Pre-launch privacy note

Collect less. Explain what remains.

This describes what the code actually does today: one preference stored in your browser, two optional forms, and analytics that stay off until you switch them on.

This is not a finished privacy policy.

It is an accurate description of what the current code does, written so the gaps stay visible. It has not been read by a privacy lawyer. It does not state a lawful basis, a list of jurisdictions, or a formal rights-request process, because none of those has been settled. Those have to be finished with qualified privacy counsel before this site collects data in production, and a longer page should not be mistaken for a compliant one.

What this site stores in your browser

One key, written only after you answer the privacy prompt. There is no advertising storage, no fingerprinting, no cross-site identifier, and no account system.

First-party storage inventory
Stored itemWhat it is and why it existsHow long it lasts
uc_consent_v1A first-party value in your browser’s local storage—not a cookie. It holds one of two words recording whether you allowed optional analytics, so the prompt does not reappear on every page. Because it is local storage rather than a cookie, it is never attached to a request to this site or to anyone else.Until you clear it. No expiry is set. Clearing site data for this domain removes it, and the prompt returns on your next visit.

Cookies set by the host

The site’s own code sets no cookies at all. Cloudflare, which serves these pages, documents a strictly necessary __cf_bm cookie placed only on sites using its bot-management features, and a cf_clearance cookie set when a visitor completes a security challenge. Whether either applies here depends on settings in the hosting dashboard rather than on anything in this site’s code, so this note describes them rather than claiming they are absent. Confirm the zone’s bot-protection settings and state the result here before launch

Analytics, and the choice that controls it

Analytics is optional and starts off. The site loads Google Tag Manager only when a container ID has been configured for the deployment. Where none is configured, no request is made to Google at all and the privacy prompt does not appear, because there is nothing to consent to.

Where a container is configured, the site declares Google’s consent signals before any tag is able to fire. Analytics storage starts denied and becomes granted only if you choose “Allow analytics.” The three advertising signals—advertising storage, advertising user data, and ad personalization—are set to denied, and the interface offers no control that turns them on. Functionality and security storage are granted, which is what allows your choice to be remembered at all.

What measurement can and cannot see

The site’s own event code reports page-level interaction: which interface control was clicked and its visible label, the hostname of an outbound link, and how far down a page you scrolled. It does not put names, email addresses, or the text of a question into the analytics data layer.

Two caveats worth stating rather than burying. First, requesting the tag container from Google reveals your IP address to Google, as a request to any server reveals it to that server; Google states that data in standard HTTP request logs is deleted within 14 days. Second, the chooser keeps your answers in the page address so a result can be reloaded or shared. Those answers are rope-selection categories rather than personal details, but an analytics tag configured to record full page addresses would record them.

Which tags actually run inside the container is decided in Google Tag Manager, not in this site’s code, so this page cannot yet tell you what each one retains. List the configured tags, their vendors, and their retention here before launch

The two forms, and exactly what each one sends

Both forms are optional, both require an explicit consent checkbox, and neither is connected to the other—asking a question does not subscribe you. There is no database behind this site. A submission is passed straight to Resend and is not written to any storage under this site’s control.

Form submissions and their destinations
FormWhat it sendsWhere it goes and what happens
Field Notes signupYour email address, which is required. A first name, which is optional. Your consent checkbox. One hidden field that a person never fills in.Posted to a function on this domain, which passes it to Resend. Your address is added as a contact in a Resend audience segment and one welcome message is sent. Every later message carries an unsubscribe link.
Reader question and correction formYour name, your email address, a topic chosen from four fixed options, and your question of between 10 and 3,000 characters. Your consent checkbox. One hidden field that a person never fills in.Posted to a function on this domain, which passes it to Resend. The fields are composed into a single email to one fixed editorial inbox, with your address set as the reply-to so a reply reaches you. You are not added to any mailing list.

Both endpoints accept requests only from this site’s own origin and reject anything larger than a small JSON body. Neither endpoint returns information about anyone else, and neither reads any of the storage described above.

The hidden field in each form

Each form contains one field that is hidden from view and skipped by keyboard navigation. A person never fills it in; automated spam usually does. If a submission arrives with anything in that field, it is discarded and nothing is sent onward. The field collects nothing about you, and it is the only concealed element in either form.

Who else receives this data

Third-party processors
CompanyWhat it does and what it receivesIts published terms
Cloudflare, Inc.Hosts the site, serves every page, and runs the two form endpoints. Your IP address and standard request metadata for every page and file you load, processed to deliver and protect the site. Cloudflare documents that HTTP request logs are not retained by default.
Resend, operated by Plus Five Five, Inc.Delivers email and holds the Field Notes subscriber list. Only what you type into one of the two forms, plus the message sent on our behalf. Resend’s own documentation states that email data is retained for 30 days on all plans, with flexible retention on enterprise plans.
GoogleDelivers the Google Tag Manager container, and only when one has been configured for the deployment. Your IP address and the request for the container file, as any server receives for any request it answers. Google states that data in standard HTTP request logs is deleted within 14 days.

Those links point at each company’s own published terms. Listing them is a statement about what those companies publish, not a claim that data processing terms have been executed for this site or that a vendor review has been completed. Neither has happened. Complete and record a data-protection review for each processor before launch

Your choices

  • Change or withdraw the analytics choice. Use the “Privacy choices” button in the site footer. It reopens the same prompt wherever analytics is configured, and your new answer replaces the old one.
  • Remove the stored preference entirely. Clear site data for this domain in your browser. Nothing is left behind on our side to restore it.
  • Leave the mailing list. Every Field Notes message carries an unsubscribe link.
  • Ask what is held about you, or ask for it to be deleted. Use the reader desk. It reaches the same fixed editorial inbox as everything else.

Requests are handled by hand, by the person described on the accountability register. Define and publish a rights-request process, response window, and identity check with counsel before launch

What is still missing before launch

Listing these is more useful than a page that reads as finished. None of the following is settled:

  • Legal review. Nothing on this page has been read by a privacy lawyer.
  • The jurisdictions this site treats itself as subject to, and the lawful basis for each processing purpose.
  • Retention periods for the editorial inbox and the subscriber list, beyond what each processor documents for itself.
  • Executed data processing terms with each processor, and a recorded review of each one.
  • A published rights-request process, a response window, and an identity check.
  • The specific tags configured inside the Google Tag Manager container, and what each retains.
  • A position on children’s data and whether an age statement is needed for this audience.
  • A breach-notification path.

Until those are settled, read this page as a description of the code rather than as a legal instrument. If something here does not match what the site actually does, that is a defect worth reporting—use the reader desk and it will be corrected the same way any other error is.

Related

Who is accountable for this site names the roles behind these decisions and marks the ones still unfilled. The safety and sourcing standard covers the separate question of how claims are scoped, dated, and bounded.