Privacy

What this site knows about you

Not much, and this page says exactly what — rather than claiming zero and quietly running server logs like everyone else.

The short version

You can read everything here without an account and without being tracked. If you create an account, this site stores your email address, an optional display name and a scrambled version of your password — nothing else about you. You can delete all of it yourself, at any time, from your account page.

If you just read

No analytics or tracking package is installed — not Google Analytics, not Plausible, not a Facebook pixel, nothing. No advertising network is present. The typefaces are served from this site's own server rather than from Google Fonts, so loading a page here doesn't announce your visit to a third party. There are no embedded videos, no social widgets and no third-party scripts.

Server access logs.Like essentially every web server, the one running this site records each request it receives: the IP address it came from, the time, the page requested, and the browser's user-agent string. An IP address can count as personal data, which is why it's named here rather than glossed over. These logs exist to keep the site running and to spot abuse. They are not used to build a profile of you and are not sold or shared.

They are held in a small rotating buffer on the server — about 30 megabytes per service, after which the oldest entries are discarded automatically. That is a size limit rather than a time limit, so on a quiet site a line may survive a while and on a busy day it will not.

If you have an account

Creating an account stores, and stores only:

  • Your email address. It identifies the account and is how a password-reset link would reach you. It is never shown to anyone else.
  • A display name, if you set one. Optional, shown only back to you in the corner of the page. There is nowhere on this site where one member is visible to another.
  • A scrambled version of your password — hashed with Argon2, which is one-way. Nobody here can read your password, and that includes us.
  • The date you signed up, and whether you signed up with a password or another method.
  • A row for each device you are signed in on, so that signing out genuinely ends the session rather than just forgetting it locally.

There is no profile, no activity history, no record of what you read. The site does not know which pages an account has visited, because the access log above is not linked to accounts.

Cookies

This site sets one cookie, and only once you sign in: lrtm_session, which is what keeps you signed in. It is marked HttpOnly, so scripts in your browser cannot read it, and it lasts seven days or until you sign out, whichever comes first.

There is no cookie banner because there is nothing to consent to: a cookie that exists solely to deliver a service you asked for — staying signed in — is exempt. If an analytics or advertising cookie is ever added, a banner arrives with it, and this paragraph changes.

When something breaks

If the server hits an unexpected error, a report goes to Sentry, an error-tracking service, so it can be found and fixed. Those reports are deliberately configured to exclude request bodies, cookies and headers — the parts that would otherwise carry a password, a session or a reset link.

Who else is involved

The site runs on a virtual server rented from Amazon Web Services, in London, so everything described above physically sits on that machine and in that company's backup storage, in the UK. HTTPS certificates are issued automatically by Let's Encrypt. Unexpected server errors are reported to Sentry, an error-tracking service, using its EU data region. Those are the only three third parties involved — nothing else receives anything about you, and no other company is in the path of a page view.

How long it is kept

Account data is kept until you delete your account. Then it is deleted from the live database immediately — the row is removed, not hidden or flagged.

Backups are the honest exception. The database is backed up nightly, and those backups are kept for up to 90 days; disk-level snapshots are kept for 7. So for a period after you delete your account, your email address still exists inside a backup file. Those backups are never read except to recover from a failure, and they age out on their own. Selectively editing a backup would defeat the point of having one, so the honest answer is that erasure is immediate in the live system and completes within 90 days everywhere.

Your rights

UK GDPR gives you the right to:

  • See what is held about you. For an account, that is the list above, and your account page shows it.
  • Correct it. Your email and display name are yours to change.
  • Delete it. There is a button for this on your account page — you do not need to ask anyone, and it happens immediately.
  • Complain.If you think this site has mishandled your data you can raise it with the Information Commissioner's Office at ico.org.uk, and you do not have to come here first.

Who is responsible

This site is run by Emma Andrew, who is the data controller for the information described here. Data requests go to hello@longroadtomaybe.com.

Changes

This page describes the site as it actually works, and it is updated in the same change as the thing it describes rather than afterwards. Last reviewed 6 August 2026.

This is a plain-English description of how the site works. It is not legal advice and it has not been reviewed by anyone qualified to write a privacy policy.