Information we collect
We collect three categories of information. Each is opt-in where it can be, and minimal where it can't.
1.1 Newsletter subscriptions
If you subscribe to the weekly newsletter, we collect your email address. That's it. We don't ask for your name, company, or job title.
1.2 Reading analytics
We collect anonymized page-view events: which article you read, when, your country (derived from IP), and the page you came from. We do not collect your full IP address, full user agent string, or any persistent cross-site identifier.
1.3 Accounts (administrators only)
If you are an editor or reviewer on the publication, you have an account. We store your email address, a hashed password, your display name, and your role. Passwords are hashed with Argon2 and never stored in plain text.
How we use your data
We use the data we collect only to run the publication:
- Send you the newsletter (if you subscribed)
- Understand which articles are useful and which aren't
- Maintain the site, fix bugs, prevent abuse
- Respond to your requests when you email us
We do not sell, rent, or share your data with third parties for advertising or marketing purposes. Ever.
Third-party services
We use a small number of third-party services to operate the publication. Each is chosen for being privacy-respecting and offering data deletion on request.
| Service | Purpose | What they receive |
|---|---|---|
| Resend | Transactional email | Your email (for the newsletter only) |
| Plausible | Privacy-friendly analytics | Anonymized, aggregated page-view events |
| OpenAI / Anthropic / Google | LLM providers for article research | Aggregated search results and research prompts |
Each provider has their own privacy policy. We do not share subscriber lists with any of them beyond the minimum needed to send the newsletter.
Data retention
- Newsletter subscriptions: until you unsubscribe.
- Analytics events: aggregated and anonymized after 90 days; raw events are deleted after one year.
- Editor accounts: until you request deletion.
- Published articles: indefinitely — they are the publication itself.
Your rights
You can:
- Access the data we hold about you — email us
- Delete your subscription or account — email us, or click "unsubscribe" in any newsletter
- Export your data in a portable format — email us
- Object to processing — email us
We respond to all requests within 30 days, usually faster.
Security
We take reasonable precautions to protect your data:
- Passwords hashed with Argon2
- HTTPS everywhere
- Database access restricted to the application
- Quarterly dependency audits
- Sandboxed experiment execution (no code from articles runs against your data)
If you discover a security issue, please email [email protected] rather than opening a public issue. We respond within 24 hours.
Children
This publication is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has subscribed, email us and we will remove the record within seven days.
Changes to this policy
We may update this policy from time to time. When we do, we'll update the "Last updated" date at the top. Material changes will be announced in the newsletter.
Previous versions are kept in our changelog.
Contact
Questions, requests, complaints: [email protected]
Security disclosures: [email protected]
Postal mail: available on request (we don't publish a P.O. box to avoid unsolicited physical mail).
This policy is written in plain English on purpose. If something is unclear, that's a bug — please email us and we'll fix it.