Privacy & Cookies
I run this network myself. No department, no legal team, no privacy counsel in a corner office. What follows is what I actually collect, why I need it, and how to make me stop. You want the version with cross-jurisdictional appendices, go hire a lawyer. This is the direct one.
The short version
Anonymous analytics so I know what's worth writing. An email list so I can reach you without renting that line from a platform that'll yank it back the minute you stop being useful to their numbers. That's the whole stack. Analytics are cookieless and self-hosted, so nothing about you leaves this server. I never see your card number. I don't sell your data, not to anyone, not ever. Email me at contact@nicheof.one and I'll show you everything I've got, or I'll delete it.
Who's asking
The person responsible for your data here, the data controller in GDPR terms, is J.D. Forrest, operating as Niche of One, an independent media operation based in the United States. Questions, requests, or complaints go to contact@nicheof.one. You're emailing me, not a ticket queue.
What I collect, and why
Analytics. I run Umami, self-hosted on my own box. Not Google, not anybody else — the numbers never leave my server, because there is nobody to send them to. Rough aggregate stuff: page views, approximate location (country level), device type. It is watching whether a guide landed, not watching you. It sets no cookies at all, ever, for anyone, and it honours Do Not Track: turn that on in your browser and it does not count you.
Your email, only if you hand it over. If you subscribe to the newsletter, I store your email address so I can send it to you. It lands on my own list, not a rented one. I use it to send you writing. You can leave with one click any time.
Server logs. Like every website, my host keeps basic access logs (IP address, browser, timestamp) for a short window. Security and "keep the lights on," not a profile on you.
Your settings. Your theme, text size, motion preference, and which rooms you've visited are saved in your browser's local storage. On your device, never sent to me. Clear your browser data and it's gone.
Cookies, specifically
Nothing on this site sets a tracking cookie. Not one. The analytics are cookieless by design, so there is no tracker to switch on or off. What the site does store is local storage — your theme, your font size, whether you have dismissed a banner — and that never leaves your device and never gets sent anywhere. If you are signed in, there is a session cookie, which is just how staying signed in works. The two pages with a Gumroad checkout button on them, the Shelf and the Skills pack, load Gumroad's own script when you touch the page, and Gumroad sets a cookie of its own at that point. That is their checkout, not my analytics, and it happens on those two pages only. Everywhere else on this site, nothing is fetched from them and nothing is set.
Who else touches your data
I'm independent, but I run on tools other companies own. When you use part of the site, that tool handles its slice of your data under its own policies:
- Nobody. Analytics are self-hosted; the traffic numbers never reach a third party.
- Gumroad, runs the store and handles checkout. If you buy something, Gumroad processes your payment. I never see or store your card.
- Resend, delivers the letters and holds the mailing list. If you are subscribed, your email address sits with them.
- Substack, hosts one of the publications and the recommendation page. It is no longer the newsletter rail.
- Amazon Associates, some outbound links are affiliate links (more on that below).
- The radio streams GZS Radio 197.7; standard streaming connection logs, nothing remarkable.
- Hosting and email keep the site online and route my mail.
Affiliate links
Some links on this site are affiliate links. Amazon, other creators' products, tools I actually run on. If you buy through one, I earn a small commission. Costs you nothing extra. I don't point you at garbage just because it pays. Buying through them is how the free part of this network keeps the lights on without running ads or paywalling everything.
Why I use any of this
To make the work better and keep food on the table. Analytics tell me what landed and what nobody read. The email list is a line I own, not one I'm renting from a platform that'll charge me double next year to reach my own readers. The affiliate links and products are how this independent operation pays for itself. I'm not pretending this is a public service. It's a small publishing operation run by one person, and the money has to come from somewhere.
The legal basis (for the GDPR crowd)
If you're in the EU or UK, here's the lawful basis for each thing:
- Consent, for sending you the newsletter. Freely given; pull it back any time.
- Legitimate interest, for cookieless aggregate analytics and short-lived security logs. Minimal data, no profiling, no third party.
- Contract, if you buy something, the data needed to actually deliver it (handled by Gumroad).
How long I keep it
- Your email: until you unsubscribe or ask me to delete it.
- Analytics: aggregate counts on my own server. No third party holds them, and you are not identifiable in them.
- Server logs: a short rolling window, then they roll off.
- Your settings: live in your browser until you clear them. I never hold them.
- Underground posts, DMs, and your profile: live as long as your account does. Delete a single post any time. Delete the whole account and every post, message, and profile field is gone immediately, not staged for later.
- What survives a deletion, and why: a door block, so somebody barred from the site cannot clear it by deleting their account. A moderation or impersonation audit record, because the person a record is about should not be able to erase it. And the money trail: what you were charged, and anything owed out to you. Nothing in that set is your writing, your messages, your profile, or your uploads. Those are gone.
Where your data goes
I'm in the United States, and so are most of the tools I run on. If you're visiting from the EU or UK, your data may be processed in the US. Those providers carry their own safeguards for international transfers: standard contractual clauses and the EU-US Data Privacy Framework. What I personally hold, I keep to a minimum.
California (CCPA)
California residents have the right to know what I collect, to delete it, and to opt out of any "sale" or "sharing" of personal information. I don't sell or share your data, so there's nothing to opt out of. Same email handles it. I won't treat you differently for asking.
Your rights
Wherever you live, and especially if the GDPR (EU/UK) or CCPA (California) covers you, you can ask me to:
- Show you what data I hold on you.
- Correct it or delete it.
- Get a copy to take elsewhere.
- Stop emailing you (or just hit unsubscribe, every email has the link).
- Walk back your cookie consent (footer → Cookie settings → Reject).
Email contact@nicheof.one and I'll handle it. No forms, no ticket queue. It's just me. If you're in the EU or UK and think I've botched something, you can complain to your local data protection authority. I'd rather you tell me first.
Minors
This network is for adults. Some of it is weird, some of it is occult, some of it will make your grandmother frown. It isn't aimed at anyone under 16, and I don't knowingly collect data from minors.
If this changes
It changes, I update the date at the top and say so here. Anything significant goes in the newsletter. You're not waking up one morning to find out I sold your email to a marketing firm, because that's not the kind of operation this is.
Plain-language notice from an independent operation. Written to be read, not to cover every legal theory in every jurisdiction. Not legal advice.