§ privacy

Privacy note

This site is designed to measure aggregate product clarity — which routes and sections are useful — without profiling individual visitors. This note describes a privacy-preserving design. It is not a claim of legal compliance; jurisdiction-specific legal review is still required.

What may be collected

  • Event name (for example page_view or section_view)
  • Server-generated timestamp
  • Normalized route pathname
  • Allowlisted section identifier or content slug where applicable
  • Coarse device class: mobile, tablet, or desktop
  • Optional referrer origin (not the full URL)
  • Optional sanitized UTM campaign fields

What is not collected

  • Raw or hashed IP addresses
  • Email addresses, names, or contact messages
  • Raw user-agent strings
  • Exact screen dimensions or precise location
  • Fingerprints, persistent visitor IDs, or session IDs
  • Analytics cookies
  • Full referrer URLs or sensitive query strings
  • Mouse paths, keystrokes, form values, or session replay
  • Cross-site advertising or remarketing signals

Why

Aggregate measures help improve information architecture and reading clarity. They are not used to identify people, build visitor timelines, or support advertising.

Storage and retention

When analytics is enabled and you opt in, events are stored in a first-party PostgreSQL database controlled with the site deployment. Raw events are retained for 30 days. Daily aggregates are retained for 12 months. There is no visitor-level reporting.

Analytics is off by default. Collection starts only after an explicit Accept action. Decline and continued browsing without acceptance do not enable collection. A preference of granted or denied may be stored in localStorage solely for interface memory. It is not an analytics identifier and is never sent as event data.

You can reopen privacy settings from the footer at any time and withdraw consent. After withdrawal, new events stop immediately and the stored preference is updated.

Third parties

This analytics system does not load Google Analytics, Plausible Cloud, PostHog Cloud, Clarity, Hotjar, Meta Pixel, or similar third-party tracking scripts. Contact delivery uses Resend for form messages and is separate from analytics.

Hosting platform access logs may still contain network metadata outside this application database. Configure host retention separately.

Requests

For privacy questions or deletion requests related to this site, use the contact page or email the address listed there. Because no persistent visitor ID is stored in analytics, deletion is handled at the aggregate/raw-event retention layer rather than as an individual profile erasure.