Privacy
What this site records when you visit, why we keep it, how long it lives, and how to have it removed. No advertising, no third-party analytics, and no cookies unless you create an account to download the feed files or to use the API.
Effective 11 September 2026 · Public Mosaic LLC is the data controller
What we record
We keep a server-side access log of requests to publicmosaic.com. For each request we store:
- Your IP address
- Date and time of the request
- The path and query string requested, the HTTP method, and the response status
- Your browser's user-agent string, the referring page, and preferred language
- Approximate location — country, region, city, and time zone — derived from your IP by our CDN
- Your network operator (autonomous system number and organisation name)
- Connection metadata: HTTP protocol, TLS version and cipher, the CDN edge that served you, and the request's trace ID
Because each listed address now has its own page, the path we log can indicate which listing you read. We do not analyse the log that way, we never join it to accounts, and it is deleted after 90 days like every other row.
Reading this site sets no cookies, requires no account, and uses no tracking pixels,
fingerprinting scripts, or third-party analytics. Downloading the machine-readable
feed files, or taking a key for the API, requires a free account: signing in sets
first-party authentication cookies
(__session, __client_uat) and uses your browser's local
storage on the page where sign-in runs, solely to keep you signed in — never for
tracking or advertising. Beyond that, we make no attempt to identify the individual
behind an address.
Accounts
An account exists to gate the feed downloads and to hold keys for the enrichment API, and is free. The account itself — the email address you sign up with and authentication metadata such as sign-in timestamps — is operated for us by Clerk (below).
If you create an API key, we keep a small accounts store of our own. It holds, and holds only: your account identifier (an opaque ID, never your email); for each API key, a one-way hash of the key (never the key itself, which is shown to you once and cannot be recovered), the label you gave it, the day it was created and the day it was revoked; and, per account, a count of API requests made on each day. It holds no path, no address, no query, and no time finer than a day — so it can say how much an account used the API, and structurally cannot say what it looked up, from where, or when.
It is never joined to the access log — the log deliberately has no account or user column, so which of its rows are yours stays as unknowable to us after you sign in as before. To be exact about the limit of that promise: the access log records that an API request arrived from an address at a time, and the accounts store records how many requests an account made that day. In principle those two could be correlated. We do not do so; they are separate databases we never join, and the same is true of the indicator archive below. Daily counts are deleted after 90 days, revoked keys seven days after revocation, and everything in the store on request (see Your rights).
Why we keep it
We publish a public threat-intelligence feed. The log exists to operate and defend it: to detect abuse, scraping and denial-of-service attempts, to diagnose faults, and to preserve the integrity of what we publish. Our lawful basis is legitimate interest (UK/EU GDPR Article 6(1)(f)) in securing a public service. We do not use the log for advertising, profiling, or automated decision-making.
How long
Log rows are deleted automatically 90 days after they are written. The deletion runs on a schedule rather than by hand, so the window holds without anyone remembering to enforce it.
The indicator archive
Separately from the access log, we keep a permanent record of the command-and-control indicators we publish — the addresses, ports, certificates and fingerprints of scanned infrastructure, the certificate issuance templates those hosts share (a fingerprint, an issuer name and an issue date — never a person), the dates on which we observed them, and public facts about the networks routing them: the registered operator name and country of the network (from the RIPE NCC's registry, or relayed by the scanner from the same public registries), third-party listings of the network (such as Spamhaus DROP), and the scanning partner's day-level estimates of when a malware family's hosting shifted toward a network — recorded by network number and day, never by address. It is kept indefinitely and is not deleted on the 90-day schedule above, because it is the only record that a given address was ever listed.
It contains nothing about you. It holds attributes of machines we scanned on the public internet, never anything derived from a visit to this site: no identifier, no session, no account, and no record of who read which page. It is a separate database from both the access log and the accounts store, and none of the three is ever joined to another — the same promise made above, enforced by them being different stores rather than by a rule we follow.
Who else sees it
We do not sell, rent, or share personal data, and we do not transfer it to advertisers or data brokers. Two third parties are involved in serving this site:
- Cloudflare hosts and delivers the site and stores the access log, the indicator archive and the accounts store on our behalf, as our processor. Traffic is served from their global network, so processing may occur outside your country.
- Clerk operates account sign-up and sign-in as our processor. If you create an account — to download the feed files or to use the API — Clerk processes your email address and authentication data; its service is reached at clerk.publicmosaic.com and accounts.publicmosaic.com, and processing may occur in the United States.
Nothing else reaches out while you read. Typefaces, stylesheets and scripts are all served from this domain — no font CDN, no embedded widgets, no analytics beacons — so no other company learns your IP address from reading this site. The one exception is the sign-in flow on /indicators: if you use it, your browser talks to Clerk's endpoints on this domain and to Cloudflare's bot-check frame. You can verify all of this in your browser's network panel.
We may disclose logs where we are legally required to, or where it is necessary to investigate abuse of this service.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or erased, to object to our processing it, or to lodge a complaint with your data protection authority. Email support@publicmosaic.com and we will respond within 30 days. Because the log is keyed on IP address and nothing else, tell us the address and approximate dates so we can find the right rows. If you have an account, write from the email address you signed up with: the accounts store is keyed on your account identifier, which we resolve through Clerk, and we erase the account, its keys and its daily counts together.
About the indicator feed itself
The indicators we publish at /indicators describe infrastructure — addresses, domains, ports and certificates assessed as command-and-control servers. They are published TLP:CLEAR for defensive use and are a separate matter from this visitor log; the two are never joined. The live page is open to everyone, as is the RSS feed; only the bulk downloadable files (JSON, STIX, CSV) and the enrichment API ask you to sign in first. If you believe a host is listed in error, or you operate a network and want it excluded, see abuse / takedown and opt-out.
Changes
If we change what we collect or how long we keep it, we will update this page and move the effective date above. Material changes will be noted here rather than made quietly.