S/U calculator · privacy · technical details
The S/U calculator reads your sensitivity files, and any covariance file you add, inside your web browser. They are not uploaded and not stored, and nobody else sees them: not the site's author, not Claude, and not GitLab, which hosts the site. This page explains how that works, what the page does send over the network, how your browser enforces it, and how to check it yourself.
Most of this work, including this page and the calculator, was generated with AI (Claude, Anthropic) under the direction of Ian H; it has not been independently reviewed. This page describes the code as published on 8 October 2026; it is not a security audit.
_sens0.m, COVERX) are read by JavaScript running in your browser tab, into that tab's memory.skipgc, with which a site's owner stops counting their own visits; it holds nothing else.)The site is static: GitLab Pages serves fixed files (HTML, JavaScript and JSON) from the public repository hardtohit10/hardtohit10.gitlab.io. There is no program on a server behind it, no database, no login and no upload address; a GitLab Pages site can only hand out files.
The calculator is three files, about 1,400 lines in all, readable exactly as your browser receives them: su-tool.html (the page), su-tool.js (its script) and su-core.js (the file readers and the arithmetic). Every change to them is in the repository's public history.
File object, and file.arrayBuffer() reads its bytes into memory. A file input only reads local files; sending them would need a form or a network request, and the page has neither (its policy forbids forms: form-action 'none').DecompressionStream.TextDecoder and parsed by parseSDF or parseSerpent in su-core.js into arrays of numbers.data: links, which the browser saves directly to your disk.The reading step, from su-tool.js:
const buf = await gunzipIfNeeded(await file.arrayBuffer());
addSDF(file.name.replace(/\.gz$/i, ""), file.size, new TextDecoder().decode(buf));
The only network calls in su-tool.js and su-core.js are fetch requests for the site's covariance files and, when you ask for them, the example files. Neither script uses XMLHttpRequest, sendBeacon, WebSockets, forms, cookies or browser storage.
| Request | When | To | What it contains |
|---|---|---|---|
| The page, its scripts and style sheets | When you open the page | hardtohit10.gitlab.io (GitLab Pages) | The names of the site's own files |
| Fonts | When you open the page | fonts.googleapis.com, fonts.gstatic.com (Google) | The names of the site's three fonts |
| Covariance index | When you calculate | hardtohit10.gitlab.io | cov/ampx/index.json, or the index of the library you chose |
| Covariance data, one file per nuclide | When you calculate | hardtohit10.gitlab.io | cov/ampx/n/92235.json and so on: the SCALE IDs of the nuclides in your files, and the library |
| Example files | Only when you press “Load the examples” | hardtohit10.gitlab.io | su-examples/… |
| Visit count | Once when you open the page, and once after you first move the pointer, scroll or touch | hardtohit10.goatcounter.com | The page's path (/su-tool.html), its title, the referring page, your screen width, a bot flag and the address's query string; the second is an “engaged” event with the path |
As with any web page, every server that answers a request also sees your IP address and your browser's identification string.
The covariance requests are the one place where something derived from your files leaves the browser. Whoever reads GitLab's server logs could tell that someone asked for, say, the U-235, U-238 and H-1 covariances of the AMPX-route library. They would not see a sensitivity, a file name, a title, k or a result. GitLab.com does not give the owner of a Pages site its access logs; the site's author sees only the GoatCounter counts. To avoid even the nuclide requests, run the calculator on your own computer.
The calculator and this page carry a Content Security Policy, a list of rules in the page's <head> that your browser applies to everything the page does:
default-src 'self';
script-src 'self' 'unsafe-inline';
style-src 'self' 'unsafe-inline' https://fonts.googleapis.com;
font-src https://fonts.gstatic.com;
img-src 'self' data: https://hardtohit10.goatcounter.com;
connect-src 'self' https://hardtohit10.goatcounter.com;
form-action 'none';
base-uri 'self';
object-src 'none'
| Rule | Effect |
|---|---|
connect-src | fetch, sendBeacon, XMLHttpRequest and WebSockets may reach only this site and the visit counter. |
img-src | Images, a common way to send data hidden in an address, may come only from this site, data: addresses and the visit counter. |
script-src | Scripts only from this site (and the short inline script of the site index); no third-party scripts. |
style-src, font-src | Style sheets from this site and Google Fonts; font files from Google Fonts only. |
form-action 'none' | No form can be submitted anywhere. |
default-src 'self', object-src 'none', base-uri 'self' | Everything else (frames, media, workers) only from this site; no plug-ins; links cannot be redirected to another site by a changed base address. |
So even a mistake in the page's code, or a later change to it, could not send your data to another server without also changing this policy, which anyone can read in the page source. Its limits: it allows requests to this site itself, which the covariance files need (GitLab Pages only hands out files, and the page's requests carry only file paths); a policy set in the page cannot control where you navigate yourself; and browser extensions you have installed can read any page you open, which no page can prevent.
cov/…json files) and for the Google Fonts, and GoatCounter's count, a POST with an empty body whose few values are in its address. No request carries anything from your files: the Payload tab shows only the address's parameters.fetch, a sendBeacon and an image request to another site were all blocked, while the site's own files loaded.)su-tool.js and su-core.js for fetch.For sensitive work you can run the calculator entirely from your own computer. Download the repository (about 30 MB to download, 150 MB on disk) and serve its public folder with any local web server, for example Python's:
git clone https://gitlab.com/hardtohit10/hardtohit10.gitlab.io.git
cd hardtohit10.gitlab.io/public
python3 -m http.server 8000
Then open http://localhost:8000/su-tool.html. The covariance files now come from your own disk, and the visit counter does not count local copies (GoatCounter's script skips localhost). Only the Google Fonts requests go out, and the page works without them, with your system's fonts. Opening su-tool.html directly as a file does not work, because browsers do not let a page read other local files with fetch.
| Who | What they can see |
|---|---|
| You | Everything: your files, the results and the downloads, in your own browser. |
| The site's author, Ian H | The GoatCounter counts of visits to the page. Nothing from your files. |
| Claude (Anthropic) | Nothing. Claude wrote the page's code, but has no connection to the published page; no AI processes your files. |
| GitLab, which hosts the site | The requests for the page and for the covariance files (which nuclides, which library), with your IP address, under GitLab's privacy statement. |
| Google Fonts | The font requests. |
| GoatCounter | The visit count described above. |