Privacy
People come here to read about bladder programs, pressure injuries, depression, and sex after injury. That is nobody else's business. This page says exactly what the site records, in plain language, and gives you a button to turn it off.
The short version
SCI.help counts how many people read each page, and groups a week's activity together so it can tell one person reading six pages from six people reading one. There are no cookies, no advertising trackers, no Google Analytics, no Facebook pixel, and no third-party analytics company of any kind. Nothing identifying is stored on your device. Your IP address is never written down. The grouping key is a one-way hash that is thrown away and replaced every week, so activity from a month ago cannot be connected to you, to your address, or to anything you read since.
Turn it off
If you would rather not be counted at all, this button stops the tracker on this device. It takes effect immediately and it sticks until you clear your browser storage.
Two notes on that button. It stores one value in your browser's local storage, the flag that tells the tracker to stay quiet, which is the only thing this site ever writes to local storage. And if your browser blocks storage entirely, in a private window or with strict blocking on, the button cannot save the setting, but browser-level tracking protection generally blocks the tracker anyway.
What is recorded when you read a page
Every page loads one small script, written and hosted here, that reports what happened on the page. Nothing is sent anywhere except sci.help. Here is every field, and why it exists.
| What | Example | Why |
|---|---|---|
| Page address and title | /articles/pressure-injuries/ | To know which guides get read and which get ignored |
| What you did on it | Clicked a link, ran a search, changed a filter, scrolled 75% down, submitted a form, hit a JavaScript error, left the page | To find broken features, searches that return nothing, and pages people give up on |
| Seconds spent reading | 90 | To tell a page that helps from a page people bounce off |
| Where you came from | google.com, chatgpt.com, a link someone shared, or Direct | To know whether this information is reaching people |
| The page you were on before | /newly-injured/ | To see which paths through the site make sense |
| A session id | A random value your browser makes, hashed before it is stored | To count one visit as one visit. Dies when you close the tab |
| A device key | A one-way hash, computed on the server, that rotates weekly | To tell returning from new inside a 7-day window. Details below |
| Country and city | US, Austin, TX | Coarse geography, from the hosting edge. Never an address, never GPS |
| Device, browser, operating system | Mobile, Safari, iOS | To catch layout and feature breakage on real devices |
| Screen size, language, time zone | 390x844, en-US, America/Chicago | Same reason |
The device key, in detail
This is the part most sites are vague about, so here is the whole mechanism.
Your browser is not given an identifier and does not send one. Instead the server computes a key from things the request already carries:
device key = SHA-256( secret salt + your IP + your browser's user agent + sci.help )
A hash is one-way: the key cannot be turned back into your IP. The salt is a long random secret held only on the server, and it is replaced with a new random value every week. The previous week's salt is kept alongside it so that a visit spanning the changeover is not split in half, which is why the practical window is 7 to 14 days rather than exactly 7.
That rotation is what makes this different from a tracking id. Once a salt is discarded, the keys it produced cannot be recreated from any IP address by anyone, including me. Old records stop corresponding to a findable person.
Your IP address is an input to that calculation and is never itself written to storage. It is not in the daily files, not in the device records, and not in anything the dashboard can display.
What a device record holds, and for how long
Inside the window, a record for a device holds the pages it viewed in order, its sessions, counts of clicks and searches, the source it first arrived from, and the coarse location and device type already listed above. Two separate rules bound it:
- Every write trims the record to the last 7 days. This holds no matter how often someone visits. A device that comes back every week for a year still never has more than a 7-day tail stored.
- Records untouched for 14 days are deleted outright. Not archived, not anonymized further, deleted.
So the honest answer to "how long do you keep it" is: 7 days of detail, gone entirely within 14. The aggregate daily counts, which are not tied to any device, are kept longer so year-over-year traffic comparisons are possible.
What this approach gets wrong
Because the IP is part of the key, people sharing one internet connection collapse into a single "device." Everyone on a rehab hospital's wifi looks like one device. So does a large share of mobile traffic, because phone carriers route many customers through shared addresses. The site's device counts therefore run low, and mobile runs lowest.
This is worth stating plainly for two reasons. It means the numbers on the dashboard understate real readership. And it means the record labeled as one device is sometimes several people's reading mixed together, which is a privacy property working in your favor, and an accuracy problem working against mine. The alternative, a permanent id stored in your browser, would count better and is what this site used until 18 September 2026. It was removed and the profiles it had built were deleted.
What is not recorded
- No cookies. The site sets none, for any purpose.
- No stored IP address. It is an input to the device hash and is never written. The hosting provider sees it in transit, the way every web server does.
- No identifier on your device. The only browser storage used is a session id that dies with the tab, plus the opt-out flag if you set one.
- No permanent history. Nothing survives the retention above, and nothing links one window to the next.
- No cross-site tracking. No advertising networks, no pixels, no fingerprinting scripts. The site loads no scripts from anyone else.
- No account, no email, no name unless you type one into a form yourself.
- Nothing is sold or shared. No data broker, no advertiser, no partner, no exceptions.
Forms you fill in yourself
Two pages ask for information, and both are obvious about it because you type into them.
- The feedback form takes your message, and optionally a name and email if you want a reply. If you leave the email blank there is no way to contact you, which is fine.
- The equipment exchange takes a listing: what you are offering, its condition and price, your city and state, and a contact email or phone so a buyer can reach you. Listings are public by design, so treat that contact information as published. Do not put a home address in a listing.
Both are handled by Netlify Forms, the hosting provider's own form service. Submissions are emailed to the site owner and kept in the hosting account. They are not added to a mailing list and not used for anything but answering you and running the exchange. If you want a feedback message or a listing deleted, ask through the feedback form.
Other companies involved
- Netlify hosts the site. Like every web host it sees request IP addresses and keeps its own short-term server logs, outside this site's control. Netlify also provides the country and city shown above, and stores the analytics files.
- Amazon. Some equipment pages link to Amazon through the affiliate program, and a purchase there earns this site a small commission at no extra cost to you. Those are ordinary links: nothing loads from Amazon until you click one, and after you click you are on Amazon's site under Amazon's privacy policy.
- Outbound links generally. ClinicalTrials.gov, CMS, PVA, MSKTC, hospital sites and the rest are independent sites with their own policies. A click is recorded here as a count of that link; where you go afterward is not visible to this site.
Children
This site is written for adults managing a spinal cord injury and is not directed at children. No account is required, and nothing here knowingly collects information from a child.
Your rights
Data protection laws such as the GDPR and the CCPA give people the right to see, correct, or delete personal information a site holds about them. There is not much here for those rights to reach: no account, no name, no stored IP, and a device key that cannot be worked backward to find you, which also means a request to produce "your" record cannot be honored, because there is no way to prove which record is yours. If you would rather not appear in the counts at all, the opt-out button above is the direct route. If you submitted a form, that message does exist and you can ask to have it deleted through the feedback form.
If this changes
This page describes what the code actually does, not an aspiration. The deploy process refuses to publish the site if the tracker starts writing a permanent identifier, if the retention windows stop matching the numbers written on this page, or if this page goes missing. That check is not a promise, it is a build step.
Last updated 18 September 2026. On that date the permanent per-browser identifier was removed and replaced with the weekly rotating server-side key described above, and the profiles built under the old scheme were deleted.
