Policy

Privacy

Last reviewed 4 September 2026.

Pweener has no accounts, no sign-up, no forms, no comments and no advertising. We ask you for nothing and we set no cookies of our own. What is described below is what our hosting provider, Cloudflare, records and runs on our behalf — and it is real data collection, so it is set out here in full.

1. What we collect directly

Nothing. There is no field on this site that accepts input from you, no login, no newsletter, no analytics of our own, and no third-party advertising, social or embedded content.

2. What is stored in your browser

Two preferences are written to your browser’s localStorage so the site looks the same on your next visit:

KeyValuePurpose
pw.unitsmetric or imperial Which units the readings are shown in.
pw.themelight or dark Your light/dark preference, if you have overridden your system setting.

These never leave your device, are not cookies, are not sent with any request, and are not read by anyone but this site’s own script. Clearing site data removes them.

3. Server logs (Cloudflare)

This site is hosted on Cloudflare Pages and served through Cloudflare’s network. Cloudflare logs every request as part of delivering and protecting the site. Those logs include, for each request:

  • your IP address, and the approximate country and network (ASN) derived from it;
  • the date and time, the URL requested, the HTTP method, the response status and the number of bytes served;
  • your browser’s user-agent string and the referring page, where your browser sends one;
  • connection details — TLS version and cipher, HTTP protocol version — and a per-request identifier (the cf-ray value).

An IP address is personal data under the GDPR and comparable laws, which is why this section exists even though we never asked you for it. The processing is necessary to serve the site and to defend it against abuse (rate limiting, bot mitigation, denial-of-service protection); under the GDPR we rely on legitimate interests for that.

We do not enable Cloudflare’s log export, we do not copy request logs into any store of our own, and we do not attempt to identify visitors from them. What we actually look at is the aggregate traffic dashboard. Retention of the underlying logs is Cloudflare’s, under Cloudflare’s own policy.

4. Scripts Cloudflare injects into these pages

Cloudflare adds two scripts to the HTML we publish. We did not write them, they are not part of our source, and they run in your browser and send data to Cloudflare. They are disclosed here because that is what they do.

4.1 Cloudflare Web Analytics

A beacon script is loaded from static.cloudflareinsights.com/beacon.min.js and reports one page-view record per page you open. That record contains the page URL and path, the referring URL, your user-agent string, your screen and viewport size, the country Cloudflare resolves from your IP, page-load and Core Web Vitals timing measurements, and a site token identifying Pweener.

Cloudflare Web Analytics is cookieless: it sets no cookie, writes nothing to your browser’s storage, and Cloudflare states that it does not fingerprint visitors or build cross-site profiles. We see only aggregate counts — page views, referrers, countries, browsers — never an individual visitor.

4.2 Cloudflare bot detection (“JavaScript Detections”)

Cloudflare’s bot management injects a small script served from this domain at /cdn-cgi/challenge-platform/scripts/jsd/main.js. It runs without any interaction from you and reports characteristics of your browser and device back to Cloudflare, which uses them to tell automated traffic from human traffic. It is a security measure, not an analytics or advertising one, and its output is not available to us as per-visitor data.

If Cloudflare ever decides a request needs a challenge, it may additionally serve an interstitial page and its associated scripts.

Cloudflare injects this one as an inline script. This site sends a Content Security Policy that does not permit inline scripts, so in a browser that enforces that policy the detection script is blocked before it runs. It is documented here anyway, because it is present in the HTML we serve and because the policy could change.

5. Cookies

Pweener sets no cookies. Cloudflare may set the following strictly-necessary cookies on its own account when the relevant protections engage:

CookieSet byPurpose & lifetime
__cf_bmCloudflare Bot management — distinguishes humans from bots. Roughly 30 minutes.
_cfuvidCloudflare Scopes rate-limiting rules to a visitor. Session only.
cf_clearanceCloudflare Records that a security challenge was passed, so you are not asked again.

None of these are used for advertising, analytics or profiling, and none are set by us.

6. The weather data itself

The desert observations shown on this site are fetched from Open-Meteo.com by a scheduled server-side job and stored in a Cloudflare D1 database. Your browser never contacts Open-Meteo, so they receive nothing about you — no IP address, no user-agent, no record that you visited. The data itself contains no personal information: it is temperatures, rainfall, wind and radiation for fixed coordinates. Open-Meteo is credited in the footer because their licence requires it, not because they process anything about you.

Requests your browser does make to /api/… on this domain go only to this site, carry no identifier, and are logged exactly as described in section 3.

7. Who else is involved

Cloudflare, Inc. is the only processor: hosting (Pages), content delivery, the D1 database, analytics and security all sit with them. No other third party receives anything about you — the weather provider named in section 6 is contacted by our server on a schedule, never by your browser. There are no data brokers, and nothing is sold or shared for advertising. Cloudflare operates a global network, so requests may be handled in a country other than your own.

8. Your choices

  • Blocking the analytics beacon. Blocking static.cloudflareinsights.com in a content blocker stops the page-view reporting in section 4.1. The site works normally without it.
  • Blocking scripts entirely. The pages remain readable, but the charts and tables are drawn in the browser, so the data views will not render.
  • Server logs and bot detection (sections 3 and 4.2) cannot be opted out of while using the site — they are how it is served and defended.
  • Do Not Track / Global Privacy Control. We run no cross-site tracking, targeted advertising, or sale or sharing of personal information, so there is nothing for such a signal to switch off.

9. Your rights

If you are in the EU, EEA or UK, you have rights of access, rectification, erasure, restriction, objection and portability over personal data relating to you. In practice the only such data here is contained in Cloudflare’s request logs, which we cannot search by person — we hold no identifier that would let us find you. If you are in California, we do not sell or share personal information and we do not use it for cross-context behavioural advertising.

This site is not directed at children and collects nothing knowingly from them.

10. Changes and contact

If this policy changes materially, the review date at the top of the page changes with it. Questions about it can be sent to [email protected].