Skip to the schedule

Privacy Policy

This is a static site with nothing to sign up for. Here is exactly what it records, what it does not, and what it keeps in your browser.

Last reviewed against the code

The short version

There are no accounts, no comments, no forms and no newsletter, so there is nothing for you to hand over and nothing for me to store. The site itself sets no cookies. Visits are counted with analytics that runs on a server I own rather than a third party's, and records nothing that identifies you. Video and podcast pages load their player straight from YouTube or Spotify, and those companies apply their own policies.

What the site is

Every page here is a file built ahead of time and served as-is. There is no application running behind it, no database, and no login anywhere on the site. Fonts, images, stylesheets and scripts are all served from this domain — there is no third-party script, no advertising network, no social widget and no remote font.

Analytics

The site can count visits using Umami, self-hosted at wa.santhoshj.com — my own server, not an analytics company's. It loads with the page. It sets no cookies and stores nothing in your browser; the small notice in the corner of the page says so on your first visit, and pressing OK simply stops it appearing again.

What gets recorded is the shape of the visit, never who made it: the page you are on, and a handful of named interactions — opening an entry or a channel, a link leaving the site, copying a code block, opening a tag or category, using a return or pager link, opening the feed, reaching the end of a piece, and asking for a URL that does not exist. Each carries only what it is about, such as which channel or which provider. None of it is joined to a person, a profile or a visit history, and none of it is shared with anyone.

If you would rather not be counted, a content blocker that blocks wa.santhoshj.com stops it entirely, and the site works exactly the same without it.

The embedded players

Video and podcast entries hold a real player from YouTube or Spotify rather than sending you away. The player loads with the page, so opening one of those entries means your browser contacts YouTube or Spotify. That provider can see your IP address and set its own storage, under its own privacy policy rather than this one. YouTube is requested through youtube-nocookie.com, its reduced-tracking embed host. Every other page on the site contacts neither company.

What is kept in your browser

One value, in this site's local storage, readable only by this site in this browser and never sent anywhere.

  • sj:notice — that you pressed OK on the privacy notice, so it does not appear again.

Clear this site's data in your browser and the notice shows again on your next visit.

The server

The site is served over HTTPS with HSTS, a Content-Security-Policy that permits only this domain plus the two embed providers and the analytics host, a referrer policy of strict-origin-when-cross-origin, and a permissions policy that denies camera, microphone and location outright. Like any web server, it keeps standard request logs — the time, the URL asked for, the response, the browser string and the IP address the request came from. They exist to run and debug the server; they are not used for analytics and are not combined with anything else.

Links that leave

The profile links at the top of every page, and the “Open on YouTube / Spotify / GitHub” reference at the foot of an entry, take you to sites I do not run. Once you are there, their privacy policies apply, not this one.

Changes

This page is part of the site's source, so it changes in the same commit as the behaviour it describes. The date above is when it was last reviewed against the code.

Questions

The profile links at the top of every page all reach me. If something here is unclear or looks wrong, say so and I will fix it.

Browse the schedule