In short

The honest summary

I run this site myself, on a single server, for my own writing. There is no advertising network, no third-party analytics product, no tracking pixel and no content delivery network. Fonts are served from this domain rather than Google's. Nobody is buying anything about you from me, because there is nothing to sell and no one to sell it to.

Three things cause data to be stored: sending me a message, signing up to read a gated series, and simply loading a page. Each is described below.

What's stored

And for how long

WhatWhyHow long
Your name, email address and message, if you use the contact form So I can read it and reply Until I delete it — there's no automatic clear-out yet. Ask and I'll remove it.
Your email address, if you sign up to read a gated series To send you a sign-in link and recognise you when you come back Until you delete your account. Signups that never confirm the address are deleted automatically after 30 days.
When you agreed, and the exact wording you agreed to So I can answer "what did this person actually consent to?" later As long as the account exists
Which series you've unlocked To decide what you're allowed to read As long as the account exists
Page address, response code, referring page, browser user-agent, response time, and a shortened form of your IP address, on every request To see which writing gets read, and to notice when the site is broken or slow 90 days, then deleted automatically

Your full IP address is never written down. It's truncated to its network prefix before the row is saved — the last part is discarded and cannot be recovered — which is enough to tell roughly where traffic comes from and not enough to point at you.

Signing in is passwordless, so there is no password here to store or to leak. Sign-in links work once and expire after thirty minutes.

Cookies are limited to the two Django needs to work — one keeping you signed in, one protecting forms against cross-site submission. Your light/dark preference is kept in your own browser's local storage and is never sent to the server. None of these are used for tracking, so there is no cookie banner to dismiss.

Who else sees it

Two companies, no others

Linode hosts the server this site runs on, so the data above physically lives on their infrastructure, in their London datacentre.

Resend delivers the sign-in emails, which means they handle your email address and the contents of that email in order to send it. Their sending region for this domain is Ireland.

Both are inside the UK and EU, so nothing here is transferred overseas to be stored or processed. That is the complete list — nothing is shared with anyone else, and nothing is sold.

Your choices

All of them self-serve

If you've signed up to read a gated series, your details page shows what's unlocked for you and lets you act without asking me: turn new-post emails on or off, and delete your account outright. Deleting removes your email address, your sign-in history and everything you'd unlocked, and cannot be undone — though nothing stops you signing up again afterwards.

Opting out of new-post emails never affects your sign-in links or what you can read. They are deliberately separate decisions, and agreeing to one has never implied the other.

For anything the page above doesn't cover — a copy of what I hold, or deleting a message you sent through the contact form — get in touch and I'll sort it out. It's me reading it, not a support queue.

Changes

If this page changes

If what I store meaningfully changes, this page changes with it. The wording readers agree to when signing up is versioned separately, so the record of what any given person agreed to stays accurate even after the words here move on.