Skip to content

How we handle your data.

1 · What sovereign means here

On this site, sovereign describes you, not our servers. It is our fourth principle turned on ourselves: any system, at any time, must preserve your right to keep control of your own data.

Here that comes to three things. We hold nothing that identifies you unless you send it: no cookies, no browser storage, and visits counted as daily totals. To send a form you tick a consent sentence first; without the tick, it cannot be sent. And you can take it back: email our contact address with the subject “Withdraw consent” and we delete your record within 30 days.

It does not mean your data stays on our own machines, or in your country. Your request passes through a small service we run on Amazon Web Services in Oregon and is kept in HubSpot, a US company that processes it for us. GitHub serves the pages, Google the typefaces, and cdnjs one library on the home page. Nor is it a certification.

If a sentence isn't true on the page, it isn't true in the system either. So check it.

2 · What the contact forms collect

When you send one of our three request forms (a 30-minute call, an introductory call, or a memo request), we receive only what you type:

The submission also carries the address and title of the form page you sent it from, so we know which request you made. The page adds no IP address, no device fingerprint, and no identifier of any kind. Optional fields left blank are not sent at all.

3 · Where it goes

When you press send, your browser sends the form to a small service we run ourselves on Amazon Web Services in Oregon, US. It does one job: it checks that the request is not automated spam and passes it to HubSpot, the customer relationship system we use to keep track of conversations. Our service keeps none of what you typed, and it does not log your IP address or your browser details. It keeps two small things: a log line saying that a request arrived, when, and whether it went through; and, for up to two days, a marker that the spam check behind your request was used, so that it cannot be used twice. Neither says anything about you. HubSpot processes the data on our behalf and hosts it in the United States.

The spam check is automatic. Your browser does a short calculation, usually a second or less, and our service verifies the result. There is no puzzle to solve, no cookie, and no outside company involved in it.

We use what you send for one purpose: to reply to your request and follow up on the conversation you started. We do not sell it, rent it, share it with anyone else, or add you to a marketing list. If you would like it corrected, email our contact address and we will do so and confirm. To have it deleted, see how to withdraw consent below.

If a submission cannot be delivered, the page offers a pre-filled email containing the same answers instead — nothing is silently lost, and nothing is stored anywhere else.

5 · Cookies

None. This site sets no cookies and uses no browser storage to identify you. We do not load HubSpot's tracking script or any other HubSpot code in your browser, and we use no third-party analytics. That is why there is no cookie banner: there are no cookies to agree to.

6 · Telemetry

To know roughly how many people read each page, the site sends a tiny beacon to a service in our own AWS account (Oregon, US). The beacon contains the page path, the host name of the site that referred you (not the full address), a coarse device size (mobile, tablet, or desktop), and, if you open a request form, the event names contact_start and contact_submit. The page adds nothing else. Like every web request, the beacon also arrives with your IP address and your browser's identification string; the next paragraph says what happens to them.

On our service, your IP address is truncated (the last part is discarded), combined with your browser's identification string and a random salt that changes every day, and turned into a one-way hash. That hash is kept for at most two days, next to that day's salt, for one purpose: so the same visitor is not counted twice in a day. Then both are deleted, and what remains is daily totals. Raw IP addresses and browser strings are never stored or logged, and because the salt changes daily, nothing links one day to the next.

If your browser sends a Do Not Track or Global Privacy Control signal, the beacon is not sent at all.

7 · Third-party requests

Your browser contacts three outside services while using this site:

Each of these sees your IP address in the ordinary course of serving a request, as any web host or server does. None of them sets a cookie on this site.

When you submit a contact form or load a page, your browser also contacts our own service on Amazon Web Services (an address ending in amazonaws.com). Your browser never contacts HubSpot; our service passes your request on.

8 · Check it yourself

The footer of every page says trust can be checked, not just claimed. So here is how, in any desktop browser.

Two limits, stated plainly. What a browser cannot show you is what our service does after it receives a request; for that you have this page and our word.

And the “Human / AI-assisted” split on the card is our own estimate of how each page was made, not something you can measure from outside.

9 · Questions and changes

Anything unclear, or a request about your data: write to our contact address. The address is kept out of this page's source so that spam harvesters cannot collect it, which is why it appears only with JavaScript turned on. If this page changes, the effective date above changes with it. Effective 5 October 2026.