Privacy

Rates and Limits collects nothing about you. There is no account to make, no newsletter to join, no form to fill in, no cookie, no analytics, no advertising and no third-party script of any kind. This page describes the site as it is actually built, and it is short because there is little to describe.

What the pages do

What we receive

Nothing. This site has no server of its own, no database and no application code that runs when you visit. Every page, every api response and every source snapshot is a file written once when the site is built and then handed out unchanged. There is no log here to read and no profile to build, because there is nothing running that could write one.

What the hosting edge necessarily sees

The files are served from Cloudflare's network. Delivering a page to you means Cloudflare receives the request that asks for it, which as with any host on the internet includes your IP address, the address you asked for, your user agent string and the time. That is a property of how the web works rather than a choice made here, and it is stated because "we collect nothing" would otherwise be a claim about a request that plainly reached somebody. Whatever Cloudflare retains for operating and protecting its network is governed by its own terms. No analytics product is enabled, nothing is exported, and nobody here reads those requests or could tell you what is in them.

Email

Writing to hello@ratesandlimits.com is the one way to hand this site personal information, and it happens because you chose to. The message and the address it came from sit in a mailbox and are used to reply to you and to check a figure against the document you named. They are not added to any list, and there is no list to add them to. Ask and the message is deleted; it is the only thing here there is to delete. See contactfor what is worth sending.

The api, the snapshots and the embeds

The JSON api needs no key, no account and no registration, so a request to it carries no identity of ours and none is asked of you. The stored source documents under/snapshots/ are plain text files served the same way. An embedded card is a small page from this domain inside a frame on someone else's: it loads nothing from anywhere but here, sets no cookie, and reports nothing back except its own height to the page that framed it, which is how it sizes itself. If you would rather not run the loader script at all, the api page shows a plain frame that works without it.

Children

This site publishes government figures and has no way to know who is reading. It asks nobody for their age because it asks nobody for anything.

If this changes

Everything above is a description of the code, not a promise about it, and the two are kept together on purpose: a tracker could not be added to this site without this page becoming false in the same commit. If something here starts collecting anything, this page says so before it ships.