Privacy Practices
Last updated: August 24, 2026
fcc.cc is built to respect your privacy. We don't run analytics, don't serve ads, and don't track you across the web. This page explains exactly what data exists when you use the site, where it lives, and how to remove it.
fcc.cc is a personal, non-commercial project. For privacy-related questions or to request a copy of your data, email barkbark@mailbox.org.
No Analytics, No Tracking
fcc.cc does not use Google Analytics, Google Tag Manager, Meta Pixel, Twitter/LinkedIn/Pinterest/TikTok pixels, Hotjar, FullStory, LogRocket, Mixpanel, Segment, Amplitude, Heap, Sentry, Bugsnag, Rollbar, or any other analytics, session recording, or tracking service. There are no tracking pixels, no fingerprinting scripts, and no behavioral profiling for advertising or analytics. We do not sell data to anyone.
When you load most pages on fcc.cc, your browser only talks to fcc.cc. The next section explains the few cases where it doesn't.
Standard web server logs (IP address, requested URL, timestamp, user agent) are kept for operational and security purposes only. These logs are not shared with third parties and are rotated regularly.
No Advertising
There are no ads on fcc.cc. No ad networks, no sponsored content, no affiliate tracking. The site is not monetized through your attention or data.
Browser Storage
fcc.cc stores small preferences and app state in your browser's
localStorage. Larger device-local data can use
IndexedDB or the browser's origin-private file
system. The data listed here lives only on your device:
-
Theme & layout — your chosen color
scheme, background, text, and card colors
(
fcc:v2:*) -
Music preferences — playlists, saved
items, recent searches, playback settings
(
musicfcc:*) -
Podcast progress — playback position,
saved episodes, speed preference
(
fcc:pods:*) - Game state — saved games, scores, and settings for sudoku, solitaire, crossword, and other games
- Weather locations — your saved locations for the weather dashboard
- UI state — dismissed tips, menu preferences, accessibility settings
- Library files on this device — FCC never receives the audiobook or PDF files you explicitly select. The local copy, its filename and embedded metadata, and your playback or reading position are not uploaded to fcc.cc or synced to your account
If you sign in to an account, some of these preferences (theme colors, weather defaults, news topic weights, layout toggles) also sync to your account on our server so they follow you between devices — see Account Data below for the exact list. Files you open locally in Library, and their metadata or progress, are excluded from that sync.
You can clear local data at any time by clearing your browser's site data for fcc.cc, or by using your browser's developer tools to inspect and remove individual keys.
Cookies
fcc.cc sets no cookies on a first visit. Cookies are set only when you do one of two things:
-
Vote or interact while signed out. An anonymous
ID cookie (
musicfcc_vote_idfor the main site,news_uidfor /news/) is set so we can recognize that you're the same logged-out person on a return visit and avoid double-counting your vote. These cookies hold only a random ID, no personal data. -
Sign in to an account. An authentication
cookie (
musicfcc_auth, plus a small per-app session cookie likefcc_news_session) is set so you stay logged in. These are HttpOnly, scoped to fcc.cc, and contain only an opaque session token.
There are no marketing cookies, no third-party cookies, and no cookie consent banners because there is nothing to consent to beyond these functional cookies.
Account Data
If you create an fcc.cc account, we store your username and email address. Sign-in uses passwordless magic links — we never store a password. We do not share account information with third parties.
For signed-in users, the following also lives on our server (in addition to your browser's localStorage), so your settings follow you between devices:
- Theme & layout — theme preset, custom background / text / card / line colors, reduced-motion preference, compact-layout toggle
- Weather — default unit (°F vs °C), default location, saved locations, most-recent location, widget section toggles
- News — topic weights you've adjusted in the news preferences panel
- Reader — feed URLs, custom feed titles and categories, read/unread state, and starred article identifiers and notes
- Library catalog state — FCC never receives user-selected audiobook or PDF files, their filenames or embedded metadata, or device-file progress. Separately, on the website, saved and recently opened public-catalog book records can sync when you are signed in
- History — your votes on history items
- Music & saved items — listening positions, podcast subscriptions, favorite stations, votes, saves/bookmarks, playlists, achievements, and recent activity
- Commons — profile name, handle, bio, posts, replies, reactions, follows, blocks, mutes, and safety reports you submit or that identify your content
- Games — your current synced game state, completed-game results, and a compact Sudoku attempt log with a random attempt identifier; modern/legacy label; difficulty and clue count; ready, start, and end times; outcome and leave reason; elapsed and active playtime; progress; and bounded move, mistake, note, auto-mark, undo, hint, and clear counters. Sudoku history does not store the puzzle, solution, individual moves, puzzle seed, IP address, or a device identifier. Detailed attempt storage is capped at 50,000 rows per account; conflict-only sync bookkeeping is removed and does not count as a game.
- Direct messages — if you use /dm/, the messages between you and other accounts. Stored on our server, not end-to-end encrypted.
You can delete your account-system data from your My Account page at any time. Support tickets are separate operational records and are not yet part of that automated deletion or account ZIP. To request review or erasure of a ticket and its eligible copies, keep the ticket ID and contact riker@fcc.cc; backup expiration and legally required preservation may limit immediate removal. You can also download a copy of your account data (votes, comments, library, activity log, etc.) as a ZIP of JSON files from the same page. Direct messages are not included in the download — they're encrypted at rest, and we don't put their contents in a portable file. Sign in and visit /dm/ to read or delete them there.
Support Tickets
A ticket stores the subject and description you submit, its site and issue category, a shortened network prefix for abuse control, and any email address, page URL, or screenshot you choose to include. Before storage, fcc.cc removes query parameters, fragments, and embedded credentials from page URLs and re-encodes accepted screenshots to remove image metadata.
Ticket reports, reporter details, internal notes, and screenshots are private to authenticated ticket operators; they are not published on the web. The reporter-facing status lookup returns only the ticket ID, workflow status, publication date, and a separately reviewed public update. Public updates are checked for likely contact details, credentials, links, network addresses, and screenshot references before publication.
Ticket records and encrypted backups are retained for support, recovery, abuse prevention, and security review. They are separate from account data and may outlive an account. To request review or erasure, use the contact process above and include the ticket ID; eligible active and backup copies are handled through the coordinated retention process rather than a browser-only delete.
Optional Website AI Game Coaching
On the fcc.cc Sudoku website, signed-in players can explicitly press Analyze my play to request coaching. This never runs automatically. fcc.cc first converts the private game log into a small set of broad categories such as completion range, pace range, and recent hint or mistake range. Only those non-identifying categories are sent from our server to Anthropic to generate the feedback. We do not send your name, email, account ID, IP address, dates, seed, puzzle, solution, grid, timeline, cells, or digits.
The model can select only server-defined advice codes; fcc.cc checks each selection against the categories that support it and writes the displayed wording itself. Under Anthropic's standard commercial API policy, API inputs and outputs are deleted within 30 days; legal or automated trust-and-safety exceptions may permit longer retention. Zero-data-retention arrangements are separate and fcc.cc does not assume one for this feature. fcc.cc may cache the resulting generic report for no more than seven days under a category fingerprint shared by players with the same broad pattern, without an account identifier. To enforce a fair daily allowance across servers, fcc.cc also keeps the current UTC day's AI-request count with your account; older daily allowance rows are deleted during the same cleanup and account deletion removes any current row. Expired reports are deleted hourly while the service is running and at service startup. If the AI service is unavailable, its budget is reached, or there is not enough detailed history, fcc.cc returns local rule-based coaching in the same format. Deleting your account removes your game log from fcc.cc; the identity-free shared report expires on its normal schedule and cannot be traced back to your account.
This optional website feature is separate from Sudoku · fcc.cc for iOS 1.0. The iOS app's Nudge and Coach experiences run on device and do not use this website AI route.
Comments
Comments across the site (on blog posts, forum threads, and shouts) are handled by self-hosted systems running on our own server. Comment data is not sent to any third-party service. Each comment stores your display name and the comment text.
Posting a comment requires a signed-in account. There is no anonymous commenting.
Native iOS Apps
The seven fcc.cc iOS apps contain no advertising, third-party analytics, or cross-app tracking SDKs. Reader, notaplayer.net, WeatherDog, Sudoku, and Library work without an account for their core reading, listening, forecast, or play features. Commons is open for reading but requires an account to post or interact. Sleep has no account at all. When an app offers sign-in, it uses the shared fcc.cc account described above.
Reader by fcc.cc
Signed-in sync stores feed URLs, custom titles and categories, read/unread state, and starred article identifiers and notes. OPML files are imported only when you choose one and exported only when you request a copy. Article images normally relay through fcc.cc. If you request on-device full-text extraction, the app fetches that article like a private browser session; the publisher then receives your device IP address and the requested article URL.
notaplayer.net by fcc.cc
If you sign in, fcc.cc stores app-functionality data such as votes and saves, podcast subscriptions and listening positions, and favorite stations so those features can sync. If you separately opt in to the newsletter during account setup, your email address is also used to send that newsletter; opting out does not affect the app.
API requests, feed XML, directory searches, and artwork go through fcc.cc. Audio is different: music streams connect to Archive.org or Jamendo, podcast episodes connect to the publisher's host, and live radio connects to the broadcaster's stream server. Those audio hosts receive your IP address and the item or station you play, for as long as you listen.
WeatherDog by fcc.cc
If you allow location access, the app rounds your coordinates and sends them to WeatherDog's own server to fetch forecasts; upstream weather providers do not receive your device IP or location from the app. Signed-out favorites remain on the device. If you sign in, WeatherDog stores your email address, saved place names and coordinates, and forecast preferences for sync. The more detailed website-and-app policy is available at weatherdog.net/privacy.
Sudoku · fcc.cc
Anonymous games stay on the device. If you sign in, the shared account can sync the current puzzle and compact gameplay record described above through the first-party FCC service. In iOS 1.0, Nudge uses the current board on device, and Coach computes from the already-loaded first-party ledger. Generating or refreshing Coach sends no separate coaching request and no data to Anthropic or another third-party AI provider. This does not change the optional first-party board and history sync described above. The optional website AI feature is separate and is not part of the iOS app.
fcc.cc Library
On the website, saved and recently opened public-catalog books can sync to your fcc.cc account when you are signed in. In the native iOS app, that catalog state remains on the device in this release. Catalog searches, book metadata, cover art, audiobook streams, and Wikipedia summaries are requested through fcc.cc; Project Gutenberg, Internet Archive, LibriVox, and Wikipedia do not receive your device IP from the app. Source-page links open only when you choose them.
FCC never receives audiobook or PDF files you open locally. No file upload or sync request is made. The website keeps its copy in that browser's fcc.cc site storage, and the iOS app keeps its copy in the app's private container. File bytes, original filename/path fields, cover art, and device-file progress are not uploaded or account-synced. Embedded metadata also remains local except for the exact editable title you may choose to send in the chapter search described below. The iOS copy is excluded from device backup. If a file is not yet local, iCloud or another File Provider may retrieve it to the device through Apple's system picker. That provider-to-device transfer is not an FCC upload or receipt; FCC does not control the provider's retrieval behavior. Removing an item deletes Library's local copy, not the original file you selected. Clearing fcc.cc site data or uninstalling the app can remove the local copy.
In the iOS app, Find chapter names online is optional and never runs before you have accepted it once. When you confirm that action, the app sends only the displayed book title directly to AudioSilo Meta to search its public, read-only audiobook metadata catalog; the author field never leaves the device and is used only to rank the results locally. AudioSilo and its hosting provider receive the request, including your IP address. An imported book's initial displayed title may have been derived from its ZIP/audio filename or a selected multi-file folder name, and the app shows the exact title before the first send. FCC does not send the audio or ZIP bytes, a separate filename or path field, author, cover, file hashes, track durations, listening progress, or any other title from your library. The app ignores remote cover URLs, uses a cookie-free temporary network session, and matches returned chapter timing to the files on your device. Accepting the first confirmation also turns on automatic matching for later imports: each newly imported audiobook's displayed title is then sent the same way, and only an exact or high-confidence match may fill still-unnamed tracks, labeled with its source and confidence. Less certain results always wait for your review, and the automatic behavior can be turned off at any time in Name chapters. You can continue naming chapters locally without making any of these requests.
Sleep by fcc.cc
Sleep has no account, advertising, analytics, tracking, or runtime network requests. Its soundscapes, artwork, and scene video are bundled with the app and playback settings remain on your device.
Commons by fcc.cc
Public profiles and posts are visible to everyone. More limited audiences are enforced by the first-party server. fcc.cc stores profile details, posts, replies, reactions, relationships, blocks, mutes, and reports (including the selected reason and optional notes) to operate and moderate the community. Link previews are fetched and rehosted by fcc.cc. Account export and deletion cover the Commons safety tables as well as ordinary posts and profiles. An export includes only blocks, mutes, and reports you initiated; it never reveals who privately blocked, muted, or reported you, or the identities of moderators. Support tickets remain subject to the separate process above.
How Third-Party Data Is Handled
Some features need data from external services (weather forecasts, Wikipedia summaries, podcast cover art, museum images, news source thumbnails). We handle these in one of two ways:
Routed through our backend
For news cards, podcast cover art, music thumbnails (including the /music/ tape-card covers), recent art and photography, the homepage weather widget, quote-of-the-day speaker images, library book covers and author photos, library audiobook MP3 streams, Wikipedia summaries, place-name geocoding, all of /weather/'s data (forecasts, archive, air quality, marine, NWS severe-weather alerts, NOAA tide stations and predictions, sunrise/sunset, rainviewer radar tiles, reverse-geocoding) and its ambient hero video, and shout/blog preview images on the homepage, your browser only ever talks to fcc.cc. Our backend fetches the public resource, caches it permanently to disk, and serves it back to you. The third-party service sees only our server's IP, never yours. The proxy uses a strict allowlist of known hosts and validates redirect targets to prevent it being abused as an open proxy. Once we've fetched a particular cover, audiobook chapter, or summary once, it stays hosted on our server forever — subsequent visits get it instantly and the third party isn't contacted again.
This relay applies only to public-catalog material. Audiobooks and PDFs you choose from the device are read from device-local storage and are never fetched by or sent to the fcc.cc backend.
The weather data sources we proxy on your behalf are: Open-Meteo (forecast, history, air quality, marine, geocoding), NWS (severe-weather alerts), RainViewer (radar tiles), NOAA Tides & Currents (tide station list + predictions), Sunrise-Sunset (twilight times), BigDataCloud (reverse-geocoding fallback when our place-name database has no hit). Listed here so you can read their policies and trust the chain; your browser never contacts them.
For /astro/ the proxied data sources are: NASA (APOD — Astronomy Picture of the Day, EPIC — DSCOVR Earth imagery), JPL Solar System Dynamics (close-approach asteroids and fireball events), NOAA Space Weather Prediction Center (GOES X-ray flux, planetary K-index, solar-wind plasma), Where The ISS At and Open Notify (live ISS position), NASA SDO and SOHO (live solar imagery + corona), and webcam imagery from the European Southern Observatory, the NRAO Very Large Array, the Canada-France-Hawaii Telescope, telescope.org, and AllSkyCam. All proxied through fcc.cc with aggressive caching (5–15 minutes for live imagery, 60 seconds for solar/space-weather feeds, 15 seconds for ISS position) so the upstream services never see your IP and your browser only ever talks to fcc.cc.
/earthquakes/ queries the USGS earthquake catalog (FDSN web service) through the same proxy chain — 5-minute cache per query, no upstream contact from your browser.
Direct browser requests (specific feature pages)
When you actively use one of the dedicated feature pages below, your browser makes a request directly to the public API. Those services may log your IP per their own privacy policies, which we link to.
| Feature page | Service | Data sent |
|---|---|---|
| /library/ and /books/ | Open Library (book metadata + author search), DictionaryAPI (in-reader word lookups), and Project Gutenberg via Gutendex (free public-domain books) are all routed through our backend — covers, audiobook MP3 streams, and search/detail JSON go via fcc.cc, so your IP never reaches those upstreams. Internet Archive (LibriVox metadata search and Gutenberg edition discovery) is still called direct from your browser. | Book/author search terms, book IDs, looked-up words |
| /music/ | Internet Archive (audio streams), Jamendo (track metadata) | Item ID being played, search terms |
| Podcasts (/pods/ and the not a player iOS app) | The podcast's own host — whoever publishes the feed (episode audio is streamed straight from their server) | Your IP address and the episode you play. Feed XML, artwork and directory search ARE proxied through fcc.cc — only the audio itself is direct, because episodes are large and range-requested. |
| Radio stations (/stations/ and the not a player iOS app) | The broadcaster's own stream server | Your IP address and which station you tuned, for as long as you listen. The station directory itself is proxied; the live stream is direct. |
| /tickets/ submission form | Cloudflare Turnstile (bot verification only) | Browser and network signals needed to distinguish a human submission from automated abuse. Ticket text, email, page URL, and screenshots are sent only to fcc.cc, not Turnstile. |
| YouTube / Vimeo embeds | YouTube (no-cookie domain), Vimeo | Only when you press play on an embed |
These calls happen only when you visit those specific pages. The fcc.cc homepage and most other pages make no third-party requests at all.
Your Rights & Controls
- Clear all local data: Open your browser's settings, find site data for fcc.cc, and delete it. This removes localStorage, IndexedDB, origin-private files, and cookies, including Library's private copies of device files. It does not delete the original files you selected.
- Inspect stored data: Open your browser's developer tools (F12), go to the Application or Storage tab, and browse localStorage, IndexedDB, and origin-private storage under fcc.cc.
- Block third-party requests: Use a content blocker or browser extension to prevent requests to external APIs. Core site functionality will still work.
- Delete your account: Go to your My Account page to delete your account and account-system data. Support tickets and any legally or operationally retained copies follow the separate process described above.
Verify These Claims
You don't have to take our word for any of this. The site is built with standard HTML, CSS, and JavaScript — open your browser's developer tools and inspect every network request, cookie, and localStorage entry yourself.
Three independent third-party scanners verify our setup from the outside. Click any of these to run the scan live against fcc.cc (results may take a moment to refresh):
- Webbkoll — run by Dataskydd.net, a Swedish digital-rights nonprofit. Audits HTTPS, headers, cookies, referrer policy, and third-party requests.
- Blacklight — run by The Markup, a nonprofit investigative newsroom. Loads the page in headless Chrome and instruments for canvas fingerprinting, session recording, third-party cookies, and known tracker scripts.
- Mozilla Observatory — run by the Mozilla Foundation. Grades HTTP security headers and best practices.
Internally, every code change to fcc.cc runs through an automated
privacy audit (scripts/privacy_audit.py) that
scans for tracker-pattern matches and any auto-loaded external
host outside our short, disclosed allowlist. Pull requests
fail if the audit finds anything new.
Changes
If these practices change, we will update this page with a new date. We are committed to never adding analytics or tracking.
Contact
For privacy-specific questions or to request your data, email barkbark@mailbox.org. For anything else, use the support tickets page or reach out through IRC chat.