Pre-launch privacy note
Collect less. Explain what remains.
This describes what the code actually does today: one preference stored in your browser, two optional forms, and analytics that stay off until you switch them on.
It is an accurate description of what the current code does, written so the gaps stay visible. It has not been read by a privacy lawyer. It does not state a lawful basis, a list of jurisdictions, or a formal rights-request process, because none of those has been settled. Those have to be finished with qualified privacy counsel before this site collects data in production, and a longer page should not be mistaken for a compliant one.
What this site stores in your browser
One key, written only after you answer the privacy prompt. There is no advertising storage, no fingerprinting, no cross-site identifier, and no account system.
| Stored item | What it is and why it exists | How long it lasts |
|---|---|---|
uc_consent_v1 | A first-party value in your browser’s local storage—not a cookie. It holds one of two words recording whether you allowed optional analytics, so the prompt does not reappear on every page. Because it is local storage rather than a cookie, it is never attached to a request to this site or to anyone else. | Until you clear it. No expiry is set. Clearing site data for this domain removes it, and the prompt returns on your next visit. |
Cookies set by the host
The site’s own code sets no cookies at all. Cloudflare, which serves these pages, documents a strictly necessary __cf_bm cookie placed only on sites using its bot-management features, and a cf_clearance cookie set when a visitor completes a security challenge. Whether either applies here depends on settings in the hosting dashboard rather than on anything in this site’s code, so this note describes them rather than claiming they are absent. Confirm the zone’s bot-protection settings and state the result here before launch
Analytics, and the choice that controls it
Analytics is optional and starts off. The site loads Google Tag Manager only when a container ID has been configured for the deployment. Where none is configured, no request is made to Google at all and the privacy prompt does not appear, because there is nothing to consent to.
Where a container is configured, the site declares Google’s consent signals before any tag is able to fire. Analytics storage starts denied and becomes granted only if you choose “Allow analytics.” The three advertising signals—advertising storage, advertising user data, and ad personalization—are set to denied, and the interface offers no control that turns them on. Functionality and security storage are granted, which is what allows your choice to be remembered at all.
What measurement can and cannot see
The site’s own event code reports page-level interaction: which interface control was clicked and its visible label, the hostname of an outbound link, and how far down a page you scrolled. It does not put names, email addresses, or the text of a question into the analytics data layer.
Two caveats worth stating rather than burying. First, requesting the tag container from Google reveals your IP address to Google, as a request to any server reveals it to that server; Google states that data in standard HTTP request logs is deleted within 14 days. Second, the chooser keeps your answers in the page address so a result can be reloaded or shared. Those answers are rope-selection categories rather than personal details, but an analytics tag configured to record full page addresses would record them.
Which tags actually run inside the container is decided in Google Tag Manager, not in this site’s code, so this page cannot yet tell you what each one retains. List the configured tags, their vendors, and their retention here before launch
The two forms, and exactly what each one sends
Both forms are optional, both require an explicit consent checkbox, and neither is connected to the other—asking a question does not subscribe you. There is no database behind this site. A submission is passed straight to Resend and is not written to any storage under this site’s control.
| Form | What it sends | Where it goes and what happens |
|---|---|---|
| Field Notes signup | Your email address, which is required. A first name, which is optional. Your consent checkbox. One hidden field that a person never fills in. | Posted to a function on this domain, which passes it to Resend. Your address is added as a contact in a Resend audience segment and one welcome message is sent. Every later message carries an unsubscribe link. |
| Reader question and correction form | Your name, your email address, a topic chosen from four fixed options, and your question of between 10 and 3,000 characters. Your consent checkbox. One hidden field that a person never fills in. | Posted to a function on this domain, which passes it to Resend. The fields are composed into a single email to one fixed editorial inbox, with your address set as the reply-to so a reply reaches you. You are not added to any mailing list. |
Both endpoints accept requests only from this site’s own origin and reject anything larger than a small JSON body. Neither endpoint returns information about anyone else, and neither reads any of the storage described above.
The hidden field in each form
Each form contains one field that is hidden from view and skipped by keyboard navigation. A person never fills it in; automated spam usually does. If a submission arrives with anything in that field, it is discarded and nothing is sent onward. The field collects nothing about you, and it is the only concealed element in either form.
Who else receives this data
| Company | What it does and what it receives | Its published terms |
|---|---|---|
| Cloudflare, Inc. | Hosts the site, serves every page, and runs the two form endpoints. Your IP address and standard request metadata for every page and file you load, processed to deliver and protect the site. Cloudflare documents that HTTP request logs are not retained by default. | Privacy policy (opens in a new tab) · Data processing addendum (opens in a new tab) · Subprocessors (opens in a new tab) |
| Resend, operated by Plus Five Five, Inc. | Delivers email and holds the Field Notes subscriber list. Only what you type into one of the two forms, plus the message sent on our behalf. Resend’s own documentation states that email data is retained for 30 days on all plans, with flexible retention on enterprise plans. | Privacy policy (opens in a new tab) · Data processing addendum (opens in a new tab) · Subprocessors (opens in a new tab) |
| Delivers the Google Tag Manager container, and only when one has been configured for the deployment. Your IP address and the request for the container file, as any server receives for any request it answers. Google states that data in standard HTTP request logs is deleted within 14 days. | Privacy policy (opens in a new tab) · How Google uses information from partner sites (opens in a new tab) · Tag Manager data practices (opens in a new tab) |
Those links point at each company’s own published terms. Listing them is a statement about what those companies publish, not a claim that data processing terms have been executed for this site or that a vendor review has been completed. Neither has happened. Complete and record a data-protection review for each processor before launch
Your choices
- Change or withdraw the analytics choice. Use the “Privacy choices” button in the site footer. It reopens the same prompt wherever analytics is configured, and your new answer replaces the old one.
- Remove the stored preference entirely. Clear site data for this domain in your browser. Nothing is left behind on our side to restore it.
- Leave the mailing list. Every Field Notes message carries an unsubscribe link.
- Ask what is held about you, or ask for it to be deleted. Use the reader desk. It reaches the same fixed editorial inbox as everything else.
Requests are handled by hand, by the person described on the accountability register. Define and publish a rights-request process, response window, and identity check with counsel before launch
What is still missing before launch
Listing these is more useful than a page that reads as finished. None of the following is settled:
- Legal review. Nothing on this page has been read by a privacy lawyer.
- The jurisdictions this site treats itself as subject to, and the lawful basis for each processing purpose.
- Retention periods for the editorial inbox and the subscriber list, beyond what each processor documents for itself.
- Executed data processing terms with each processor, and a recorded review of each one.
- A published rights-request process, a response window, and an identity check.
- The specific tags configured inside the Google Tag Manager container, and what each retains.
- A position on children’s data and whether an age statement is needed for this audience.
- A breach-notification path.
Until those are settled, read this page as a description of the code rather than as a legal instrument. If something here does not match what the site actually does, that is a defect worth reporting—use the reader desk and it will be corrected the same way any other error is.
Related
Who is accountable for this site names the roles behind these decisions and marks the ones still unfilled. The safety and sourcing standard covers the separate question of how claims are scoped, dated, and bounded.