Privacy
Collect little. Explain it plainly.
This disclosure describes the data features and owner-approved operating policy for the current private Version 2.1 checkpoint.
Last reviewed: September 3, 2026
Email updates
If you subscribe, the site stores your normalized email address, display email, consent version, date, source path, and limited UTM or referrer-domain context in Cloudflare D1. A sending provider is not connected, and the public response does not reveal whether an address was already present.
Active subscriber email addresses are retained while the subscription remains active, until the subscriber unsubscribes or requests deletion. After unsubscribe, the address is removed from the active subscriber database. Only the minimum suppression information reasonably necessary to prevent unwanted future email may be retained if that becomes necessary after outbound email infrastructure is activated.
Limited source-attribution information legitimately associated with an active subscriber record may remain for the life of that subscription.
Corrections and data requests
The form stores your correction type, message, optional source URL, optional email, page path, date, and review status in D1. Do not submit sensitive information.
Correction submissions are retained for up to 24 months, unless earlier deletion is appropriate or a longer period is reasonably necessary for an unresolved editorial matter. Privacy, deletion, and similar data-rights request records are retained for up to 24 months for operational and compliance recordkeeping.
First-party interaction events
The site records a small allowlist of events such as diagram control use, research filters, source opens, copy actions, and completed forms. Records can include path, time, a numeric control value, and limited UTM or referrer-domain context. They do not include submitted email addresses, free-form page content, or keystrokes.
First-party interaction-event records are retained for up to 13 months. Referrer-domain and campaign or UTM information used for aggregate interaction measurement is also retained for up to 13 months.
Abuse prevention
Form requests use short-lived rate-limit records derived from a one-way hash of an IP address. Raw IP addresses are not written to the application database by these handlers.
Temporary rate-limit and abuse-prevention records are retained for no longer than seven days and are deleted earlier whenever the technical protection no longer requires them. The current implementation removes expired records during subsequent form or event requests.
Analytics, cookies, and service providers
The private preview runs on the Sites hosting service and uses Cloudflare D1 for form and first-party event records. Hosting infrastructure may process ordinary request metadata and provide aggregate service-level analytics under its own operating terms.
No third-party analytics identifier, advertising tracker, or newsletter sending provider is configured. The application code sets no analytics or advertising cookies; the private-preview access gate may use strictly necessary session technology.
RecurrentDepth.org does not sell personal information, and does not share personal information for cross-context behavioral advertising. We do not use subscriber information for third-party advertising.
If an external newsletter provider, analytics provider, advertising system, or other material data processor is added in the future, this privacy policy must be reviewed and updated before that integration becomes publicly active.
Your choices
You can unsubscribe using the link in any future newsletter. Before a sender is connected, or to request access or deletion, use the corrections form, choose “Privacy or data request,” provide the email address involved, and describe the request. Verification may be required before records are disclosed or deleted.
RecurrentDepth.org follows data-minimization principles and does not retain information longer simply because storage is available. These retention periods are the owner-approved operating policy for Version 2; they are not described as legal requirements. Last reviewed September 4, 2026. This operational disclosure is not legal advice.