Data practices
Privacy
The site collects only what each function needs and applies fixed retention limits.
Contact
Contact submissions are stored in a private database before an administrative email notification is attempted. Raw IP addresses and User-Agent values are not stored with messages.
Contact submissions are deleted after they are more than 365 days old.
Newsletter
Buttondown processes newsletter addresses using its default double opt-in flow. The site does not keep a second local or Supabase copy of newsletter email addresses.
Chat
Chat text is redacted for common identity and token patterns before storage. The current question and up to five previous question-and-answer pairs—at most six user questions in total—are sent to the configured LLM provider to generate an answer.
Anonymous chat records are deleted after 30 days.
Abuse prevention
A request-time HMAC digest of the client IP is used for rate limiting. The raw IP and User-Agent are not written to the application database.
Rate-limit buckets become eligible for deletion after 48 hours and are normally removed by the scheduled cleanup.