Privacy Policy

Last updated: 16 September 2026

Ethics of Data is a personal blog written by Steven Tiell. This policy covers ethicsofdata.com and nothing else. It describes what the site actually collects — verified against what the site is running, not copied from a template.

The short version

  • There are no accounts, no ads, and no paywall.
  • The contact form goes to one mailbox and is the only place you are asked to write to me directly.
  • Comments are open for 21 days after a post is published, then close automatically. A comment publishes the name you type and what you wrote; your email address and IP address are stored but never shown.
  • Traffic is measured two ways: a cookie-free counter that never leaves this server, and Google Analytics, which does set cookies and does send data to Google.
  • Nothing collected here is sold, rented, or used to build a profile of you.

Information you give us

The contact form asks for your name, email address, a subject, and a message. Submissions are emailed to a mailbox hosted on Google Workspace and may also be stored in this site’s database so that a message is not lost if email delivery fails. The form is protected by Cloudflare Turnstile, described below.

That information is used to read and reply to what you sent. It is not added to a mailing list, not passed to anyone else, and not used for any other purpose.

Comments

Comments are accepted for 21 days after a post is published and close automatically after that, so most of the archive no longer takes them. Leaving a comment asks for a name, an email address, and optionally a website. The name, the website link, and the comment itself are published. The email address is not published. WordPress also records the IP address the comment was sent from and the browser’s user-agent string, both of which are visible only to the site owner and are used to identify spam and abuse.

Every comment is held and read before it appears. Nothing you write is published automatically. Comments and everything attached to them are stored in this site’s own database on the hosting server. They are not sent to a third-party comment service, there is no social login, and commenting does not create an account or subscribe you to anything.

Spam filtering is handled by Antispam Bee, which runs on this server and does not transmit comment content to an external service. The comment form is also protected by Cloudflare Turnstile, described below. If you tick the box offering to remember your details, WordPress stores your name, email address, and website in cookies on your own device so you do not have to retype them; leave it unticked and no such cookie is set.

Information collected automatically

Server logs

The site is hosted by IONOS, whose servers keep standard access logs: IP address, browser user agent, the page requested, and a timestamp. These are used for security and troubleshooting and are retained under the hosting provider’s own schedule.

On-site statistics (Statify)

Statify records the date, the page viewed, and the referring site. It sets no cookie, stores no IP address, and keeps everything on this server. It cannot identify you or follow you to another website.

Per-article view counts

Post Views Counter shows how many times an article has been read. It sets a short-lived cookie so that reloading a page is not counted twice. It records a number, not an identity.

Google Analytics

Google Analytics 4 runs on this site through the Site Kit plugin, under measurement ID G-CR74WC2ZH2. It sets cookies and sends data about your visit to Google, which processes it as a separate controller under its own privacy policy. IP anonymisation is enabled.

Google Signals is switched off. That is the setting which would otherwise tie a visit to a signed-in Google account and feed it into advertising and cross-device reporting. With it disabled, no data from this site reaches Google’s advertising systems and nothing is sent to doubleclick.net. Analytics here measures which articles get read — nothing more.

Google Search Console is also connected. It reports aggregate search terms that led people here; it does not give this site any visitor-level data.

Cookies

CookieSet byPurposeLifetime
_gaGoogle AnalyticsDistinguishes one visitor from anotherUp to 2 years
_ga_CR74WC2ZH2Google AnalyticsKeeps session state for this propertyUp to 2 years
pvc_visitsThis siteStops a page refresh being counted as a second readHours
comment_author_*This siteRemembers your name, email, and website for the next comment — only if you tick the box1 year

There are no advertising cookies. You can block or delete any of these in your browser settings, and Google publishes a browser add-on that opts you out of Analytics entirely.

Other services this site touches

  • Google Fonts. Typefaces are loaded from fonts.googleapis.com and fonts.gstatic.com, which means your IP address is visible to Google when a page loads.
  • Gravatar. Used to display avatars next to the author’s name and next to comments. To look one up, WordPress sends Gravatar a one-way hash of the email address together with the requesting IP address. Gravatar is operated by Automattic under its own privacy policy.
  • Share buttons. The LinkedIn, Facebook, and Mastodon buttons use Shariff, which means they do not contact those networks until you actually click one. No silent social tracking.
  • Cloudflare Turnstile. A privacy-preserving alternative to CAPTCHA, used on the contact form and the comment form to tell people apart from bots. It examines browser signals and your IP address in order to decide whether to let a submission through. It does not ask you to identify traffic lights, and Cloudflare states that it does not use this data to track people across sites or to serve advertising. See Cloudflare’s privacy policy.
  • IONOS. Hosting and server infrastructure.
  • Google Workspace. Where contact form messages are delivered and stored.

What this site does not do

  • No advertising, ad networks, retargeting pixels, or affiliate tracking.
  • No sale or sharing of personal information — for money or for cross-context behavioural advertising.
  • No accounts, registration, or mailing list. The Autonomy Is Earned newsletter is published on LinkedIn; subscriptions are handled entirely by LinkedIn under its own privacy policy, and this site never sees that list.
  • No profiling and no automated decision-making.

Why we are allowed to do this

For readers in the EEA and UK: replying to a message you send rests on taking steps at your request. Server logs and cookie-free statistics rest on legitimate interests in keeping the site secure and understanding what people read. Analytics cookies rest on consent where consent is required, and you can withdraw it at any time by clearing or blocking them.

Your rights

Depending on where you live, you may have the right to see what data is held about you, correct it, delete it, restrict or object to how it is used, receive a copy, or withdraw consent. Readers in California may also ask what has been collected and request deletion, and cannot be treated differently for asking. Since nothing here is sold or shared, there is no opt-out to exercise on that front.

To exercise any of these, use the contact form. Requests are handled personally, usually within a few days. If you are in the EEA or UK and you are not satisfied, you may complain to your national data protection authority.

How long things are kept

Contact form messages are kept for as long as the conversation is useful, then deleted. Published comments are kept indefinitely so that a thread still makes sense years later; ask and yours will be removed. On-site statistics are aggregate and kept indefinitely because they identify no one. Analytics data is retained according to the schedule set in Google Analytics. Server logs follow the hosting provider’s retention period.

Where your data goes

Hosting and email are in the United States, and Google processes analytics data in the United States and elsewhere. If you are reading from the EEA or UK, your data therefore leaves your region, relying on the transfer safeguards those providers have in place.

Security

The whole site is served over HTTPS: any request over plain HTTP is permanently redirected to the encrypted version before a page is returned. Access to the administrative side is limited and protected by application passwords rather than shared credentials. No website can promise perfect security, and this one makes no such promise.

Children

This site is written for a professional audience. It is not directed at children, and there is no knowing collection of information from anyone under 16.

Changes

If what the site collects changes, this page changes with it, and the date at the top moves. There is no separate notification.

Contact

Questions about any of this go through the contact form. It reaches Steven directly.