Browser-only inputs
Passwords, TOTP secrets, CIDR values, hash inputs, timestamps, and Markdown editing are processed locally unless a tool explicitly states otherwise.
CMS administration
The administrator session uses a necessary secure cookie. CMS content, revisions, and image metadata are stored on the VPS. Uploaded images become publicly accessible when referenced by published pages.
Server requests
The server receives technical information including source IP, user agent, requested URL, and time of access.
Optional first-party analytics
Vishow Tools may use first-party analytics when collection is enabled by the administrator and a visitor chooses Allow analytics. Before that choice, no analytics visitor or session identifiers are created and no analytics data is collected.
When allowed, the browser receives a random visitor identifier and a 30-minute session identifier. Analytics stores only SHA-256 hashes of those random identifiers. It may record the requested page path, time, referrer domain, traffic source, device category, bounded acquisition/search parameters, page views, and visible-page engagement time. Raw IP addresses, passwords, TOTP secrets, hashes, Markdown content, and other tool inputs are not stored by the Analytics module.
The visitor can decline analytics or change the choice later through Privacy settings. Declining or withdrawing consent removes the analytics visitor/session cookies and stops new analytics collection. Previously collected pseudonymous records remain only until the configured analytics retention period expires. The current defaults are 90 days for stored analytics data and 365 days for the remembered visitor identifier when analytics is allowed.
Advertising
No advertising is active in this release. This policy must be reviewed again before advertising or third-party tracking is introduced.