Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The example explicitly records click-tracking metadata including IP address, user agent, and referrer, which are personal or potentially identifying data in many jurisdictions. Even though this is demo code, it normalizes privacy-sensitive collection without notice, consent, minimization, or retention guidance, making downstream misuse or noncompliant deployment more likely.
