Legal

Privacy

What UXLab stores about you, what it does not, and who it sends anything to.

This is a personal site. Here is what it stores about you, what it does not, and who it sends anything to. Every statement below is true of the code as it runs; if the code changes, this page changes with it and the date above moves.

Reading

You can read everything marked public without an account. Reading is counted by Fathom, a privacy-first analytics service: it counts page views without cookies, without identifying you, and without following you to other sites. There is no advertising here and nothing about you is sold.

Accounts

Accounts are by invitation only. If your address has not been invited, you cannot create an account, and nothing is stored when you try. Sign-in is passwordless — a magic link or a one-time code sent to your email, a code sent to your phone by SMS, or your GitHub account. There is no password to store, so none is.

When you sign in, the site keeps:

  • your name, email address, and profile image if the sign-in method supplies one, plus your phone number if you sign in that way;
  • your role — member, or owner;
  • a session: a token in a cookie, the IP address and browser it was made from, and when it expires;
  • for GitHub sign-in, the link between your account here and your GitHub account;
  • the verification codes and links it sent you, until they expire.

That is the whole list. It lives in a database hosted by Turso, for a site that runs on Railway.

If your invitation is withdrawn, your account stops working but the record is kept, so that re-inviting you restores it. Ask through the contact page to have it removed instead.

Email and SMS

Email and SMS are used for one thing: sending you the link or code you asked for when signing in. Email goes through Resend; SMS goes through Twilio. Neither is used to send you anything you did not just request.

The newsletter form on the home page does not reach a server at all today: it saves the address in your own browser's storage and nowhere else. Nothing is sent, and nothing arrives here.

Maps and your location

Three pages load Google Maps: the ZIP locator, the maps example, and the find-a-provider demo. Google's script runs on those pages only, and on the ZIP locator only once you ask it to. If you allow the ZIP locator to use your location, the coordinates are used for one lookup — turning them into a ZIP code — and are not stored anywhere. Google's own privacy policy applies to what its script does.

Files

Only the owner can upload files (images for the site). They are stored with the storage provider the deployment is configured for — local disk, Amazon S3, or Cloudinary — and are not yours in any case.

Asking

For anything about what is held about you, use the contact page. There is one person behind this site, and that person answers.