Project
Nightshift privacy
How the Nightshift website and plugin handle website requests, project state, support bundles, external links, and third-party coding hosts.
Answers: Nightshift privacy policy · Updated
The Nightshift website has no account system, forms, advertising, or data sale; it uses cookie-free Cloudflare visit counts and disclosed Microsoft Clarity and Google Analytics measurement. The plugin keeps its working state in project-local files and does not require a separate Nightshift server or API key. Hosting and linked services apply their own policies.
Website data
This static site is served through Cloudflare, which processes standard request data (IP address, user agent) to deliver pages and provides aggregate traffic counts. The site uses three measurement tools. Cloudflare Web Analytics counts visits at the edge and sets no cookies. Microsoft Clarity records sessions — where people click, how far they scroll — without identifying anyone; it sets cookies to tell returning browsers apart and sends what it records to Microsoft under the Microsoft privacy statement, keeping recordings for 30 days and aggregate heatmaps for nine months. Google Analytics measures visits and the channels that drive them; it sets cookies and processes data under Google’s privacy policy. Blocking any of these scripts breaks nothing.
- No Nightshift account system, forms, advertising, or data sale.
- No newsletter or marketing profile is created.
- External links leave this site and follow the destination’s policy.
Plugin and project state
Nightshift stores its punch list, decisions, logs, recovery markers, and optional receipts in project-local files. It has no separate Nightshift API key or hosted Nightshift account.
- Project state stays under the configured Nightshift workspace.
- The optional receipts repository is local-only and has no remote by default.
- The coding host and tools you authorize may process data under their own configuration and terms.
Support material
The support exporter creates a local, permission-restricted bundle and removes configured secrets, transcripts, URLs, and identifying paths according to the released sanitizer. Nothing is uploaded automatically.
- Inspect any bundle before sharing it.
- Do not publish secrets or private project content.
- Security reports can use the repository’s private advisory path when appropriate.
What this workflow does not claim
- The website is served through Cloudflare, which processes standard request data to deliver pages; Microsoft Clarity and Google Analytics are disclosed on this page.
- Installing a coding host or external integration remains subject to that provider's separate privacy terms.
Evidence and sources
These links support the released behavior, public outcomes, or problem language described on this page.