// privacy / changelog

Privacy Policy — Changelog

Every revision of the privacy policy, oldest at the bottom. The current effective version is at /privacy.

  1. v1.8

    2026-07-27

    Corrections found by auditing this policy line-by-line against the code that implements it. Four claims did not hold. We said we derived approximate geolocation from your IP — we do not, and the lookup cache that once did was deleted; we store only the first three octets and a truncated User-Agent. We said a cookie remembered your language selection — there is no language selector, and the cookie is set automatically and always says English. We said material changes are announced to newsletter subscribers and shown in a site banner — neither mechanism exists, so the policy now tells you to check back rather than promising a notification that will not arrive. And contact-submission retention claimed a hard delete once an enquiry closed, when no deletion job exists: submissions are kept until erased on request or in a periodic clear-out, which is the truth. Two entries were also strengthened rather than corrected: hCaptcha now loads only when you interact with a form instead of on every page carrying one, and error reports are redacted field-by-field — including the exception message — rather than only having the request envelope stripped.

  2. v1.7

    2026-07-26

    The site no longer has user accounts. Sign-in, the account dashboard, multi-factor authentication, session tracking, the per-request activity log and the forensic audit log were all removed from the product, so every section describing them is gone from the policy — along with the GitHub OAuth sub-processor, which was already unused. What we hold is now just contact-form submissions, newsletter subscriptions, and Plausible’s cookieless aggregate analytics. Two substantive improvements: erasure is now an outright delete rather than a 30-day anonymisation, and Sentry error reports are stripped of cookies, headers, query strings and request bodies before they leave our servers.

  3. v1.6

    2026-07-17

    Removed the on-site AI assistant. The site no longer sends anything you type to an AI provider, and the Vercel AI Gateway is no longer a sub-processor. Contact-form and booking data handling is unchanged.

  4. v1.5

    2026-07-12

    Added the optional on-site AI assistant. When enabled, messages typed into the chat are processed by our AI provider via the Vercel AI Gateway to generate replies — disclosed as a new sub-processor, with a dedicated "AI assistant" section. Messages are not used for ads, profiling, or tracking; transcripts are not stored; lead details are only kept when explicitly submitted through the existing contact form or booking.

  5. v1.4

    2026-05-07

    Sub-processor regions generalised to country-level (specific cloud region codes moved to internal operational documentation). Audit log hash-chain language softened from algorithm-specific to general cryptographic-chain description. No reduction in disclosure scope or user rights.

  6. v1.3

    2026-05-06

    Brand-readiness expansion. New sections: categories of data, sub-processors table (replaces "Where data lives"), retention schedule, international transfers, children, cookies, audit log, complaint right, DPO + DPA contact, breach notification, client-engagement clause, automated decision-making. Amended: authentication wording, Plausible IP disclosure, contact form spam-triage line, contact alias (privacy@), versioning split into lastUpdated + effectiveDate.

  7. v1.2

    2026-05-03

    Added MFA section (TOTP secret encryption with AES-256-GCM, hashed backup codes, retention until disable). Idle-timeout bumped from 4h to 30 minutes.

  8. v1.1

    2026-05-01

    Added activity-log + session-metadata sections with 90-day retention disclosure. Genericised provider names (specific list available on request) — superseded in v1.3 by the sub-processors table.

  9. v1.0

    2026-04-15

    Initial policy. GDPR + CCPA-shaped baseline covering newsletter, contact form, OAuth profile, no-tracking-cookies stance.