Privacy
Short version: an email address, a list of what you have read, and no cookies for tracking. You can delete all of it yourself, at any time, and it goes.
What is stored
Your email address. It is how you sign in — there is no password to store, because sign-in is a six-digit code emailed to you. It is held by our authentication provider, Supabase.
Your readings. The work, which sections, the translator, the date, and any note you wrote. Nothing else. These rows are protected at the database level by row-level security keyed to your account, which means no other signed-in reader and no anonymous visitor can select them — not merely that the site does not show them.
Your reading record is private. The lists — the canon and the syllabus — are public and identical for everyone; what is lit up on them is visible only to you.
Analytics, and the absence of cookies
We use PostHog to count page views and a handful of product events (a sign-in code was requested, a reading was logged). It is configured with in-memory persistence, which means no analytics cookie and no localStorage entry is written to your browser. Nothing follows you between visits, and there is no consent banner because there is nothing to consent to.
The cost of that is ours, and it is real: we cannot tell a returning reader from a new one. That seemed the right trade for a site whose entire content is a private reading log. Analytics requests go through this domain (/ingest) rather than to a third-party host.
What we do not send: the titles you have read, the translators you chose, or the text of your notes. A logged reading is recorded to analytics as the fact that one happened.
Vercel Web Analytics also counts page views. It is cookieless by design and collects no personal data.
Cookies that do exist
One kind: the session cookie that keeps you signed in after you enter your code. It is strictly necessary — without it you would be signed out on every page — and it is not used for tracking or advertising.
The only email this site sends is your sign-in code. There is no newsletter and no marketing list, and your address is not shared with anyone.
Deleting your account
Your account page has a delete button. It removes your account and every reading attached to it, immediately and permanently. There is no grace period and no soft delete: a reading log is not a business record, and when someone asks for it to be gone the honest implementation is that it is gone.
You do not need to email anyone to do this, and you will not be asked why.
Who processes what
- Supabase — authentication and the database (your email, your readings).
- Vercel — hosting, and cookieless page-view analytics.
- PostHog — cookieless product analytics, proxied through this domain.
- Resend — delivery of the sign-in code email.
Each has its own project for this site. Nothing about your reading is shared with the other sites Noble Fluency runs, and none of the four is given data beyond what is described above.
Asking
hello@winedark.app reaches a person. If you want a copy of what is stored about you, ask and you will get it.
Noble Fluency LLC