See T132103 for the more immediate issue, but even the fact that it uses WordPress.com directly (it's not proxied by us, the policy.wikimedia.org sub domain points to their servers) is somewhat unfortunate. While this isn't our actual privacy policy (those are on https://wikimediafoundation.org) it is about our policies in general and often linked from social media.
Perhaps we can convert it to a static html site (it's pretty simple) like https://transparency.wikimedia.org/, https://15.wikipedia.org/ and https://annual.wikimedia.org/2014/.
Or perhaps we can proxy it (and then make sure all requests are routed through our domain, and analytics disabled).
See also:
- T70982: Remove X-Hacker HTTP header served on sites hosted by WordPress VIP (Automattic) (applies to policy.wikimedia.org as well)