Privacy Policy
What this site collects, what it does not, and who else is involved. It is short because the site does very little.
Last updated September 21, 2026
The short version
This is a personal site. There are no ads, no tracking pixels, and nothing about you is sold or shared with anyone. Most of it works without collecting anything at all. The parts that do collect something are the parts you choose to use: the contact form, the comments, and the assistant.
No cookies are set until you sign in to leave a comment. Analytics does not run unless you say yes.
Who is responsible
Michael Kinder runs this site from Haysi, Virginia, in the United States. For anyone reading this from the EU or the UK, that makes me the data controller. I do not publish an email address, so the contact form is the way to reach me about anything on this page, including a request about your own data.
What happens when you just read a page
Nothing that identifies you. There is no account, no profile, and no fingerprinting. The site is built as static files and served by Vercel, who handle the request and keep short-lived server logs that include IP addresses, as almost every web host does.
Typefaces are whatever your device already has, so nothing is fetched from a font service. Icons and images are served from this site. Two exceptions involve your browser contacting someone else, which means they can see your IP address:
- Album artwork. The covers on the About page and in the now playing bar are loaded from Last.fm's image CDN, which runs on Fastly. This happens on those pages whether or not you interact with them.
- Cloudflare Turnstile. The anti-spam check on the contact page. It loads on that page only, and it looks at browser signals to decide whether you are a person.
Analytics
I would like to know roughly how many people read which posts. For that I use GoatCounter, which is open source and which I run myself at tracking.foggymtndrifter.com. That matters more than the choice of tool: no analytics company is involved, and nothing about your visit is handed to one. It is my own subdomain, and the numbers stay with me.
It sets no cookies and stores nothing on your device. What it records is the page you looked at, the site you arrived from, your rough country, and what your browser says about itself, meaning browser, operating system and screen size.
Beyond page views it counts a short list of things people do here, so I can tell which parts of the site are worth keeping: opening the assistant and asking it something, following one of its suggested links, opening search and opening a result, filtering the blog, sending the contact form, signing in to comment and posting one, opening a track in the now playing bar, and opening the coffee sheet, including which amount was chosen by anyone who carries on to Cash App.
The assistant's opening message shows a running visitor total. That number is read back from the same counter, which sends nothing about you and only happens if analytics is switched on. GoatCounter caches the figure for a few hours, so it is a rough position rather than an exact one, which is why the wording says so.
These are tallies of actions, not of people. Nothing you typed is ever sent: not your question to the assistant, not what you searched for, not your comment, not your message. Nothing marks which visitor did what, and no payment details exist here to send, because the payment happens on Cash App rather than on this site.
To tell one visit from several, it does not tag you. It takes your IP address and your browser's description, mixes them with a secret that is thrown away and replaced through the day, and keeps only the result. Your IP address itself is not stored, and once that secret rotates the result cannot be traced back to you or matched against tomorrow's.
None of it loads until you allow it. Until you answer the banner there is no analytics code on the page and no request to that subdomain at all. You can change your answer whenever you like with the Privacy choices link in the footer. Turn it off and nothing further is sent, and since nothing was stored on your device there is nothing left to clear.
Cookies and browser storage
All of it is first party. None of it is used for advertising, and none of it follows you anywhere.
- gh_oauth_state
- Cookie, 10 minutes. A one-time random value that proves the sign-in coming back from GitHub is the one you started. Strictly necessary.
- gh_redirect_to
- Cookie, 10 minutes. Remembers which post to return you to after signing in. Strictly necessary.
- gh_token
- Cookie, 30 days. Keeps you signed in so you can post and delete your own comments. Strictly necessary. Signing out removes it.
- fmd.consent
- Local storage, until you clear it. Your answer to the analytics banner, so you are not asked again on every page.
- fmd.np.dismissed
- Local storage, one hour. The moment you swiped away or closed the now playing bar, so it stays gone for an hour instead of coming straight back on the next page.
- fmd.np.seen
- Session storage, until you close the tab. The last track the now playing bar opened up for, so it does not announce the same song again on every page you visit.
- fmd.ask.thread
- Local storage, until you clear it. The last few messages of your conversation with the assistant, so it survives moving between pages. Clearing the conversation removes it.
The three cookies are only ever set if you sign in to comment, and all three are HttpOnly, which means scripts on the page cannot read them.
The contact form
It asks for your name, email address, a subject and a message. When you send it, all four are delivered to a private Discord channel that only I read. They stay there until I delete them, which in practice means as long as the conversation is useful.
Two things guard the form. Cloudflare Turnstile checks that you are not a bot, and the form quietly measures how long the page was open and includes a field that humans never see, because scripts fill it in and people do not. There is also a limit on how many messages one address can send in ten minutes, which keeps IP addresses in memory for that long and never writes them anywhere.
Comments
Comments run on GitHub Discussions rather than on a database of mine. Signing in uses GitHub's own sign-in, after which I can see your GitHub username, your profile link and your avatar. I never see your GitHub password, and I do not receive your email address.
Comments are public. They live in a public GitHub repository, they are visible to anyone, and they are covered by GitHub's privacy statement as well as this one. You can edit or delete your own comments, and deleting one on GitHub removes it here.
The assistant reads them too, because people sometimes say things in a thread that are not anywhere else on the site. That means a comment of yours can be quoted back to someone who asks a related question, along with your GitHub username, and that the text goes to OpenRouter and Anthropic as reference material the same way a page does. The assistant is told to say who wrote what and never to pass a reader's words off as mine. Delete a comment on GitHub and it leaves the assistant within the hour.
The assistant
When you ask the assistant something, your question, the last few messages in the conversation, and the path of the page you are on are sent to OpenRouter, which passes them to Anthropic's Claude to write the answer. The answer itself is drawn only from this site's own pages and the public comment threads under the posts.
The site does not store your conversation on the server. It is kept in your browser, and clearing it in the panel removes it. Treat it like any other chat box and do not type anything sensitive into it.
Buying me a coffee
The coffee button opens Cash App in a new tab, carrying the amount you picked. No card or bank details ever touch this site, and nothing is sent to Cash App until you choose to go there. What happens after that is between you and Block, who run Cash App. If analytics is switched on, the amount you were on when you left is counted, and nothing else about it.
Who else is involved
These are the companies that handle something on this site's behalf. Each has its own privacy policy, and none of them are given your data for their own marketing. Analytics is not on this list, because it is not a company: it runs on my own subdomain.
- Vercel, United States. Hosting and server logs.
- Cloudflare, United States. Turnstile anti-spam on the contact page.
- Discord, United States. Delivery of contact form messages.
- GitHub, United States. Sign-in and comment storage.
- OpenRouter and Anthropic, United States. The assistant's answers.
- Last.fm, United Kingdom, with images served via Fastly. Album artwork and my listening history.
- Block, United States. Cash App, if you use the coffee link.
Most of these are in the United States, so if you are in the EEA, the UK or Switzerland, using those parts of the site means your data is transferred there. Those transfers rely on the providers' standard contractual clauses and, where the provider is certified, the EU-US Data Privacy Framework.
Why I am allowed to do this
If you are in the EEA or the UK, the legal bases are these. Analytics happens on consent, which is what the banner is for. Replying to your message and showing your comment happen because you asked me to, which is your request and my legitimate interest in running a site people can talk to. Spam checks and rate limits are a legitimate interest in keeping the site working.
How long things are kept
- Contact messages: in Discord until I delete them.
- Comments: public on GitHub until you or I delete them.
- Server logs: however long Vercel keeps them, which is a matter of days.
- IP addresses used for rate limiting: minutes, in memory, never written to disk.
- Analytics: aggregate counts only, with nothing to tie back to a person.
- Anything in your browser's storage: until you clear it.
Your rights
If you are in the EEA or the UK, you can ask for a copy of what I hold about you, ask me to correct it or delete it, object to or restrict what I do with it, ask for it in a portable form, and withdraw consent at any time. You can also complain to your national data protection authority.
If you are in California, you can ask what I have collected, ask me to delete or correct it, and opt out of the sale or sharing of personal information. There is nothing to opt out of: I do not sell or share personal information, I never have, and I do not use it for cross-context behavioral advertising. Asking me about any of this will never get you worse treatment.
Similar rights exist under other state and national laws, and I will honor them the same way regardless of where you are. Use the contact form and say what you want. In practice the honest answer is often that I hold nothing about you beyond a message you sent me, because the site does not collect much to begin with.
Children
This site is not aimed at children, and I do not knowingly collect anything from anyone under 13, or under 16 in the EEA. If you think a child has sent me something, tell me and I will delete it.
Changes
If this page changes, the date at the top changes with it. If a change affects what analytics does, the banner asks again rather than assuming your old answer still applies.