Privacy
Static files, a log that expires in two weeks, and one inbox.
When a page opens
Each page is a file prepared ahead of time and handed over unchanged by the web server, nginx. Everything the page needs comes from this domain, and your browser is never sent to fetch anything from a third party. Nothing is stored on your device: no cookies, no local storage. There is no analytics package, advertising code, social button, embedded video or tracking pixel, and the site has no accounts, comments or forms to fill in.
The access log
For each request, nginx writes down the IP address it came from, the time, which page was requested, the response code and size, the page that linked to it if your browser reports one, and the user-agent string your browser sends. Failed requests can also show up in an error log. Both files start fresh every day, and each day’s file is deleted after 14 days. They are opened only to keep the server healthy or to deal with abuse, and they are never joined up with other information, sold or given to anyone.
Email sent to the inbox listed under Contact is used to reply to you. The address and the message stay out of any list and are not passed along. Ask, and the whole thread is deleted.
What you can ask for
Readers covered by data protection laws, whether the GDPR in Europe or a state law such as California’s, may ask what is held about them and have it erased. Given how the site works, that comes down to an email thread and, at most, two weeks of log lines. Write to the same address to ask.