Privacy

This page covers audience measurement on docs.toryo.ai. The toryo privacy policy covers everything else we collect, and it applies here too.

What this site measures#

The site sets no cookies for audience measurement and embeds no third-party trackers. Optional audience measurement estimates public page displays, unique visitors and visits to understand aggregate usage of the documentation. Repeat displays count again; blocked requests, network failures and imperfect bot filtering can cause undercounting or overcounting. Visitor and visit counts are estimates: they are not people, accounts or verified attribution.

When enabled, measurement retains the normalized documentation page path, server timestamp, a daily visitor hash and a visit record (both described below), broad browser and operating-system families, approximate country and region (not city or coordinates), external referrer hostname, internal, external or unknown referrer classification, which toryo site an internal referral came from (toryo.ai or docs.toryo.ai, never the page), and approved source, medium and campaign labels, and for each page display, how long the page was visible (up to 30 minutes) and how far down it was scrolled, as a percentage. No labels are currently approved for this site. Unknown attribution and unavailable location or browser details stay unknown. When you leave a counted page, including by moving to another page on this site, the browser sends that page's visible time and scroll depth in one final request, without cookies or a referrer.

Measurement on this site also records one custom event: a click on a link to another site. It retains the event name, the page the link was on, the server timestamp, the daily visitor hash and visit described below, and the hostname the link leads to when it is toryo.ai, docs.toryo.ai or github.com. Any other destination is kept as unknown, and a destination's path is never sent. Custom events never start, extend or end a visit. They follow the same opt-out, GPC and Do Not Track suppression as page displays, are sent only for a page whose display was counted, and are kept and deleted on the same schedule. The event list changes only with a reviewed release; any other event is rejected.

To count visitors and visits without cookies, the server computes a visitor hash from a secret random salt, the fixed name toryo.ai, your IP address and your browser's full user-agent string, using a keyed one-way function (HMAC-SHA256), and keeps only the first 64 bits. A new salt is generated at random for each UTC day and is used to compute stored hashes only on that day. It is kept through the following UTC day, only so that a visit crossing midnight UTC continues, and is then deleted, so no salt is kept longer than about 48 hours unless an outage delays that deletion. While a salt exists, someone holding both it and the measurement database could test guessed IP addresses and user agents against a hash. Once it is deleted, hashes made with it can no longer be matched to an IP address or user agent. The same browser gets an unrelated hash each day, so separate visits on different days cannot be linked, except that a visit continuing across midnight UTC links that browser's hashes for those two days. The same hash is used on toryo.ai and docs.toryo.ai, so someone who reads both sites on the same day counts as one visitor. Page displays from the same visitor hash belong to one visit until 30 minutes pass with no display, not counting up to 30 minutes of time spent viewing each counted page, and leaving a page you viewed restarts that count; the next display after that starts a new visit. A visit record holds its start and last-activity times, first and last page, the site it began on, its number of displays, total visible time, whether it was a single-display visit with under 10 seconds of visible time, and a copy of the referrer hostname and classification, campaign labels, coarse location, and browser and operating-system families of its first display, with the traffic channel derived from them. Your IP address and user-agent string are used only in memory to compute the hash and are never stored. When the server cannot establish a trusted client IP address, it records the display without a visitor hash or visit.

Measurement records and diagnostics never store IP addresses, full user-agent strings, full referrers, full URLs or query strings. The daily visitor hash and the visit record are the only per-visitor data kept, and they are not linked to cookies, accounts or other devices. Measurement has no account or signup linkage, advertising integration or external analytics vendor.

A trusted ingress IP may be used transiently, in memory, to compute the visitor hash and to look up approximate location in a locally stored MaxMind GeoLite2-City database. The server periodically downloads that database from MaxMind; visitor IPs are not sent to MaxMind for lookup.

Individual page-view events and custom events, with their visitor hashes, and visit records are kept for 13 calendar months; there are no separate aggregate counts. Visitor-hash salts are deleted as described above. Scheduled sweeps remove expired data; outages and catch-up backlogs can extend physical retention.

Your choice#

Measurement is enabled on this site. Checking the control below suppresses measurement in this browser. It stores only a local opt-out flag, not a visitor identifier, in this site's localStorage.

The preference is specific to docs.toryo.ai. It is stored separately from the one on toryo.ai, so opting out on one site does not opt you out on the other, and it needs to be set separately on another browser or device.

Global Privacy Control (GPC) and Do Not Track suppress measurement and override allowance. Failure to read or write browser storage also suppresses collection. Opting out aborts pending requests where possible, but cannot retract events already received.

Reading browser preference.