// privacy / changelog
Privacy Policy — Changelog
Every revision of the privacy policy, oldest at the bottom. The current effective version is at /privacy.
v1.8
2026-07-27Corrections found by auditing this policy line-by-line against the code that implements it. Four claims did not hold. We said we derived approximate geolocation from your IP — we do not, and the lookup cache that once did was deleted; we store only the first three octets and a truncated User-Agent. We said a cookie remembered your language selection — there is no language selector, and the cookie is set automatically and always says English. We said material changes are announced to newsletter subscribers and shown in a site banner — neither mechanism exists, so the policy now tells you to check back rather than promising a notification that will not arrive. And contact-submission retention claimed a hard delete once an enquiry closed, when no deletion job exists: submissions are kept until erased on request or in a periodic clear-out, which is the truth. Two entries were also strengthened rather than corrected: hCaptcha now loads only when you interact with a form instead of on every page carrying one, and error reports are redacted field-by-field — including the exception message — rather than only having the request envelope stripped.
v1.7
2026-07-26The site no longer has user accounts. Sign-in, the account dashboard, multi-factor authentication, session tracking, the per-request activity log and the forensic audit log were all removed from the product, so every section describing them is gone from the policy — along with the GitHub OAuth sub-processor, which was already unused. What we hold is now just contact-form submissions, newsletter subscriptions, and Plausible’s cookieless aggregate analytics. Two substantive improvements: erasure is now an outright delete rather than a 30-day anonymisation, and Sentry error reports are stripped of cookies, headers, query strings and request bodies before they leave our servers.
v1.6
2026-07-17Removed the on-site AI assistant. The site no longer sends anything you type to an AI provider, and the Vercel AI Gateway is no longer a sub-processor. Contact-form and booking data handling is unchanged.
v1.5
2026-07-12Added the optional on-site AI assistant. When enabled, messages typed into the chat are processed by our AI provider via the Vercel AI Gateway to generate replies — disclosed as a new sub-processor, with a dedicated "AI assistant" section. Messages are not used for ads, profiling, or tracking; transcripts are not stored; lead details are only kept when explicitly submitted through the existing contact form or booking.
v1.4
2026-05-07Sub-processor regions generalised to country-level (specific cloud region codes moved to internal operational documentation). Audit log hash-chain language softened from algorithm-specific to general cryptographic-chain description. No reduction in disclosure scope or user rights.
v1.3
2026-05-06Brand-readiness expansion. New sections: categories of data, sub-processors table (replaces "Where data lives"), retention schedule, international transfers, children, cookies, audit log, complaint right, DPO + DPA contact, breach notification, client-engagement clause, automated decision-making. Amended: authentication wording, Plausible IP disclosure, contact form spam-triage line, contact alias (privacy@), versioning split into lastUpdated + effectiveDate.
v1.2
2026-05-03Added MFA section (TOTP secret encryption with AES-256-GCM, hashed backup codes, retention until disable). Idle-timeout bumped from 4h to 30 minutes.
v1.1
2026-05-01Added activity-log + session-metadata sections with 90-day retention disclosure. Genericised provider names (specific list available on request) — superseded in v1.3 by the sub-processors table.
v1.0
2026-04-15Initial policy. GDPR + CCPA-shaped baseline covering newsletter, contact form, OAuth profile, no-tracking-cookies stance.