No story collection by default

Privacy and no-logs design

The public site is static-first and does not intentionally collect a person’s story.

Application behavior

  • No analytics, advertising, tracking pixel, account system or application database.
  • No custom request logging in Worker code; Cloudflare observability is disabled in configuration.
  • API validation and hashing are stateless and return results without application retention.
  • Private or restricted data must fail closed rather than route to an unapproved provider.

Infrastructure boundary

“No custom logs” is not the same as proving that every network, DNS, browser, hosting, security or access-control layer stores nothing. Operators must inspect Cloudflare account settings, access policies, DNS, GitHub Actions, domain registration, error reporting and legal requirements. Do not submit identifiable case, health, child, immigration or legal records to the public site.

Machine-readable privacy statement