Privacy, reader accounts and email
You can browse, search inside PDFs, read, download, and follow podcast links without registering. Reader access does not grant Author permissions.
Optional reader accounts and subscriptions
Reader registration and subscriptions are available as optional tools.
Registration asks for a first name and email address; a last name is optional. We use a short-lived email link rather than a password. A reader account lets you manage your own profile and email preferences. Changing its email address requires confirmation in the current mailbox and verification of the new one. A reader account cannot manage the Catalog or view another reader’s information.
New-essay emails require a separate, affirmative subscription choice and email confirmation. You can subscribe without creating an account. Registering, reading, or sending a Contact message does not subscribe you. We retain the subscription status, the consent wording/version, and when and through which form you requested and confirmed it.
Notifications concern genuinely new first publications after activation, not the existing archive or ordinary corrections. Each includes an introduction and a public essay link, with a podcast link when available. Unsubscribe links require no login. Unsubscribing stops pending and future essay notifications but does not delete your account. It cannot recall a message already handed to the email provider. Re-subscribing requires a fresh choice and confirmation.
Reader information and email retention
Names, email addresses, account records, consent evidence and delivery records are stored privately in the Catalog’s database. They are not included in public search, Catalog downloads or the Curiosity Counter. Only the Author can view the reader-management reports. Permanent bounces and complaints are recorded to stop further delivery; a public form cannot remove that protection.
Reader sign-in uses a secure, HttpOnly, same-site session cookie with a seven-day lifetime renewed during continued use. Sign-in and email-verification links normally expire after ten minutes. Verification links are single-purpose private information; do not share them. Queued email must temporarily contain the links needed for delivery.
Background cleanup removes expired sessions and verification records after an additional day, expired subscription-confirmation requests after 30 days, and delivery-webhook receipts after 90 days, in bounded batches. Terminal email bodies become eligible for redaction after one day; uncertain deliveries retain their payload for reconciliation. Cleanup can lag while processing is unavailable. Account records, consent evidence, unsubscribed/suppressed status and delivery-status records remain until reviewed or removed for their purpose. Request deletion through Contact; minimal suppression information may need to remain to honor your request not to receive mail.
Temporary technical and rate-limit records protect forms against abuse. Network-address information is used for request limits, but reader sessions do not retain a browsing history or network address. This processing is separate from anonymous visit counting. Signing out removes the active reader session; unsubscribing is a separate action.
The Curiosity Counter
This is a cumulative count of Catalog visits, not an exact count of individual people. The same Catalog-only total may appear on the homepage. Main-site visits are not added to it.
A visit uses a random token in your browser tab’s session storage. A new tab, unavailable storage, or more than 30 minutes without a recorded Catalog navigation or document/podcast action may start a new visit. Normal page navigation and refreshes within that session do not add visits. Crossing midnight alone does not start a new counter visit. Reading or scrolling without a recorded action does not extend the session.
Counting starts with the first eligible visit after activation. The displayed start date is in UTC. Existing statistics are not imported into this total. Public totals can lag by a few minutes because they are cached. If the counter is unavailable, we do not invent a number.
Signed-in Author activity, recognized bots and monitoring tools, local previews, Do Not Track, and Global Privacy Control are excluded where identifiable. Automated visitors may evade these checks. Separate browser tabs may count separately. Storage restrictions and abuse limits can undercount. This is a measure of activity, not a precise census.
What is stored
The Catalog keeps aggregate daily page views, PDF-reader opens, download clicks and podcast-link clicks for the Author, plus the public visit total. It does not store names, email addresses, IP addresses, search terms, referrers or an individual browsing history for this counting. Browser tokens are random, not fingerprints or advertising identifiers. Server-side hashed tokens and duplicate-prevention receipts expire after 48 hours and are removed as new events arrive; cumulative and daily aggregates are retained.
Your browser also remembers local interface preferences such as motion and reading position. These are separate from the visit total. Closing the tab normally clears its session token.
Contact messages
The Contact form can be used without registration. It stores your submitted name, email address and message privately in WordPress and attempts email delivery to the site owner. Sending a message does not subscribe you to essay alerts. Messages remain available to the owner for correspondence until removed; request deletion through Contact.
Services and external links
The Catalog uses OpenAI Sites and Cloudflare hosting/storage; the main WordPress site is hosted by GoDaddy. Those services may process technical request information under their own policies. Author sign-in uses OpenAI. YouTube links leave this site and are subject to YouTube’s privacy practices.
Reader sign-in is handled by the Better Auth library within the Catalog, with its records in the Catalog database. Resend processes email addresses, message contents and delivery reports for reader mail. Upstash QStash triggers background processing; the scheduled requests contain no reader name, email address, essay text or verification link. These services may retain operational logs under their own policies. Reader-email setup does not replace the WordPress Contact workflow.
Questions or deletion requests
Please use Contact for privacy questions or to request deletion of information you supplied. We may need to verify ownership of the email address before changing or deleting private records. The Curiosity Counter itself never creates an account or subscription.