Privacy policy
Emoji Directory is designed to work without knowing who you are. This page describes exactly what data the site handles, which is limited to ordinary server logs, anything you send through the contact form, and two items stored in your own browser.
Published · Updated
Who operates the site
Emoji Directory (emojidirectory.co) is independently owned and operated. The operator is the controller of any personal data described on this page.
The operator’s legal name and postal address are not yet published. They will be added here once confirmed by the owner. Until then, use the contact form for any privacy question or request.
What is collected, and why
Server logs
Like almost every website, the web server records each request: the address requested, the date and time, the HTTP status, the referring page if your browser sends one, your browser’s user-agent string and your IP address. These logs exist to keep the site running, to detect abuse and to diagnose errors. They are written by the LiteSpeed web server on the site’s own server and are rotated automatically; log files are kept for 10 days and then deleted.
Contact form
If you use the contact form, the site stores the name, email address, subject and message you enter, the time of submission, your browser’s user-agent string and a one-way hash of your IP address (used only to limit repeat submissions; the raw address is not stored with your message). This data is used to read and reply to your message and for nothing else. It is stored in a directory outside the web root on the site’s server with restrictive file permissions. Messages are kept until the enquiry is dealt with and then deleted, and in any case for no longer than 12 months. Rate-limit records expire after one hour.
Data that stays in your browser
Two items are stored with your browser’s local storage, on your device only. emoji-favorites-v1 holds the IDs of emoji you have saved with the Save button, so they are there next time; it is written only when you press Save and only if you have not switched off functional storage in the cookie settings. ed-consent-v1 records the choice you made in the cookie banner. Neither is sent to the server, and neither can identify you. The cookie policy lists both in detail.
What is not collected
- No account, registration or login exists.
- No analytics or audience-measurement service is used; there is no Google Analytics, no pixel and no tag manager.
- No advertising, no affiliate tracking and no social-media widgets are embedded.
- No third-party fonts, scripts or content-delivery networks are loaded; every file comes from emojidirectory.co.
- Searches and combinations are processed entirely in your browser. What you type in the search box is never transmitted.
Third parties
The site is hosted on a virtual server rented from Hostinger and operated by the site owner; the hosting provider processes network traffic and stores the server’s disk in the ordinary course of providing hosting. TLS certificates are issued by Let’s Encrypt, which involves no personal data from visitors. No other processor receives visitor data.
Pages link to outside websites (Unicode, GitHub, NASA, Creative Commons, Emojipedia and others). Those sites have their own privacy practices, which this policy does not cover. Links to other sites are marked by their address and open the site you see in the link.
Legal basis and your rights
Server logs are processed on the basis of the operator’s legitimate interest in running a secure, working website. Contact-form data is processed because you asked for a reply. Browser storage is used only for a feature you explicitly requested (saving an emoji) or to remember your own consent choice.
Depending on where you live, you may have the right to ask what personal data is held about you, to have it corrected or deleted, to object to or restrict its processing, and to complain to a supervisory authority. Because the site holds so little, the practical answer to most requests is that nothing is held beyond a log line that expires within 10 days; contact-form messages can be deleted on request at any time. Send requests through the contact form choosing “Privacy request”; you will receive a reply at the address you provide.
This policy describes the site’s actual practices. It is not a statement that the site has been audited for, or certified under, any particular data-protection law.
Children
The site does not knowingly collect personal data from children. It has no accounts and no features that ask for age or identity; the contact form should be used by adults or with a guardian’s help.
Security
All traffic is served over HTTPS; requests over plain HTTP are redirected. The contact form uses signed tokens, a rate limit and server-side validation, and stored messages are readable only by the server process. No method of storage is perfectly secure, and the site does not store anything sensitive enough to require more than these measures.
Changes to this policy
When practices change — for example if an analytics tool were ever added — this page and the cookie policy will be updated before the change takes effect, and the “Updated” date at the top will move. Continued use of the site after a change means the updated policy applies.