Privacy policy.
Plain-English version of what this site collects, why, and what you can do about it. The legal version is below.
- → The newsletter form collects your email so I can send the newsletter. That's it.
- → The contact form collects your name, email, and message so I can reply.
- → Google Tag Manager loads on every page; from there I run Google Analytics 4 for aggregate traffic stats.
- → I don't sell your data. Ever. No "data partners," no audience exchanges.
- → Want your data deleted? Email via the contact form and I'll do it within 30 days.
What I collect
Information you give me
- Newsletter signup — email address only. Stored by my email service provider.
- Contact form — name, email, message body, and the topic radio button you selected. Stored by my form provider (currently Resend via Cloudflare Pages Functions).
- Course purchase (if applicable) — name, email, and payment method handled entirely by Stripe. I see name and email; I never see your card number.
Information collected automatically
Standard web analytics: IP address (truncated by GA4), approximate location (country/region — not street address), browser type, device type, referring URL, pages visited, time spent, and outbound link clicks. This data is aggregated and anonymized.
How I use it
- Send the newsletter to people who asked for it.
- Reply to messages you send via the contact form.
- Decide which posts are working and which to rewrite or kill.
- Improve site performance (page speed, broken links, etc.).
- Comply with the law if served with a valid subpoena or equivalent.
I do not use your data for behavioral retargeting, audience selling, ad networks, or any "data enrichment" service.
Cookies and tracking
The site uses the following:
- Google Tag Manager (
GTM-WCQ8BCT) — a script loader that runs the analytics + tag stack below. Sets a_gacookie chain. - Google Analytics 4 — page views, sessions, events, outbound clicks. Cookie:
_gaand_ga_*. Retention: 14 months. - Cloudflare — performance / DDoS protection. Sets
__cf_bmsession cookie (30 min) per their bot-management. - Pagefind — on-site search runs locally in your browser; no tracking.
You can opt out of GA4 via the Google Analytics opt-out browser add-on, or by blocking the GTM script in your browser. The site works without it.
Sharing
I don't sell, rent, or trade your data. I do share it with the following service providers — narrowly, only what each one needs to function:
- Email service provider (newsletter delivery)
- Cloudflare (hosting, DDoS, edge functions, form submissions)
- Google (Tag Manager + Analytics)
- Stripe (payments, if you purchase)
- Resend (transactional email + form notifications)
If I ever sell the business or transfer it to a successor, your data moves with the business. You'd be notified before that happens.
SiteWide MCP
SiteWide MCP is a connector that lets your own AI assistant (such as Claude) read your marketing data. It only ever connects to the tools you connect yourself on your SiteWide account page, and only reads data to answer requests you make through your assistant. This section covers what that involves.
Your account
- Account details — your email address (to sign you in with a one-time link and send receipts), the sites you add, your plan, and a monthly count of how many requests you've made.
- Your connector token — stored only as a one-way hash, so it can't be read back, even by me. If you lose it, you get a new one.
- Apps you connect — an app you connect by signing in (Claude, Claude Code, Cursor) gets its own access to your account. Each one is listed on your account page, and you can revoke any of them there without affecting the others.
- Billing — handled entirely by Stripe. I see your name, email and subscription status, never your card number.
Tools you connect
Each tool is connected by you and can be removed at any time, from your account page or by asking me. Your credentials are encrypted (AES-256-GCM) before they're stored on Cloudflare, are never logged, and are only used to fetch the data you ask for:
Every connection below is read-only unless it says otherwise, and each one only reaches the accounts the login or key you connect can already see.
- Google (Search Console, AdSense, Analytics, Ads, and, once they're offered, Tag Manager, Business Profile, YouTube Analytics and Merchant Center) — through Google's own consent screen, or by adding SiteWide's service account as a viewer on your property. Details in the next section.
- Bing Webmaster Tools — through Microsoft's consent screen for Bing, or an API key you generate in Bing Webmaster Tools. Reads search performance and crawl statistics for the sites verified in your Bing account.
- Ahrefs — an API key you generate in your Ahrefs account.
- Semrush — an API key from your Semrush account. Reads domain, keyword and backlink reports, and each request spends your own Semrush API units.
- WordPress — an Application Password you create or approve in your own WordPress admin. By default it's only used to read your posts' SEO metadata. It changes SEO fields (titles, descriptions, canonicals, schema type, image alt text) only on sites you've explicitly switched to writable, only after showing you the before-and-after, and never touches the body of a post. Revoke it in WordPress at any time.
- Microsoft Advertising — through Microsoft's own consent screen. Reads the ad accounts your Microsoft login can see and their spend, clicks, conversions, campaigns and search terms. Stored: the access grant, your Microsoft Advertising user email, and the names of the ad accounts found when you connected. It never changes a campaign or a bid.
- Meta Ads (Facebook and Instagram) — through Facebook Login, with the
ads_readpermission only. Reads your ad accounts' spend, reach, results, campaigns and ad-level performance. Stored: the access token, your Facebook name and app-scoped user ID, and your ad accounts' names and currencies. Meta's access expires after about 60 days, and you sign in again. If you remove SiteWide in your Facebook settings, or ask Meta to delete your data, Meta notifies SiteWide and the stored token and details are deleted automatically; Meta gives you a confirmation code you can check. - LinkedIn Ads — through LinkedIn's own consent screen, with read-only ad and reporting permissions. Reads the ad accounts your LinkedIn login has a role on and their spend, clicks, conversions, leads and campaigns.
- TikTok Ads — through TikTok for Business's own authorization screen. Reads the ad accounts you authorize and their spend, clicks, conversions and campaigns.
- HubSpot — through HubSpot's own consent screen. Read-only: it reads counts of your contacts, companies and deals and where new contacts came from, your deals by pipeline stage including their amounts and the totals per stage, won and lost deals, your forms and their submissions, and your marketing email statistics. It never changes anything in HubSpot.
- Mailchimp — through Mailchimp's own consent screen. Reads campaign reports (sends, opens, clicks, bounces, unsubscribes, and store revenue if a store is connected) and audience size and growth. Stored: the access token, your account's data center and its name. It never reads individual subscribers' details and never sends anything.
- Klaviyo — through Klaviyo's own consent screen, with read-only campaign, flow and metric permissions. Reads campaign and flow performance, including attributed revenue. It never reads individual profiles and never sends anything.
- Public data — PageSpeed Insights, the Chrome UX Report, the Internet Archive, and SiteWide's own crawler, which reads the public pages of sites on your account. None of these need anything from you.
Disconnect any of them from your account page at any time. Where the provider lets SiteWide revoke the grant (Google, HubSpot, Klaviyo, TikTok, Meta, WordPress), disconnecting does that too; where it doesn't (Bing, Microsoft Advertising, LinkedIn, Mailchimp), SiteWide deletes its copy and the account page tells you where to remove the app on the provider's side.
You also choose which of your sites SiteWide may access, with an on/off switch per site on your account page. Switch any site off at any time and every SiteWide tool stops reading it.
Data fetched from these tools isn't stored: it goes straight back to your assistant. It's never sold, never used for advertising, and never used to train AI models. How your assistant handles it after that is governed by that assistant's own privacy policy.
Your Google data
If you connect your Google account, here's exactly what that gives SiteWide MCP access to and what happens to it.
What it can access
Only the Google products you connect, each with its own permission on Google's consent screen. You can untick any of them there:
- AdSense (
adsense.readonly) — your AdSense earnings reports. - Google Ads (
adwords) — campaign, keyword and search-term performance for the accounts you choose. SiteWide MCP only reads Google Ads data; it never creates, changes or pauses anything. - Google Analytics (
analytics.readonly) and Search Console (webmasters.readonly) — traffic and search performance reports for your properties. - Tag Manager (
tagmanager.readonly) — your containers and the tags, triggers and variables in their published versions. - Business Profile (
business.manage) — your locations, their performance (calls, direction requests, website clicks, views) and reviews. Google only offers this one permission, which would also allow edits; SiteWide MCP only reads and never replies to a review or changes a listing. - YouTube Analytics (
yt-analytics.readonly) — your channel's views, watch time, subscribers and traffic sources. - Merchant Center (
content) — your products' approval status and their clicks and impressions on Google. Google only offers this one permission, which would also allow edits; SiteWide MCP only reads and never changes a product or a feed. - Your Google account's email address, so the account page can show which Google account is connected.
How it's used
Google data is used only to answer the requests you make through the connector: your AI assistant asks for a report, SiteWide MCP fetches it from Google and returns it to that assistant. Nothing else. Specifically, Google user data is never:
- sold, rented or shared with anyone other than the AI assistant you connected;
- used for advertising, including retargeting or building advertising profiles;
- used to develop, improve or train AI or machine-learning models;
- read by a person, unless you ask me to for support, it's needed for security, or the law requires it.
SiteWide MCP's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Storage and deletion
SiteWide MCP stores one thing from Google: the access grant (a refresh token) that lets it fetch reports on your behalf. It's encrypted (AES-256-GCM) before it's written to Cloudflare's storage, and it's never logged. The reports themselves aren't stored — they're fetched when your assistant asks and passed straight back to it.
Disconnect at any time from your SiteWide account page, which revokes the grant with Google and deletes it immediately, or from your Google account permissions. You can also ask me to delete it through the contact form, and I'll do it within 30 days.
Your rights
Regardless of where you live:
- Access — request a copy of any data I hold about you.
- Correction — fix anything that's wrong.
- Deletion — remove it entirely. Mailing-list unsubscribe is one click.
- Portability — get a machine-readable export.
- Opt-out — turn off analytics or marketing emails any time.
EU/UK/EEA residents have additional rights under GDPR. California residents have additional rights under CCPA/CPRA. Either way, the request mechanism is the same: send a note via the contact form and I'll process it within 30 days.
Data retention
- Newsletter list — kept until you unsubscribe, then deleted within 60 days.
- Contact-form messages — kept for 24 months in case the conversation resumes, then deleted.
- Analytics — 14 months, then anonymized further.
International transfers
The site is hosted on Cloudflare's global network and data may pass through servers in the US, EU, or elsewhere. Where required (GDPR), my providers use standard contractual clauses or equivalent transfer mechanisms.
Children's privacy
This site isn't directed at anyone under 13. I don't knowingly collect data from children under 13. If you believe I have, contact me and I'll delete it.
Changes
I'll update this page whenever the data practices materially change, and bump the "Last updated" date at the top. For email-list members, I'll send a notice if anything changes that affects you directly.
Contact
Questions, requests, complaints? Use the contact form and I'll get back within 48 hours.