Measurement
How this site counts visits
This notice covers both pages of the Throwing Kindness website: the home
page at / and the heart link pages at /h/…. They are being
compared against each other, so they are measured in exactly the same way, described here
in exactly the same words. Neither has an account, a sign-up or a message box. This page
explains what is counted — and everything that deliberately is not.
It is not anonymous by accident
We are not going to claim that nothing at all is processed, because that would not be true: opening any web page means a web server receives a request from you, and the infrastructure that serves it processes that request's metadata — including your IP address — in order to answer it. That is set out under Web server logs below, and it is true of both pages equally. What is true on top of it is that neither page holds anything that could identify you, and both are built so that they cannot.
What is never used here
- No cookies.
- No
localStorage,sessionStorageor other browser storage. - No visitor ID, device ID, advertising ID or fingerprint of any kind.
- No way to recognise you if you open the page again, or on another day.
- No Google Analytics, Meta Pixel, TikTok Pixel or any other third-party analytics.
- No advertising or attribution SDK.
- No request to any other company's servers — including web fonts. Both pages load everything from this site alone.
- No name, no email address, no message and no form to type anything into.
What is measured
We want to know whether receiving a heart makes people curious about the app. To find that out we keep four running totals — not records of people. An event is a single small message with these fields and nothing else:
event— which of four steps happened: the page was genuinely opened, the heart started, the heart finished, or an app-store button was tapped.campaign— which link it was, e.g.cardorfacebook. A channel, never a person.armandvariant— which version of the page was shown.source—print,social,web,directorretired.platform—ios,androidorunknown.storeStateandstore— which app stores the page was able to offer, and which button was tapped.
Every one of those fields is chosen from a fixed list written into the page's code. There is no free-text field, so there is nothing a person, a link or a page could put into an event even deliberately. No time of day is sent. Nothing links one event to another, and nothing links any event to you.
Four totals, not a journey
What comes out of this is four independent aggregate milestone counts per day and per link: how many pages were genuinely opened, how many hearts started, how many finished, how many store buttons were tapped. Because nothing identifies anyone, it is never known that the same person did one thing and then the next. Comparing the totals gives rough conversion proxies — enough to tell whether one page works better than the other, and deliberately not enough to follow a person through it.
When an event is sent
Only when the page has actually been looked at: the tab is visible, the page has really drawn on screen, and there has been either about a second of visible time or a real tap or key press. Obvious automation and passive previews — browsers that identify themselves as automated, link unfurlers, prerenders, background tabs, and requests that never render the page at all — are filtered out where practical.
We will not overstate that. It is a filter, not a proof: a determined automated browser that hides what it is and behaves like a person would still be counted, and so would one person opening the same link ten times. These totals may still contain automated or repeated traffic. They are directional, and they are never a count of distinct people. Closing that gap would mean identifying visitors, and we would rather have rougher numbers than do that.
Events are sent as a small POST request to this same website. Simply loading a URL never creates an event, and no event ever changes anything.
Links we do not recognise
Every heart link we publish is on a short reviewed list. If you open a /h/…
address that is not on it — a typo, a guess, or a link we have since retired — you still
get the whole heart, exactly as anyone else would. What that visit does not do is join any
total: an unrecognised link is excluded from measurement entirely, so nobody can move our
numbers by inventing a URL.
Right now, no events are sent at all. Measurement is switched on only
when the page's own source contains a collector address, and this build contains none.
You can check that yourself: view the page source and look for
tk-metrics-endpoint.
Web server logs
This site is hosted on Google Firebase Hosting, and this applies to every page on it, the home page and the heart links alike. Like every web host, it keeps standard server request logs, which include the IP address that made the request — that is infrastructure processing your request metadata, and we are not going to bury it. Those logs are created and retained by the hosting platform under Google's terms, not by us, and we do not control their retention period. We do not copy IP addresses into our own data, and no event described above contains one.
Children
A heart link is a single page with a heart on it. It asks for nothing, stores nothing on the device and offers no way to contact anyone. Nothing on either page is personalised, and nothing about a visitor is collected in order to make it work.
The heart is not from a particular person
A heart you receive here comes from Throwing Kindness itself. The page will never claim that a named person sent it to you.
Questions
Write to throwingkindnessapp@gmail.com and a real person will answer.
This page describes the Throwing Kindness website — the home page and the heart link pages. The Throwing Kindness app has its own privacy notice.
Back to Throwing Kindness