Legal · Last updated September 24, 2026

Privacy policy.

Plain-English version of what this site collects, why, and what you can do about it. The legal version is below.

TL;DR
  • → The newsletter form collects your email so I can send the newsletter. That's it.
  • → The contact form collects your name, email, and message so I can reply.
  • → Google Tag Manager loads on every page; from there I run Google Analytics 4 for aggregate traffic stats.
  • → I don't sell your data. Ever. No "data partners," no audience exchanges.
  • → Want your data deleted? Email via the contact form and I'll do it within 30 days.

What I collect

Information you give me

Information collected automatically

Standard web analytics: IP address (truncated by GA4), approximate location (country/region — not street address), browser type, device type, referring URL, pages visited, time spent, and outbound link clicks. This data is aggregated and anonymized.

How I use it

I do not use your data for behavioral retargeting, audience selling, ad networks, or any "data enrichment" service.

Cookies and tracking

The site uses the following:

You can opt out of GA4 via the Google Analytics opt-out browser add-on, or by blocking the GTM script in your browser. The site works without it.

Sharing

I don't sell, rent, or trade your data. I do share it with the following service providers — narrowly, only what each one needs to function:

If I ever sell the business or transfer it to a successor, your data moves with the business. You'd be notified before that happens.

SiteWide MCP

SiteWide MCP is a connector that lets your own AI assistant (such as Claude) read your marketing data. It only ever connects to the tools you connect yourself on your SiteWide account page, and only reads data to answer requests you make through your assistant. This section covers what that involves.

Your account

Tools you connect

Each tool is connected by you and can be removed at any time, from your account page or by asking me. Your credentials are encrypted (AES-256-GCM) before they're stored on Cloudflare, are never logged, and are only used to fetch the data you ask for:

Every connection below is read-only unless it says otherwise, and each one only reaches the accounts the login or key you connect can already see.

Disconnect any of them from your account page at any time. Where the provider lets SiteWide revoke the grant (Google, HubSpot, Klaviyo, TikTok, Meta, WordPress), disconnecting does that too; where it doesn't (Bing, Microsoft Advertising, LinkedIn, Mailchimp), SiteWide deletes its copy and the account page tells you where to remove the app on the provider's side.

You also choose which of your sites SiteWide may access, with an on/off switch per site on your account page. Switch any site off at any time and every SiteWide tool stops reading it.

Data fetched from these tools isn't stored: it goes straight back to your assistant. It's never sold, never used for advertising, and never used to train AI models. How your assistant handles it after that is governed by that assistant's own privacy policy.

Your Google data

If you connect your Google account, here's exactly what that gives SiteWide MCP access to and what happens to it.

What it can access

Only the Google products you connect, each with its own permission on Google's consent screen. You can untick any of them there:

How it's used

Google data is used only to answer the requests you make through the connector: your AI assistant asks for a report, SiteWide MCP fetches it from Google and returns it to that assistant. Nothing else. Specifically, Google user data is never:

SiteWide MCP's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Storage and deletion

SiteWide MCP stores one thing from Google: the access grant (a refresh token) that lets it fetch reports on your behalf. It's encrypted (AES-256-GCM) before it's written to Cloudflare's storage, and it's never logged. The reports themselves aren't stored — they're fetched when your assistant asks and passed straight back to it.

Disconnect at any time from your SiteWide account page, which revokes the grant with Google and deletes it immediately, or from your Google account permissions. You can also ask me to delete it through the contact form, and I'll do it within 30 days.

Your rights

Regardless of where you live:

EU/UK/EEA residents have additional rights under GDPR. California residents have additional rights under CCPA/CPRA. Either way, the request mechanism is the same: send a note via the contact form and I'll process it within 30 days.

Data retention

International transfers

The site is hosted on Cloudflare's global network and data may pass through servers in the US, EU, or elsewhere. Where required (GDPR), my providers use standard contractual clauses or equivalent transfer mechanisms.

Children's privacy

This site isn't directed at anyone under 13. I don't knowingly collect data from children under 13. If you believe I have, contact me and I'll delete it.

Changes

I'll update this page whenever the data practices materially change, and bump the "Last updated" date at the top. For email-list members, I'll send a notice if anything changes that affects you directly.

Contact

Questions, requests, complaints? Use the contact form and I'll get back within 48 hours.

↵ ↵ to see all results esc esc to close