Privacy policy
Last updated
Short version: this site sets no cookies, runs no advertising, and doesn’t try to identify you. The long version follows, and it’s genuinely short, because there isn’t much to tell.
1. Who we are
This site is published by Tiny Bytes, based in Canada. We’re the data controller for it.
Questions, requests or complaints: [email protected].
2. What we collect when you read a post
Two things, neither of which identifies you.
Analytics. We use Cloudflare Web Analytics to see which posts people read. It’s a privacy-first product and it is the reason this site has no cookie banner:
- It sets no cookies and uses no local storage or other client-side state.
- It does not fingerprint you — not by IP address, not by user-agent string, not by anything else — and cannot track you across other sites.
- It records: page views and visits, which pages are popular, referring site, country, browser and device type, and page-performance measurements (Core Web Vitals).
- It does not log URL query strings.
- No individual profile is built, and there is nothing in it we could tie back to you if we wanted to.
Server and security logs. Cloudflare hosts and serves this site, and like any web host it processes requests — including your IP address — to deliver pages and to block attacks and abuse. That’s a necessary part of running a website and we don’t use those logs for analytics or marketing. Cloudflare’s handling is covered by its own privacy policy.
What we don’t do: no advertising networks, no tracking pixels, no social media trackers, no session recording, no heatmaps, no A/B testing tools, no data brokers, and nothing sold or rented to anyone, ever.
3. Cookies
This site sets no cookies of its own. No consent banner, because there’s nothing to consent to.
Two caveats worth being straight about:
- Links to other sites. If you follow a link from here to another site — a retailer, a vendor, a research paper — that site does whatever it does under its own policy. That includes affiliate links where they exist; see the disclosure page.
- Embedded content. Where we embed something from another service (a video, for instance), that service may set cookies once you interact with it. We keep embeds to a minimum and prefer a plain link.
4. Legal basis for processing
We’re based in Canada, so Canadian federal privacy law — PIPEDA — is the law that governs this site. PIPEDA is built around consent, and the honest position here is that there is very little to consent to: the analytics set no cookies, build no profile and don’t identify you, and there are no accounts, so we hold nothing we could connect to you. We’ve kept it that way deliberately rather than asking you to agree to a list of things.
For readers in the UK, EU and EEA, where GDPR may reach a site like this one: we process the analytics data above on the basis of legitimate interests — understanding which articles are read so we can write better ones. Because the analytics are cookieless and non-identifying, this involves no meaningful intrusion on you. Server and security logs are processed on legitimate interests too: keeping the site up and defending it.
We don’t ask you to agree to anything, because we don’t do anything that needs it.
5. How long we keep things
Analytics data is retained by Cloudflare according to its own retention schedule — unsampled for a short window, then aggregated for longer-term reporting. We keep no separate copy. Server and security logs are retained by Cloudflare on its standard schedule and we don’t export them.
6. Who we share it with
Only our hosting and analytics provider, Cloudflare, which acts as our processor. Nobody else. No advertisers, no brokers, no partners.
Cloudflare operates globally, so data may be processed outside your country. Cloudflare maintains the standard safeguards for international transfers, including Standard Contractual Clauses.
7. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, object to processing, or ask for it in a portable form. In Canada, PIPEDA gives you a right of access to your personal information and a right to have it corrected. In the UK, EU and EEA these are UK GDPR / GDPR rights; in California, CCPA/CPRA gives you comparable ones, including the right not to be discriminated against for exercising them.
We have never sold or shared personal information for cross-context behavioural advertising, and never will.
One honest limitation: because the analytics are non-identifying and we hold no accounts, we almost certainly hold no personal data about you that we could locate even if you asked. There’s no user record to produce. If you contact us at [email protected] we’ll tell you exactly that, and help with anything we do hold. We’ll respond within 30 days.
If you think we’ve got this wrong, you can take it to a regulator: in Canada, the Office of the Privacy Commissioner of Canada; in the UK, the Information Commissioner’s Office; in the EU or EEA, your national data protection authority.
8. Children
This site is written for adults working with technology. It isn’t aimed at children and we don’t knowingly collect anything from anyone under 16. We have no mechanism that could — there’s no signup, no comments, no accounts.
9. Automated decision-making
None. We don’t profile you and we make no automated decisions about you. (The site’s articles are AI-drafted — that’s a different thing entirely, and it’s explained on How we write.)
10. Changes to this policy
If this policy changes materially — a new analytics tool, a newsletter, anything that collects more than today — we’ll update the date at the top and note what changed at the bottom. We won’t quietly broaden it.