Privacy
Referrer-Policy
Don't leak URLs to third parties.
What it is
Controls how much of the current URL is sent in the Referer header when the user navigates or loads a resource.
Why it matters
URLs often contain tokens, IDs or private paths you don't want leaking to analytics, ads or external links.
Risk without it
A permissive policy (or the browser default) can send full URLs — including query strings — to any third party you link to or load resources from.
Recommended
strict-origin-when-cross-origin (a good default) or no-referrer (maximum privacy).
Set it
add_header Referrer-Policy "strict-origin-when-cross-origin" always;