Privacy

What the desk collects, and what the desk does not.

A plain-language summary of the desk's privacy practice. No tracking pixels, no third-party analytics, no remarketing.

A mobile device and wallet resting on a wooden surface, photographed from a low angle with calm overhead light.
What the desk collects is limited to what the site needs to work.

What the desk collects

The site does not run analytics, advertising pixels or remarketing tags.

The site serves a single stylesheet, a single script and the Google Fonts CSS. The Google Fonts CSS is fetched from fonts.googleapis.com and fonts.gstatic.com. The site does not set any cookies. The site does not run a fingerprinting script.

The Cloudflare edge may set a cf_clearance cookie for bot protection; that cookie is set by the Cloudflare network, not by the site, and is documented in the Cloudflare privacy notice.

What the desk does not collect

The desk does not collect IP addresses beyond the standard server log. The desk does not collect names, emails or any other identifier. The desk does not run any form on any page.

Server logs and the Cloudflare edge

What the standard web server records, and what the edge records separately.

Like every public web server, this site's hosting stack records a standard access log: the requested path, a status code, a byte count, a timestamp, and (in most cases) the IP address that made the request. The log is retained for a defined period, then rotated out. The desk does not read individual log entries, and the desk does not sell, rent or share the log with any third party.

Cloudflare sits in front of the site as a reverse proxy. Cloudflare records its own access log, and Cloudflare's privacy notice applies to that log. Cloudflare may set the cf_clearance cookie described below; Cloudflare does not share that cookie with the desk, and the desk does not read its value.

The cf_clearance cookie, explained

When a visitor passes a Cloudflare bot-management challenge (the "Checking your browser…" interstitial that some readers see), Cloudflare sets a cookie called cf_clearance. The cookie carries a signed token that tells the Cloudflare edge the visitor is human for a defined window, commonly 30 minutes to 24 hours. The cookie is set by the Cloudflare network on the visitor's browser; the desk neither sets it nor reads it.

How long the server logs are kept

The standard access log is rotated and compressed on a rolling window. The desk has no business reason to retain individual entries beyond that window. Where a regulator requires a longer retention, the desk will publish the retention rule on this page.

What the desk does not collect

The short list of things the desk has chosen not to run.

The desk does not run cookies on this site beyond the cf_clearance cookie set by Cloudflare. The desk does not run a fingerprinting script, a canvas hash, an audio-context probe, or any other browser-fingerprint technique. The desk does not run Google Analytics, Matomo, Plausible, Fathom, Mixpanel, Amplitude, or any other product analytics tool.

The desk does not run Meta Pixel, Google Ads conversion tracking, Twitter Pixel, LinkedIn Insight, TikTok Pixel, or any other advertising or remarketing pixel. The desk does not run a session-replay tool such as Hotjar, FullStory, LogRocket or Microsoft Clarity. The desk does not run an A/B testing framework on the public site.

What this means in practice

A reader who opens this site in a fresh private window will see no first-party cookie set by the site itself, no third-party tracking pixel firing on any page, and no analytics call being made. The reader's request reaches Cloudflare, and (if the reader follows an outbound affiliate link) the reader's click reaches the operator. The desk's view of the site is the published HTML; the desk does not see the reader's behaviour.

Where this rule has limits

The affiliate link is a 302 redirect to a third-party operator. Once the reader follows the link, the operator's own privacy notice governs what the operator collects. The desk cannot speak for the operator, and the desk does not have visibility into the operator's telemetry. The operator's current page is the only honest source for that information.

Google Fonts and the third-party data flow

The one third-party fetch the site still makes.

This site loads its typography from Google Fonts. The CSS file at fonts.googleapis.com is fetched on first visit; the actual font files are fetched from fonts.gstatic.com. Google records a request against the visitor's IP address for both fetches, and Google's privacy notice applies to those requests.

The desk chose Google Fonts for editorial reasons: the font is readable at small sizes, it loads predictably across devices, and the licensing is clear. The desk weighed that against the privacy cost of a third-party fetch and decided to keep the fetch. A reader who prefers not to make that fetch can block fonts.googleapis.com or fonts.gstatic.com at the network level; the site will fall back to a system font.

What changes if Google Fonts is blocked

If the reader blocks the Google Fonts fetch, the site falls back to a system sans-serif font (Inter if installed locally; otherwise the browser default). Headings and body copy remain legible; line metrics shift slightly. No page breaks, no missing content.

Self-hosting fonts

The desk has considered self-hosting the Inter font as a long-term privacy improvement. Self-hosting would remove the third-party fetch on every page view. The desk has not yet self-hosted because the current fetch is small, the cache hit rate is high, and the privacy cost is limited. The desk will revisit the decision if the third-party fetch changes materially.

Retention policy and reader rights

How long the desk keeps what it has, and what a reader can ask for.

The desk's retention policy is short. The desk does not hold a contact-form submission after the editorial reply is sent; the desk does not hold an email thread after the issue is closed; the desk does not hold a comment after the comment is moderated. The standard server log is rotated on a rolling window described above.

Right of access

A reader who has written to the desk may ask what the desk holds about that reader's correspondence. The desk will reply within 30 days with the relevant emails, contact-form submissions, and any internal notes tagged to the reader. The desk will not withhold a record on editorial grounds; the only basis for withholding is a documented legal hold.

Right of deletion

A reader may ask the desk to delete the reader's correspondence. The desk will delete the correspondence within 30 days, except where a documented legal hold applies. Deletion of the standard server log follows the rolling rotation; the desk cannot delete a single log entry on demand.

How to exercise a right

Write to the desk at the address listed on the contact page. The desk will reply from the editorial address within five working days to confirm the request and to ask for any identification the desk needs to verify the request is from the same person. The desk does not require a notarised request or a formal letter; a plain email is enough.

Complaints and escalation

A reader who is not satisfied with the desk's reply may escalate to the relevant data-protection authority in the reader's jurisdiction. The desk will cooperate with any reasonable request for information from that authority.

The affiliate link

The only third-party track on the site.

The affiliate link is a 302 redirect to the operator. The operator may set its own cookies and may run its own analytics. The desk has no visibility into what the operator collects after the redirect. The operator's privacy notice is the only honest source for that information.

The desk chose the redirect specifically so that the affiliate link is the only third-party track on the site. The site itself runs no analytics, no advertising, and no remarketing.

Cookies set by the desk, in plain words

A line-by-line read of what is set on a fresh visit.

On a fresh visit to any page on this site, the only cookie set is the Cloudflare cf_clearance cookie, and only when the visitor crosses a bot-management threshold. The cookie is set by the Cloudflare edge, not by the site's HTML or JavaScript. The cookie carries a signed token; the cookie does not carry the visitor's name, email, or any other identifier the visitor has provided.

What about local storage and session storage?

The site does not write to window.localStorage or window.sessionStorage. The site does not write to IndexedDB. The mobile-drawer open / closed state is held in an in-memory attribute on the drawer element; that state is lost when the page reloads. The mobile CTA bar is rendered statically in the document; no client-side state is persisted.

What about the affiliate redirect?

The affiliate link is a 302 redirect to a third-party operator. The redirect itself does not set a cookie on this site; the request is forwarded to the operator's domain, and any cookies set from that point onward are governed by the operator's privacy notice. The desk has no read access to those cookies and does not write to them.

Browser settings that respect this policy

A reader who disables third-party cookies at the browser level will still see the cf_clearance cookie if Cloudflare decides to set one; the cookie is set by the first-party context (Cloudflare's edge, served from this site's domain). A reader who disables all cookies entirely may see the Cloudflare bot-management interstitial more often, because Cloudflare uses the cookie to remember that the visitor has passed the challenge.

PLAY NOW