Effective August 30, 2026. Severity Daily is published by Express Development Group LLC. This policy describes what this website actually does today. When that changes, this page changes first, and the change is logged at the bottom.
The short version
We run two Google services: Google Analytics 4, to see which stories get read, and Google AdSense, which is loaded on every page. We do not sell your personal information. We have no newsletter, no accounts, no comment form, and no contact form, so there is nowhere on this site to give us your name or email address.
If you are in the European Economic Area or the United Kingdom, analytics and advertising permissions are denied by default and stay that way unless you accept. Everywhere else they are on by default and you can switch them off from the footer of any page. If your browser sends a Global Privacy Control or Do Not Track signal, we apply the strictest settings without asking you.
The rest of this page is the detail behind those sentences.
Who we are
Severity Daily is a publication of Express Development Group LLC, a United States company. For the purposes of the EU and UK General Data Protection Regulation, Express Development Group LLC is the data controller for this website.
Privacy questions, requests, and complaints: [email protected]. We answer within 30 days, and usually much sooner.
What we collect, and why
1. Analytics
We use Google Analytics 4, loaded through the Site Kit by Google plugin under measurement ID GT-WVJ8PWB2. We use it to see which stories get read and how people find them. That is the whole purpose.
When analytics are active, Google sets cookies in your browser (_ga and _ga_<container>) and receives:
- the pages you view on this site, and when
- the site or search that referred you
- your device type, browser, operating system, and screen size
- an approximate location, derived from your IP address at the country or region level
- a randomly generated identifier that distinguishes your browser from another browser, and which is not tied to your name or to any account
Google Analytics 4 does not record your IP address in our reports. Google uses the IP address transiently to work out approximate location and then discards it. We cannot see your IP address in Analytics, and we cannot identify you personally from anything Analytics shows us.
Consent, and exactly what it does. We use Google Consent Mode v2. For visitors in the European Economic Area and the United Kingdom, four permissions — analytics_storage, ad_storage, ad_user_data and ad_personalization — are set to denied before anything else runs. While denied, Google sets no cookies and builds no profile of you.
We want to be precise about one thing that most policies gloss over. Consent Mode does not prevent Google’s scripts from loading. It instructs them how to behave. While your permissions are denied, Google still receives what it calls cookieless pings — a signal that a page was viewed, carrying your approximate location, user agent, and referrer, but no cookie and no identifier that persists between visits or links one page view to another. So it is accurate to say no analytics cookie is set and you are not tracked across visits. It would not be accurate to say nothing at all reaches Google, and we are not going to tell you that.
Outside the EEA and UK — including in the United States — these permissions are granted by default, so analytics and advertising cookies are set from your first page view. You can withdraw that at any time using the cookie settings link in the footer, and if your browser sends a Global Privacy Control or Do Not Track signal we apply strictly-necessary settings without asking.
2. Server logs, security, and delivery
This site sits behind Cloudflare and runs on commercial web hosting. Like effectively every website, the servers in that path keep short-lived request logs that include your IP address, your browser’s user agent string, the URL you asked for, and the time you asked for it. This happens whether or not you consent to analytics, because without it we cannot deliver pages, block attacks, or diagnose an outage.
We rely on our legitimate interest in operating and defending the site, under Article 6(1)(f) of the GDPR. We do not use these logs to build a profile of you, and we do not combine them with analytics data.
3. Things we deliberately do not do
Being specific about absence is as useful as describing presence, so:
- No comments. Comments are closed sitewide. We have never received or stored a comment.
- No contact or subscription forms. There is no field anywhere on this site that asks for your name, email address, or any other personal detail.
- No accounts. Readers cannot register. The only login accounts belong to the people and automated processes that publish the site.
- No social media trackers, session recording, or heatmaps. There is no Meta pixel, no LinkedIn or X tracking tag, no session-replay tool, and no heatmap tool. Advertising is a separate matter and is described in full below.
- No data brokers. We do not buy, enrich, or append data about our readers from anyone.
- No sale or sharing of personal information as those terms are defined under United States state privacy laws, including the California Consumer Privacy Act as amended. We have never done this and are not set up to.
Cookies
A cookie is a small file a website asks your browser to keep. This site uses two kinds.
- Functional cookies record your own consent choice so the banner does not ask again on every page. These are set by our consent management software and are exempt from consent requirements, because without them we could not honor the preference you just expressed.
- Statistics cookies are the Google Analytics cookies described above, and they are only set once you permit them, in regions where permission is required.
You can change or withdraw your choice at any time using the cookie settings link in the footer of every page. You can also delete cookies directly in your browser settings; doing so removes your recorded preference, so the banner will ask again on your next visit.
Global Privacy Control. If your browser or extension sends a Global Privacy Control signal, we treat it as an opt-out of analytics and, should we ever run them, of advertising cookies. You do not need to interact with the banner for that to take effect.
Who receives your data
We do not sell your data and we share it with no one for their own independent purposes. Below is the complete list of third-party hosts your browser actually contacts when you load a page here. We compiled it by recording the network requests a real page load makes, rather than by listing the services we remembered adding — the second method is how sites end up with privacy policies that are quietly wrong.
| Host | Why |
|---|---|
googletagmanager.com |
Loads Google Analytics 4 |
pagead2.googlesyndication.com |
Google AdSense |
googleads.g.doubleclick.net |
Ad serving, part of AdSense |
ep1.adtrafficquality.google, ep2.adtrafficquality.google |
Google’s ad fraud and traffic-quality checks |
fonts.googleapis.com |
Web fonts used by the site theme |
secure.gravatar.com |
The author avatar shown on article pages. Gravatar receives a hashed identifier and your IP address in order to return the image. |
static.cloudflareinsights.com |
Cloudflare’s page-performance measurement |
cookiedatabase.org |
Cookie descriptions used by our consent tool |
Requests to Google-owned hosts carry your IP address and user agent by necessity, because that is how the web works — a server cannot send you a file without knowing where to send it. What those services are permitted to store and use is governed by the consent permissions described above.
Behind all of this, Cloudflare, Inc. delivers the site and terminates TLS, and our hosting and backup providers store the site and its backups. Google’s own handling is governed by its Business Data Responsibility terms and Privacy Policy.
We will also disclose information if a law, subpoena, or court order compels it. If that happens and we are permitted to say so, we will say so on this site.
International transfers
We are a United States company and this site is hosted in the United States. If you visit from the European Economic Area, the United Kingdom, or Switzerland, your data is transferred to and processed in the United States. For analytics, that transfer relies on the European Commission’s Standard Contractual Clauses as incorporated into Google’s data processing terms, together with Google’s participation in the EU–US Data Privacy Framework. Cloudflare likewise relies on Standard Contractual Clauses.
How long we keep things
- Analytics data: retained by Google for 14 months from your last visit, then deleted automatically. This is the shortest retention period Google Analytics 4 offers for the data we collect.
- Consent records: your recorded preference stays in your browser for up to 365 days, after which the banner asks again.
- Server and security logs: short-lived, generally days to a few weeks, depending on the provider, and retained longer only where a specific security incident requires it.
- Backups: rotated on a rolling schedule, so anything in them ages out with the backup itself.
Your rights
If you are in the EEA, the UK, or Switzerland
Under the GDPR and UK GDPR you have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to how we process it, to receive it in a portable format, and — where we relied on your consent — to withdraw that consent at any time without affecting anything done before you withdrew it. You also have the right to lodge a complaint with your national supervisory authority. In the UK, that is the Information Commissioner’s Office.
If you are in California or another US state with a privacy law
You have the right to know what personal information we collect and why, to obtain a copy of it, to have it corrected or deleted, and to opt out of its sale or sharing and of targeted advertising. As stated above, we do not sell or share personal information and do not run targeted advertising, so there is nothing to opt out of in that respect — but you can still switch off analytics using the footer link. We will not treat you differently for exercising any right; the site works identically either way.
How to exercise any of this
Email [email protected]. Please tell us which right you are exercising. We may ask for information that helps us locate the relevant data. You may use an authorized agent, in which case we will ask for proof of their authority.
One practical caveat, offered honestly: because we collect no names, no email addresses, and no account identifiers, we usually have no way to connect a request to a specific person’s browsing data. Under GDPR Article 11 we are not required to acquire additional information purely to identify you, and asking you for more personal data in order to find data we hold anonymously would make your privacy worse, not better. Where that is the case we will tell you plainly instead of pretending otherwise, and we will still help you switch analytics off.
Children
Severity Daily is written for people who run technology inside organizations. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, write to us and we will delete it.
Advertising
Google AdSense is active on this site. The AdSense script is loaded on every page from pagead2.googlesyndication.com under our publisher account. That is true right now, on the page you are reading.
What that means in practice:
- We have not placed any ad units in our page templates ourselves. There are no ad slots written into our markup.
- Google may nevertheless serve advertising automatically, because the script we load is the site-level one that permits it to do so. Whether an ad appears on a given page is Google’s decision, not ours.
- AdSense can set advertising cookies and use the data described in this policy to select what it shows you, subject to the permissions below.
Your control over it. The three advertising permissions — ad_storage, ad_user_data and ad_personalization — are denied by default for visitors in the EEA and the UK, and stay denied unless you accept. Elsewhere they are granted by default and you can refuse them at any time through the cookie settings link in the footer. Declining does not remove advertising, but it does prevent advertising cookies and personalization based on your behavior.
An honest limitation. Denying advertising permissions, or arriving with a Global Privacy Control signal, stops advertising cookies and personalization. It does not currently stop Google’s advertising scripts from loading and contacting Google’s servers — we have measured this and it is true today. Those requests carry your IP address and user agent. If you want no contact with Google’s advertising infrastructure at all, a content blocker in your browser is presently the only way to guarantee it, and we would rather tell you that than let you assume otherwise.
Google’s own handling of advertising data is governed by its advertising policies and its Privacy Policy.
Two commitments. We do not sell or share your personal information for cross-context behavioral advertising, and if that ever changes it will be stated here in these words before it takes effect, not after. And advertising does not influence what this publication reports or how a story is written; if an advertiser is ever the subject of a story, that story runs the way it otherwise would.
Security
The site runs over HTTPS, sits behind Cloudflare, and is backed up regularly. The account that publishes stories automatically holds the minimum WordPress role that lets it do that job and cannot alter site settings, users, or plugins. We think a publication about security incidents should be able to say specifically what it does rather than promise vaguely that your data is safe, so that is the specific answer.
Changes to this policy
Material changes are logged here with a date, and the effective date at the top of the page is updated. We do not quietly edit this page, for the same reason we do not quietly edit stories.
- August 30, 2026 — First published.
Contact
Express Development Group LLC
Publisher, Severity Daily
[email protected]
This policy is written to be read and understood, not to be technically unfalsifiable. It is not legal advice, and it has not been reviewed by an attorney.