Skip to content
Home Calibration Methodology Deutsch

Legal & transparency

Privacy notice

BrowserBenchmark.org technically separates audience measurement, benchmark operation, voluntary calibration data and public result sharing.

1. Controller

Sebastian Schöne
Fregestr. 7
04105 Leipzig
Germany
Email: 4websolutions@web.de

2. Hosting and server logs

The website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The web server processes technically necessary connection data such as IP address, time, requested resource, transferred data volume, browser/operating-system information and, where available, referrer data. This is used to provide and secure the website. The legal basis is Art. 6(1)(f) GDPR. A data-processing agreement under Art. 28 GDPR is in place. Server logs are routinely deleted unless a security incident requires longer retention.

3. Benchmark operation without calibration consent

To run a benchmark, the server creates a random run and processes measurement samples, suite ID, normalised technical environment information, runtime phases, integrity data and quality information. Scores are calculated server-side from validated raw samples. The time-critical measurement phase makes no network requests.

The full IP address is not stored in the benchmark database. A daily-changing HMAC value derived from the IP address is used for short-term abuse and rate limiting. Results that are neither contributed to calibration nor explicitly shared are currently deleted after no more than 24 hours. The legal basis is Art. 6(1)(f) GDPR.

4. Voluntary calibration and statistics consent

Before the benchmark, you may voluntarily consent to the run being used for later reference calibration and statistical methodology. The benchmark also works without this consent. Calibration consent is separate from public result sharing.

With consent, we retain the complete validated run, including raw samples, quality and warning information, runtime phases and data-minimised environment information. Source and confidence metadata are stored for relevant environment fields. Mobile runs are marked separately as exploratory in the current beta.

Calibration data is retained for as long as it is needed to build, review and complete the reference calibration. After the reference calibration has been completed, calibration data that is no longer required for that purpose will be deleted or handled under a separately documented legal basis. The legal basis for voluntary calibration processing is Art. 6(1)(a) GDPR.

Consent can be withdrawn for future processing from the associated result page using the locally stored owner key. The additional calibration record is then removed and the run is no longer treated as a calibration contribution. A separately enabled public result share is not changed by that withdrawal.

5. Temporary device signature during calibration

Only after calibration consent, the browser creates a temporary device signature before the test. Its purpose is to stop, for example, ten runs from the same computer being counted as ten independent devices. The signature is used solely as a technical deduplication aid while the reference dataset is being built.

For the most cross-browser-stable signature possible, screen dimensions, device pixel ratio and colour depth, reported CPU threads, touch points, a coarsely normalised platform family and the time zone are combined. Depending on browser availability, coarse memory and client hints for architecture, bitness, platform version and model may additionally be collected as calibration metadata. These browser-dependent extras are not part of the stable device identifier. No font lists, audio fingerprints or canvas-pixel images are collected.

Signature features are normalised server-side and transformed into an HMAC-based check value. The HttpOnly cookie bb_cal_device lasts at most one hour. The server-side device value follows the retention of its calibration run and will not be continued as a permanent visitor identifier after reference calibration is complete. The resulting device count remains a technical estimate rather than a guaranteed count of physical devices.

End-device information is processed only after explicit calibration consent; the legal bases are Art. 6(1)(a) GDPR and § 25(1) TDDDG.

6. Same-device browser comparison via pairing link

After a result, you can voluntarily create a random comparison link to test the same computer in another browser. The code is random and is not reconstructed from device information. After opening, it is moved to the HttpOnly cookie bb_pair and removed from the URL. An incomplete pairing expires after at most 2 hours.

If two runs have explicitly been linked and are used for calibration, that pairing relationship may be retained together with the associated calibration data until reference calibration is complete. Pairings are not reconstructed from fingerprints.

7. Public result sharing and deletion

Each result has a hard-to-guess result URL and a separate owner/delete key stored only in the local browser. Results are not marked public by default and are delivered with a noindex directive. Public sharing can only be enabled or disabled through a separate owner action.

Publicly shared result summaries remain stored until sharing is revoked, the result is deleted with the owner key, or another technical deletion rule applies. If a run belongs to the voluntary calibration dataset, its raw samples may remain until reference calibration is complete. Raw samples from other completed runs are removed after the technical raw-data period of no more than 90 days. A complete result deletion also removes any still-present samples, calibration and pairing relationships through the database links.

8. Consent, cookies and LiteStats audience measurement

On general public information pages, a consent tool from our own stats1.de infrastructure manages consent for the cookie mode of LiteStats/LiteTrack. LiteStats runs on our own stats2.de infrastructure hosted in Germany at Hetzner. By default it operates without cookies and records page/time, referrer and technical information such as browser, operating system, screen resolution and language. A daily-changing check value derived from IP address and browser identification is used to distinguish sessions within one day; full IP addresses are not permanently stored. The legal basis for cookieless audience measurement is Art. 6(1)(f) GDPR.

With consent, LiteStats additionally uses _lt_ses for 30 minutes and _lt_vid for up to 365 days. The legal bases are Art. 6(1)(a) GDPR and § 25(1) TDDDG. LiteStats consent is separate from benchmark calibration consent. See the LiteStats privacy information for details. The statistics scripts are deliberately loaded neither on the benchmark test page nor on tokenised result pages. This prevents statistics traffic from interfering with measurement. Tokenised result pages additionally send no referrer, so the hard-to-guess result URL cannot reach audience measurement indirectly after navigating to a general page.

9. Local browser storage

Functional local storage includes the appearance preference (bb-theme) and the locally held owner/delete key for results (bb-delete-…). Losing browser storage can make owner actions unavailable for an existing result.

10. Encryption and security

The website is served over TLS/HTTPS. Security-relevant cookies use HttpOnly and SameSite properties. Private configuration, the database, logs, backups and calibration exports remain outside the public web root.

11. Contact

When you contact us by email, the contact details and message content you provide are processed to answer the request. The legal basis is Art. 6(1)(b) GDPR where the request relates to a contract, otherwise Art. 6(1)(f) GDPR.

12. Your rights and complaints

Data subjects have the rights provided by the GDPR, including access, rectification, erasure, restriction, portability and objection where applicable. Consent may be withdrawn at any time for future processing. Complaints may be submitted to the Saxon Data Protection and Transparency Commissioner (Sächsische Datenschutz- und Transparenzbeauftragte), Maternistraße 17, 01067 Dresden, Germany, email post@sdtb.sachsen.de.

13. Version

This privacy notice is dated August 2026 and will be updated when processing, calibration methodology or legal requirements change.

BrowserBenchmark.org Version 1.0.0-alpha.8.8 · core-1.0.0-alpha.8
Privacy Legal notice Administration

Independent project · not affiliated with BrowserBench.org