Privacy

How the site reaches you

vlist.io is served through Cloudflare. To deliver the pages, Cloudflare processes information about your request, including your IP address. Cloudflare describes this in its privacy policy.

Cloudflare's responses also ask your browser to report failed requests: if a request to vlist.io fails, a browser that supports this may send a report of the failure to Cloudflare, at a.nel.cloudflare.com.

Counting visits

Visits are counted with Cloudflare Web Analytics. If your visit reaches Cloudflare through one of its data centers in the EU, the EEA, Switzerland or the UK, the analytics script isn't loaded (Cloudflare's description, read on 3 October 2026). Otherwise, your browser loads it from static.cloudflareinsights.com, and the beacon reports to this site's own /cdn-cgi/rum, which Cloudflare handles at its edge.

Cloudflare says that Web Analytics "does not use any client-side state, such as cookies or localStorage, to collect usage metrics", and that it doesn't "fingerprint" individuals through their IP address, User Agent string, or any other data to display analytics. Source: Cloudflare Web Analytics, read on 3 October 2026.

Cookies and other sites

The server sets no cookies. The example pages keep one choice — how they scroll — in a first-party cookie named vlist-scroll-mode, written by their own code and sent only back to vlist.io.

Some examples show pictures from other sites: the photo album and the carousel load photos from picsum.photos (served from fastly.picsum.photos), the variable-sizes example loads avatars from i.pravatar.cc, the track list loads cover art from asset.radiooooo.com, and the social-feed example loads Reddit's images. Your browser requests those images from those hosts.

The analytics script, where it is loaded, comes from Cloudflare's static.cloudflareinsights.com. Everything else — fonts, styles, scripts — comes from vlist.io itself.

An RSS feed you add to the social-feed example is fetched by our server from that feed's host.

What the site remembers

The site keeps your choices in your browser, and only once you change one of them:

The site doesn't send these to anyone else. The scroll-mode cookie goes back to vlist.io with your requests and the server ignores it, and the social feed's subreddit or feed address is sent to our server to fetch the feed. To remove them, clear the site data for vlist.io in your browser's settings.

If you run a benchmark

When a benchmark run on the benchmarks page succeeds, the page sends the result to our server, which stores it in the site's SQLite database, data/benchmarks.db: the benchmark's scores, the user agent your browser reports, and the number of CPU cores. A run that fails is not stored, and nothing else about you is attached.

Submissions are rate-limited by IP address, so one visitor cannot fill the database: the address is held in memory for a few minutes at most, to count submissions, and never written down.

Contact

Questions about this page: open an issue on GitHub.

Last updated 3 October 2026.