← Back

Privacy

You’re reading a privacy policy. Voluntarily. Something has gone wrong in your life and I’m delighted to be part of it.

Here’s the short version. I count page views. I use one optional cookie to spot repeat visits, and one essential cookie to remember whether you wanted the first one. Nobody stores your full IP address. If you subscribe to the newsletter, that email address sits in a separate system with no shared key, so I can’t connect it to anything you read.

The long version is below, because UK GDPR insists. You can turn all of it off at the bottom of this page.

Who I am

I’m Will Hackett. I run this site on my own. There’s no company behind it, no analytics team, and no growth department. Just me, a domain name, and an unreasonable interest in what people click on.

For privacy questions or requests, email gdpr@willhackett.com. It comes straight to me. For anything else, I’m on LinkedIn.

I only want to know which posts land

There are no ads on this site, no affiliate links, and no pixels working for anyone else. I write things and I’m curious whether they work.

To prove how mundane this is, here are the results. Agentic coding workforce is my most-read post this year. Just use Postgres is second. My least-read post is a 404, because I deleted it. It was a pre-relationship agreement written as a comedy sketch about how grim internet dating had become, from 2014, back when I had no filter. It is still floating around the web somewhere if you’re determined enough.

Nobody pays me for any of that data. I just like knowing.

One disclosure, because a privacy policy that oversells its own purity isn’t worth reading. I co-founded a company called flowstate, and I write about it here fairly often. Some of these posts are, in the honest sense of the word, an advert.

What that doesn’t change: nobody at flowstate has access to this site’s analytics, the two run on entirely separate infrastructure, and no reader has ever been handed over as a lead. Knowing which posts land does make me better at writing about my own company. That’s a motive, and now you know about it.

What I collect

When you read a page, I record:

If you subscribe to the newsletter, I collect your email address. Nothing else. Not your name, not your blood type, not your mother’s maiden name.

The cookie

One cookie, called visitor. It holds a random ID that looks like 0f9c1a2b-3d4e-4f50-8a6b-7c8d9e0f1a2b. It means nothing on its own and it isn’t derived from anything about you. Your browser invents it.

Its only job is to turn “300 people read this” into “300 people read this, and 40 of them had read something else of mine first”. That is the entire feature.

The banner calls it wafer-thin. That’s the only Monty Python reference in this document, and if you know the sketch you’ll understand why I stopped at one.

There’s a second cookie, visitor-consent, which remembers your answer so I only ask once. Yes, I need a cookie to remember that you didn’t want a cookie. I didn’t design this system and I’m as delighted by it as you are.

Both are set on willhackett.com with no domain attribute, so they’re never sent to any subdomain. Neither is shared with anyone.

Ignore the prompt for 30 seconds and it answers no for you, then says so. Silence should never count as a yes.

Cookie banners belong in the browser

If your browser sends Do Not Track or Global Privacy Control, you get no prompt and no cookie at all. Neither signal legally binds me in the UK, and the Do Not Track standard was abandoned in 2018, but both are a clear enough no that arguing would be rude.

Years ago I put it to the EU that this whole problem could be solved by moving consent into the browser, where it plainly belongs. I’d like to report that this went well.

The ePrivacy Regulation was proposed in 2017. The Commission announced it was giving up in February 2025, on the basis that nobody expected the co-legislators to ever agree, and the formal withdrawal was published that October. California then passed a single bill, and from January 2027 any browser serving Californians has to offer the setting anyway. Eight years of negotiation, outpaced by one state legislature and a checkbox.

Things I don’t do, and can’t be bothered to start

Check all of that yourself

Don’t take my word for it. Open DevTools and look. This is the only privacy claim on the internet you can audit in about 90 seconds.

The lawful basis, for the lawyers

Counting page views doesn’t identify anyone, so it relies on the statistical purposes exception that PECR gained on 5 February 2026. That needs no consent, but it only holds if I give you a way to object. The switch at the bottom of this page is that way.

The visitor ID is different. A random string that persists across visits counts as personal data under UK GDPR even though I have no idea who you are, and storing it needs permission first under PECR regulation 6. So it rests on your consent, under UK GDPR Article 6(1)(a).

I show the prompt in the UK and the EEA, where asking first is the law. Elsewhere the cookie is set without one, and there the basis is my legitimate interest in knowing whether anyone comes back, which is about as mild as a legitimate interest gets. Either way the switch below turns it off, and a refusal sticks.

One thing I’d rather say than have you find: the page address I record includes anything after the question mark. Most of the time that’s nothing. Sometimes I send a person a link with a parameter on it, and for those I can tell that particular link got opened. It isn’t a general capability and I don’t use it to build a picture of anyone, but it means I shouldn’t claim every URL in that database is anonymous.

Newsletter subscriptions rest on the same consent basis, plus PECR. You give it by typing your email and clicking the confirmation link. Classic double opt-in.

There ought to be a carve-out for this. Nothing elaborate. Something along the lines of: if your website carries no advertising, no third parties and nothing whatsoever to sell, you may write down what you collect and then get on with your life. There isn’t one. The regime that governs an ad network with a legal department also governs me, alone, working out whether a random number in your browser justifies four paragraphs of statute.

It does, apparently. So here we are, citing regulation 6 at each other. All of it applied in good faith by a man whose least-read post is a comedy pre-nuptial agreement he had to delete.

Who else touches your data

Resend sends the newsletter and acts as my data processor under a proper agreement. I use their Ireland region, so the mail goes out from Ireland. Being straight with you about the rest: Resend is a US company and it holds account data, email metadata and operational logs in the United States whichever sending region you pick. An earlier version of this page said your email stayed in the EU. That was wrong, and this is the corrected version.

Bunny serves the site and answers the country lookup that decides whether to show you the cookie prompt. Its logs keep the truncated IP described above and nothing else about you.

Vercel runs the Umami server and Neon hosts the database behind it. Both are configured to EU regions, so the page view data lives in the EU. Their own account, support and operational records may sit elsewhere, because that’s how those platforms work and I can’t pretend otherwise. I don’t own the metal. I do own the software, the database, and every row in it.

Those four are the lot. Nobody else is sent anything, including the company I co-founded.

How long I keep it

Your rights

Depending on the circumstances, UK GDPR gives you the right to ask me to:

In practice the only data I hold about anyone is a newsletter email address, so most of that list resolves to the same short answer. See below.

Withdrawing is deliberately easier than granting. The switch below takes one click, and every newsletter carries a one-click unsubscribe link.

If you think I’m handling this badly, you can report me to the Information Commissioner’s Office at ico.org.uk. They will take you more seriously than you might expect.

Making me delete it

Email gdpr@willhackett.com. You’ll get an automatic reply, because the answer is almost always one of two things.

If you subscribe to the newsletter, click Unsubscribe at the bottom of any email I’ve sent you. Your address comes off my list straight away. It survives a while longer in Resend’s own delivery logs, which are theirs to expire and not mine to purge. On my side nothing is kept behind it, no suppression list, no record that you were ever there.

For the analytics, press the switch at the bottom of this page. That deletes the cookie and tells my server to strip your random ID from every row it’s attached to. The page views survive as counts. The thing connecting them to a browser does not.

If you’ve already cleared the cookie and want the old rows dealt with anyway, I need the ID itself, because it’s genuinely the only handle I have. Open DevTools, go to Application, then Cookies, copy the value of visitor, and email it to me. Without it I’d be searching a table of random numbers for the one that happens to be yours, which is a fair description of the whole point of building it this way.

Your tracking state

Remembering you between visits

Checking…

Counting page views

Checking…

Last updated: 2 August 2026.