Privacy
What this site collects.
Short version: this site has no analytics, no advertising, no tracking pixels, and no third-party scripts beyond a spam check. It stores an email address if you subscribe to the newsletter, and a message if you use the contact form. Nothing else.
Last updated July 21, 2026.
What is stored, and why
If you subscribe to Notes from altitude
- Your email address. It is the newsletter. It is stored so issues can be sent to it.
- A consent record: the IP address and browser user-agent your signup came from, the date and time, and which page you signed up on. This exists so that if a mailbox provider or you ever ask "why is this address on your list?", there is a truthful, specific answer. It is not used to profile you, is never combined with anything else, and is not shared.
- The date, time, and IP address of your confirmation click — the second half of the same consent record.
- Delivery outcomes reported by the email provider: whether a message hard bounced or was reported as spam. Those are used to stop sending, which is the only respectful response to either.
Double opt-in. Submitting the signup form does not subscribe you. It sends one confirmation email; the subscription does not exist until you click the link in it. If you never click, you are not on the list and you will not hear from this site again.
There are no tracking pixels and no click tracking in the newsletter. Open rates are not measured. There is no way to tell from here whether you read an issue, and that is deliberate.
If you use the contact form
- Your name, email address, message, and the reason you selected. The message is emailed to a mailbox that a person reads, and a copy is filed in a private workspace so it does not get lost.
Cookies
These pages set no cookies, run no analytics, and carry no tracking of any kind. There is no consent banner because, for ordinary reading, there is nothing to consent to.
The one cookie, and exactly when it exists
The previous version of this page said a subscriber sign-in area was planned. It has now shipped, so here is the specific accounting — the same rule that produced this page in the first place.
- Name:
__Host-bhl_sess - Purpose: to keep you signed in at /account after you click a sign-in link, so you can see and change what you are subscribed to. That is its only function.
- What it contains: one random, opaque value and nothing else. No email address, no name, no identifier that means anything outside this system, and nothing that can be read by looking at it. The server stores only a one-way hash of it, so even the database does not hold a usable copy.
- Lifetime: 30 days, extended while you keep using the account page, and deleted immediately when you sign out.
- When it is set: only after you deliberately request a sign-in link and click it. It is never set by reading an essay, the home page, or any other page on this site — browsing here sets no cookie at all, before or after you have an account.
- Where it goes: only to
api.zacharywood.ai. It is deliberately scoped to that single hostname and is not sent to this site's pages or to any other subdomain. - What it is not used for: no analytics, no advertising, no measurement, no profiling, and no sharing with anyone. It cannot follow you to another site, because it is not sent to one.
This is a strictly necessary cookie in the sense the ePrivacy rules use: the feature you asked for cannot work without it, and it does nothing else. That is why there is still no consent banner — not because the cookie is being waved through, but because you only ever get it by asking to sign in, and refusing it would simply mean not signing in.
You never have to sign in. Unsubscribing works without an account: every issue carries a one-click link, and most email clients show their own Unsubscribe button on these messages. The account page exists to make changing your mind easier, not to put a login in front of something that used to be open.
Who else touches this data
- Postmark (Wildbit, LLC) is the email provider. It processes newsletter and contact messages in order to deliver them, and reports bounces and spam complaints back.
- Cloudflare hosts this site and runs Turnstile, the spam check on the forms. Turnstile is used specifically because it works without behavioural profiling or tracking cookies.
- Notion stores contact-form submissions in a private workspace.
That is the complete list. Nothing is sold, rented, or shared for advertising, and no data is handed to anyone not named above — except where the law genuinely requires it.
How to leave, and how to get your data removed
- Unsubscribe: every issue carries a one-click unsubscribe link in its footer, and most email clients also show their own Unsubscribe button on these messages. Either takes effect immediately — no sign-in, no survey, no "are you sure".
- Change what you get: /account sends you a sign-in link and lets you switch each list on or off, or turn everything off at once. Optional — the unsubscribe link above needs no account.
- Deletion: email [email protected] and ask. Your subscriber record and its consent history will be deleted.
- A copy of what is held: ask at the same address.
Unsubscribing keeps a minimal record that you unsubscribed. That is on purpose: it is what stops a later import or a mistake from putting you back on the list. Ask for deletion if you would rather that record not exist either.
How long it is kept
Subscriber records are kept while you are subscribed and for as long as the unsubscribe record is useful for suppression. Contact-form messages are kept as ordinary correspondence. Neither is kept on a schedule designed to accumulate anything.
Children
This site is not directed at children and does not knowingly collect their information.
Changes
If what this site collects changes, this page changes in the same release — the same rule that produced it. The date at the top is the last time that happened.
Questions
Write to [email protected]. For anything relating to Blue Horizon Labs's own services rather than this site, see bluehorizonlabs.ai.