The Personalized Privacy Assistant Project: Privacy Policy

Last updated on March 12, 2016


  • We collect cookie and usage data for analytics and research purposes only.
  • IP addresses are anonymized when storing usage data, so usage data is not easily identifiable.
  • If you subscribe to our mailing list or contact us directly, your contact information will be stored and only used to communicate with you
  • Personally-identifiable information is not shared with third parties. Aggregated information may be shared with third parties and reasonable efforts will be taken to ensure that individuals cannot be re-identified through ordinary means.

Your Consent to This Privacy Policy

By using the website or applications of the Usable Privacy Project, you acknowledge and agree to the terms of this Privacy Policy.

Collection and Use of Information

Websites and applications of the Personalized Privacy Assistant Project collect and use the following types of information for the purposes described below:

Usage Data

Websites and applications of the Personalized Privacy Assistant Project, including the websites and, automatically collect usage data. We use this data to make sure that the website functions properly and we perform analytics, including measuring the popularity of different parts of the site, on this data to improve the operation of the website and its usability. Website usage data is also used to inform the improvement and further development of our websites and applications and for research purposes.

Usage data is collected with the open analytics platform (Piwik) that runs on servers located and maintained at Carnegie Mellon University. We set and collect cookies in your browser and record anonymized IP addresses. This means that we can learn how you use the websites and applications operated by us, but cannot easily link this information to your identity. Additional information can be found here.

We respect DoNotTrack requests. Learn more about DoNotTrack at

Detailed visitor logs containing usage data will be deleted after 6 months. Historical, aggregated web analytics reports are retained indefinitely but do not allow the identification of individual visitors.

Contact Information

We provide the opportunity to subscribe to a mailing list to receive news about the Personalized Privacy Assistant Project. If you subscribe to the mailing list, your email address and your name (if you choose to provide it) will be stored on a mail server operated by Carnegie Mellon University. Contact information will only be used to send you news about the Personalized Privacy Assistant Project and related activities.

If you contact project members directly, your email address and personal information may be used to communicate with you.

Sharing of Information

Personally-identifiable information

We do not share personally-identifiable information with third parties, unless required to fulfill your request or required by law.

We embed videos from our YouTube channel using YouTube’s privacy-enhanced mode. It is our understanding that this mode means that YouTube will not store information about you unless you play the video, in which case YouTube may store information about you viewing the video and may place cookies on your computer. Learn more about YouTube’s privacy-enhanced mode here​.

Aggregated information

Aggregated or anonymized information, such as web usage statistics, may be made public on our websites, in our applications, and as part of publications or presentations. Whenever aggregated information is made available in any form, we will take reasonable efforts to ensure that individual users cannot be re-identified through ordinary means.

User Access

To access, change or delete information related to your mailing list subscriptions, login to the subscription management page for the mailing lists to which you are subscribed.

Age Restriction

The website and online applications of the Personalized Privacy Assistant Project are not directed to, and we do not knowingly collect any information from, anyone under the age of thirteen (13). If you are under thirteen (13), please do not use this website or its applications. If you learn that your minor child has provided us with personal information without your consent, please contact us.

Changes to this Privacy Policy

This privacy policy may be updated to ensure consistency with data collection, use and sharing practices and legal or regulatory requirements. If changes become necessary, they will be posted here. The most recent update date is shown at the top of this privacy policy. The policy update will also be announced on the website’s homepage if it alters collection, use or sharing practices. Your continued use of the website or applications of the Personalized Privacy Assistant Project after any changes to this privacy policy constitutes acceptance of those changes.

Privacy Contact

The privacy policy pertains to websites and applications operated by the Personalized Privacy Assistant Project. If you have questions or requests concerning data practices, please contact us:

Personalized Privacy Assistant Project
Primary contact: Norman Sadeh
Institute for Software Research
School of Computer Science
Carnegie Mellon University
5000 Forbes Ave.
Pittsburgh, PA 15213, USA.