Privacy
The short version: I don't do analytics, profiling, or outside sources that might subtly do tracking. Your identity is your own. The long version is below, but I would get a Red Bull or something becuase it's really not exciting.
TLDR
This site was built very carefully to avoid collecting information, because I don't need that kind of stress in my life. There is no analytics code, no ad tracker, no unique visitor counter, no reader profile, no third-party scripts, fonts, images or like people named George. Never trust a George. I have a little script that prevents me from updating the site if I break these rules. That's how serious I am about it. I intentionally annoy myself on your behalf.
Now, if you choose to subscribe to one of my email lists, that's a different story. But even then, I'm not sending those emails to you directly. Not after the great BCC Debacle of 2019. Never again. Read the email section if you want to know more.
What the site does not collect
- No audience analytics. The site code runs no analytics service and builds no visitor profile.
- No advertising or behavioural tracking, and nothing is sold or shared. Except your left kidney. Sorry, you read this line, now it's too late to go back. Use bubble wrap when shipping.
- No view counts, likes or shares. I don't need no counter to know you hate me. I can feel it.
- No site accounts. This is my site, not yours.
- No comments. Comments were a great part of the early internet before everyone got so mean. I have enough negativity in my life thanks to ::gestures to the world::, so I'm not soliciting new crankiness at this time.
- No recommendations. Nothing is watching you, aiming to upsell you on the next thing. In fact, I pride myself in never pleasing the same people twice. Wait, that sounds wrong.
Cookies and what your browser stores
This site has no tracking cookies. Thre is a consent banner, but that's kept in whats called local storage on your browser, so much so that if you open a different browser on your same machine, you will be stuck dismissing that little popup all over again. But let's get into detail, because you're not here for easy answers, you want sleep-inducing material!
- Your theme choice, is kept in
localStorage, but only if you press the day/night toggle. If you don't click the little sun/moon icon in the header, this doesn't apply. Now, full disclosure: if your name happens to be Sunny or Moon, then yeah, we might have accidentally stored some of your personal information in the browser. But, counterpoint: you have an awesome name, so it all balances out. - When you dismiss the privacy notice, we store that choice in
sessionStorage, which keeps the panel in the corner from reappearing on every page you visit for the rest of your entire life. This gets unset when you leave the site, though, so you never have to go long without dismissing notices. - What you've read, if you tick anything on the reading list in the Commons,
goes into
localStorageas a list of titles. The Commons uses it to show you each character as they were at the point you stopped reading, rather than as they are now — and it works that out on your machine, from a page you already have, because there is nowhere else for it to happen. Press Clear, or untick everything, and it's gone. Nobody but you ever knows you're four books behind.
If you go into your browser settings and clear site data, all of them go away. None of them is readable by anyone but this site, and we don't send any of it back to the server because — fun fact — this site is static HTML and has no server to send back to. I know, right? Small world. Anyway, enough of this tracking nonsense. Hey Siri, next section.
What the page loads
It made my head hurt to do it, but this site works with JavaScript turned off. There are a few scripts that add functionality if you want it, but it's really just the theme switcher, audio controls, some search tools and the privacy notice (ah! it came back!). That's like... basically nothing.
The font I use is served from this domain rather than the usual fornt CDN. Why, you ask? Because a stylesheet request to a remote server can be tracked, so Big Font can see who you are, where you came from, what you're reading, and possibly your eye colour. I'm less sure about that last one. But anyway, the point is: using CDN fonts means all my privacy work went out the window, so I serve the font myself, where it can't do any harm.
What my web host sees
This site is hosted by Cloudflare, who you may recognize from those little intersititials that ask you to confirm you're human. Like every web host, data coming in is logged for things like the page requested, the time, and the address the requst came from. They do this so they know what page to show you (I still think fully random page serving is the way of the future, but whatevs) and to prevent abuse (like if you happen to really love a certain page and try to reload it 10,000 times a second — they frown on that kinda thing). Unfortunately, these things kinda need to exist for sites to exist. But it's never used to follow readers, measure engagement or build a profile.
Feeds ask for nothing
If you want to be really safe, use the RSS feeds, because they keep you up to date with the site without needing to visit the site. Counterpoint: you'll miss out on all the fancy stylings of the site. Sigh, yeah, I know, it's not a compelling argument.
- Blog — Posts from mcm.1889.ca — writing, publishing, open culture, and asides.
- Topic Tag Tuesday — A reader suggests a topic. I write the story.
- Soundtracks — The music written alongside the writing, subscribable in any podcast app.
Email subscription privacy
Ordinary browsing never calls the email service. The form remains closed until the sender’s physical address, authenticated sending domain, restricted database roles and unsubscribe flow have all been verified. If you later choose to use it, the site asks only for an email address and separate, unchecked consent for new-episode announcements. You'll get a confirmation message first because, again, lawyers, and only after you click the second confirmation button will your soul officially belong to— wait, sorry, wrong document.
Behind the scenes fun: the email service I use (Resend) retains your addrss and the record that you agreed to subscribe. It doesn't keep a username, name, location, IP address, user agent, cookie, referrer, fingerprint, iris scan or vial of blood. Resend will process enough metadata to deliver your confirmation email, and those confirmations expire after 48 hours. I don't do open- or click-tracking, and every email includes an unsubscribe link, so you can come to your senses at any time. And incidentally, I won't use your email address for advertising, profiling, or unrelated messages. Though to be fair, all my content is fairly unrelated by default.
Who else touches an address
Oh baby. But no, seriously. Resend uses its own suppliers to run its service, and that bears some exploration. Or so my lawyers tell me. Honestly, I think they just wanted to bill the extra hour. Anyway.
As of August 2026, the suppliers for Resend number around 22 companies, all in the United States. That includes Amazon Web Services for the sending, Google, Cloudlflare (again!), Stripe, Anthropic, and a number of database, monitoring and analytics vendors. The list is published by Resend, who commit to fourteen days' notice before adding or replacing anyone on it. If in doubt, check there. I have trouble concentrating long enough to— oh hey, peanut butter! I'm hungry.
Now, if handing an address to that stack of crazies is not a trade you want to make, don't worry about it. Use the feeds and Jeff Bezos will never know. It's just as good as email, except much less likely to end up in a spam folder.
Your choices
Since the site knows nothing abut you (unless you hand it over for some weird reason) this section is short. Your rights:
- You have the right to remain silent.
- Anything you do say may be used against you—
Hold on. That's my murder list. Where's the... aha, here we go. The email rights list. You can:
- Withdraw consent at any time. Every message has a little unsubscribe link that you can use to GFTO. You don't need to explain yourself. I feel the same way.
- Ask what is held. In terms of personal information. Spoiler alert: it's your email address, the consent language you agreed to, and the day and time you agreed. But if you really want to ask, you can, and I'll confirm it. However, I would just like to point out that making me process that manually will expose it to more eyes that it would have been otherwise.
- Ask for deletion. Write to me and I will delete you. Your record, I mean, not you-you. Unless you're into that kinda thing, in which case you have the right to remain silent...
- Do nothing. In general and, as in this case, simply ignore a confirmation request, which will expire in 48 hours anyway. If you changed your mind after starting sign-up, you don't need to explicitly bail. Ghosting me is totally fine. I can take it. I'll just be over there, crying a little, that's all.
Now, if you haven't signed up for emails, you don't have any data on record, so if you write to me asking me about your personal information, I will almost certainly be stuck making something up, and then submitting the same information to Interpol, and then the whole world will know about your little llama-fighting ring, you sick bastard.
Help, I need a human!
You and me both, sister. But no, if you need to talk this out with a real person, you can email me directly at mcm@1889.ca. If something on this page turns out to be wrong, drifts out of date, or is simply stupid, please let me know. I'll love you forever.
Curious how this site is put together and how it relates to privacy? Me neither, but if you want to torture someone, send them to the colophon, which is just a fancy word for sticking a long camera up your—