Privacy and statistics
Pebblyhill provides project and laboratory software. Account, membership, operational and controlled audit data support the service and its customer organizations. This notice describes the public statistics and optional organization access-history features introduced in September 2026.
We count public page totals to improve this website. Only the page category and day are aggregated; no visitor identity, referrer or device profile.
No exclusion saved. Basic public page counting applies when globally enabled.
Exclusion applies only to this browser and site. Reset removes the preference and resumes basic counting for visible public pages, unless a privacy signal or the global switch prevents it. Reset is not consent to extra data. Older allow choices enable no enrichment. Authenticated organization history is separate.
Public website statistics
When global collection is enabled, we count visible visits to Home, Product tour, Project work, Laboratory operations, Pricing, Security, Deployment, Privacy and the seven public laboratory/engineering product guides. Basic counting starts without a prior opt-in unless this browser is excluded or sends Global Privacy Control (GPC) or Do Not Track. Its sole purpose is to understand and improve this public website through daily page-category totals.
Basic counts contain only a public page category and UTC day. We do not add referring domains, device categories or location. We do not collect private app navigation, full URLs, query strings, search terms, fragments, accounts, form values or raw IP addresses into analytics. No advertising SDKs, third-party analytics scripts, tracking cookies, persistent visitor identifiers, fingerprints or cross-site tracking are used. These statistics are not used for advertising or decisions about individuals.
A random navigation identifier exists only in page memory for delivery retries. The server stores its hash with a 15-minute expiry to avoid counting a retry twice; it is not a visitor or session identifier and is not joined to other data. Rate-limit buckets expire within 24 hours. Public daily aggregates are retained for at most 90 days; the platform owner can shorten this. Expired information is excluded from reads immediately; managed deletion may follow later.
Use “Exclude my browser” here or in any public-page footer to object, free of charge. Only that exclusion preference is saved locally. Existing exclusions remain effective. “Reset exclusion” removes the preference; it is not an affirmative consent record. An older saved allow choice enables no extra data. GPC and Do Not Track always prevent collection.
These are page views, not unique visitors, sessions or verified humans. Reload and visible Back/Forward navigation count again; merely hiding and showing a page does not. JavaScript-disabled browsers, blockers and exclusions are not measured. Known automation is excluded where detectable; some bots remain. Only the platform owner can read public statistics. Earlier opt-in measurements remain separately labelled legacy history; we do not invent counts for visits that were missed.
This narrowly limited audience measurement uses immediate aggregation, a clear notice and a simple objection control. Cookie-free implementation alone does not create a universal legal exemption. Applicable statistical-measurement conditions and the separate handling of personal service data remain part of our privacy review.
Organization access history
Your Subscription Owner may enable history for your organization. A visible workspace notice then explains collection. History contains user and organization identity, primary Team, server-observed workspace entry, verified Firebase authentication time when newly observed, foreground activity observations and explicitly observed sign-out. Firebase authentication can include reauthentication; token refreshes are not new sign-ins. Silent browser closure is not sign-out. We do not reconstruct earlier history or measure working hours, attendance, productivity, keystrokes, employee location or browsing trails.
Activity is coalesced into five-minute intervals across tabs. An unattended or hidden page does not generate activity observations. Retention is at most 30 days and can be shorter. The Subscription Owner and explicitly delegated history readers can inspect organization history; active members can inspect their own. Platform ownership alone grants no tenant history access. Your organization determines its purpose and applicable employment/data-protection obligations before enabling collection.
Infrastructure and your controls
Google Firebase Authentication, Firestore and App Hosting process service data as hosting providers. Their operational request logs and backups are separate from these analytics collections and may contain IP addresses and request metadata under infrastructure retention. Protected laboratory, financial and command audits follow their separate retention rules. We do not sell these statistics or send raw IPs to a new geolocation service.
You can object to public collection using the controls above without losing service access. Contact your Subscription Owner for organization history access and retention questions, or use the existing Pebblyhill pilot support channel for platform privacy requests. Browser preferences do not identify your other devices.