessions, and does not build a profile of you. It tells me which pages are read, roughly where readers come from, and how quickly pages load, nothing that identifies an individual.
Nothing you enter into the quiz, the assessments, the roadmap, or any tool is ever sent to the analytics service. Only the fact that a page was viewed is recorded.
The measurement script is added by Cloudflare as pages are served, rather than being part of the site's own code. If you would rather not be counted, standard browser or extension blocking of static.cloudflareinsights.com works, and nothing on the site depends on analytics loading.
Infrastructure logs
The site is served as static files by GitHub Pages behind the Cloudflare content delivery network. Like virtually every host on the internet, these providers process standard web request metadata (such as your IP address, browser user agent, and the URL requested) to deliver pages and protect against abuse. That processing happens under their policies, not mine:
I see aggregate, non-identifying traffic counts from Cloudflare (page views by country and page). I have no way to identify individual visitors and no interest in trying.
Fonts
Pages load typefaces from the Google Fonts content delivery network, which receives the standard request data needed to serve the font files. Details are in the Google Fonts privacy FAQ.
Outbound and affiliate links
This site links out to official standards bodies, vendors, training providers, and other resources. Once you follow a link, the destination site's privacy policy applies, not this one.
Some outbound links are affiliate links, which means a partner may credit this site for your visit using a cookie set on their site after you click. This site itself sets no tracking cookies and shares no information about you with affiliate partners; attribution happens entirely on the destination's side. For the full picture, read the affiliate disclosure.
Ransomware watch alerts
The news page offers an optional email alert: you give an email address and up to five watch terms (organization names or domains), and you get an email if a matching claim appears in the ransomware victim feed. This is the only feature on the site that stores anything server-side, and it is entirely opt-in.
What is stored, in a Cloudflare D1 database: your email address, your watch terms, confirmation state and timestamps, and a record of which feed entries you have already been alerted about. Nothing else. No names, no IP addresses tied to your subscription (request IPs are used only as salted hashes for rate limiting and are purged within two hours), and no usage tracking.
Alerts are double opt-in: nothing is sent beyond a single confirmation email until you click the link in it, and unconfirmed requests are deleted automatically after seven days. Every email includes an unsubscribe link, and unsubscribing deletes your email address and watch terms immediately; there is no dormant state and no list you remain on. Alert delivery uses Resend, which processes recipient addresses to deliver the mail. Your subscription is never used for anything except these alerts: no newsletters, no marketing, no sharing, no selling.
One caution worth repeating from the news page: the feed consists of claims made by criminal groups, so an alert means your term matched a claim, not that a breach is confirmed.
If you email me, I use your address only to reply. It is never added to a list, shared, or sold.
Changes
If this policy changes, the new version appears on this page with an updated effective date. Given how the site is built, changes should be rare and boring.
Contact
Questions about privacy here? Email [email protected] or open an issue on GitHub.