Skip to content

Privacy Policy

Last updated: 29 July 2026.

1. Who is responsible

Worth or Skip is published and operated by Roberto Oliveira, an individual, based in Brazil. For the purposes of the EU/UK General Data Protection Regulation, he is the data controller for personal data processed through this website.

To contact us about anything on this page, use the Contact form and choose Privacy request. We have not appointed a Data Protection Officer and are not required to: we carry out no large-scale processing and no systematic monitoring of individuals.

2. What we collect, why, and on what basis

Server logs — collected automatically

Our hosting provider records standard web-server logs: IP address, browser and device type, the page requested, the referring page, and a timestamp. We use them to keep the site available, diagnose faults, and detect abuse such as brute-force login attempts. Legal basis: legitimate interests, GDPR Art. 6(1)(f). These logs are not used to profile you and are not combined with any other data set.

Analytics — only after you say yes

We use Google Analytics 4 and Microsoft Clarity to understand which pages are read and where the site is confusing. Legal basis: your consent, GDPR Art. 6(1)(a).

These tools do not load, and set no cookies, until you accept them in the consent banner. That is enforced technically, not by policy: Google Consent Mode v2 is set to deny all storage before any tag loads, and the tags themselves are not injected until consent exists. If you decline, or simply ignore the banner, no analytics runs at all. We apply this everywhere in the world, not only in Europe.

You can withdraw consent as easily as you gave it, using Cookie preferences in the footer. It takes effect immediately.

Newsletter — only if you sign up

If you subscribe, we collect your email address, the IP address you signed up from, and the fact and time of your subscription and consent.

Why: to send you an email when a new verdict publishes, and to keep a record that you actually consented — the IP address and timestamp are our evidence of that consent, in case it is ever disputed. Legal basis: your consent, GDPR Art. 6(1)(a), for the emails themselves; legitimate interests, GDPR Art. 6(1)(f), for keeping the consent record.

The list lives on our own server and the emails are sent directly from it — no mailing-list vendor holds your address. Outgoing mail is relayed through a Google SMTP account, so Google’s servers handle delivery in transit; see §4.

Every email carries a one-click unsubscribe link that works without logging in. Unsubscribing marks your record inactive immediately; we keep the inactive record rather than deleting it outright, so we do not accidentally re-add you if you resubscribe by mistake. This list is entirely separate from the mailing list of the publisher’s Portuguese-language site.

Contact form — only if you write to us

Whatever you put in it: typically a name, an email address, and your message. We use it to answer you. Legal basis: legitimate interests, GDPR Art. 6(1)(f). Messages are delivered by email and are not stored in this website’s database.

Affiliate links

When you follow an affiliate link, the merchant may set a cookie on their domain recording that you arrived from this site, so a commission can be attributed. We do not control that cookie, cannot read it, and never see your purchase details, payment details, or identity.

We do count the click on our own side, to know which reviews are useful. That record contains the link name, the campaign token, the date, and a salted hash of your browser’s user-agent string for filtering out bots. It contains no IP address and nothing that identifies you.

What we never collect

We do not ask for or store payment details, government identifiers, or health data. There is no reader login. We do not use Gravatar, and we load no webfonts or scripts from third-party CDNs — so your IP address is not sent anywhere just for the page to render.

3. Cookies

Strictly necessary — set without consent. Remembers your consent choice and keeps the site secure. No tracking.

Analytics — consent required. Google Analytics 4, Microsoft Clarity.

Advertising — none. This site carries no advertising pixels and no remarketing tags. If that changes, this page will be updated before the tag is installed, not after.

4. Who your data goes to

  • Hostinger — hosting and server logs. Data centre in Brazil.
  • Google Ireland Ltd / Google LLC — analytics, if you consent; and SMTP relay for outgoing email (contact replies, newsletter, unsubscribe confirmations). EU and United States.
  • Microsoft Corporation — Clarity, if you consent; Bing Webmaster Tools. United States.

We do not sell your personal data and we do not disclose it to anyone else except where the law requires it.

5. International transfers

This site is hosted in Brazil. If you are in the European Economic Area or the United Kingdom, your data is therefore transferred outside it. Brazil is not covered by a European Commission adequacy decision, so that transfer relies on appropriate safeguards in our agreement with the hosting provider. You may request details of those safeguards through the Contact page.

6. Your rights under the GDPR

If you are in the EEA or the UK you have the right to: access your data; have it corrected; have it erased; restrict or object to its processing; receive it in a portable format; and withdraw consent at any time without affecting processing that already happened.

To exercise any of these, use the Contact page. We respond within one month. There is no charge and you do not have to justify the request.

You also have the right to lodge a complaint with your national supervisory authority. In the UK that is the Information Commissioner’s Office; in the EU, the authority where you live.

7. Your rights under the CCPA/CPRA (California)

California residents have the right to know what personal information is collected and why, to request its deletion, to request correction, to opt out of the sale or sharing of personal information, and not to be discriminated against for exercising any of these.

Categories collected in the last 12 months: identifiers (IP address in server logs; email address if you write to us or subscribe to the newsletter) and internet activity information (pages viewed, and interaction data if you consented to analytics). We do not collect the categories the statute treats as sensitive.

We do not sell personal information. As currently built, the site runs no advertising pixels, so nothing is shared for cross-context behavioural advertising. If that changes, this section will be updated and a “Do Not Sell or Share My Personal Information” link will be added to the footer.

We honour the Global Privacy Control (GPC) browser signal as a valid opt-out request. If your browser sends it, no analytics loads and you are not shown a consent banner at all.

8. Children

This site is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has provided us with personal information, tell us and we will delete it.

9. Security

The site is served over HTTPS with HSTS. Administrative access is rate-limited against brute force, the file editor is disabled, and the site sends a content security policy and related hardening headers. No system is perfectly secure — but the publisher’s day job is infrastructure security, and this site is configured accordingly.

10. Changes to this policy

If we change how data is handled, we will update this page and change the date at the top. Where a change is material — a new category of data, a new recipient, a new purpose — we will say so prominently rather than relying on you to re-read the page.