Privacy Policy
Updated:
Last updated: 27 August 2026
This policy explains what happens to information about you when you read JS Ledger. It is written to meet Articles 13 and 14 of the General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”).
The short version
JS Ledger is a static website. It has no accounts, no forms, no advertising, no tracking cookies, and no profiling. The only personal data involved in serving you a page is what any web server unavoidably receives — chiefly your IP address — plus anything you choose to put in an email to us.
The detail below explains that properly, because a summary is not a legal basis.
Who is responsible
The controller for the processing described here is:
JS Ledger (Jonah Vail) Email: contact@jsledger.com
Because of the nature and scale of this processing, no data protection officer is required under Article 37, and none has been appointed. Email reaches the person responsible directly.
What is processed, and why
1. Technical data from serving the page
When your browser requests a page, our hosting provider receives and processes the information any HTTP request contains: your IP address, the URL requested, the time of the request, the HTTP status returned, your user agent string, and the referring URL when your browser sends one.
- Purpose. Delivering the page you asked for, protecting the site against denial-of-service traffic and abuse, and diagnosing errors.
- Legal basis. Article 6(1)(f) — our legitimate interest in operating a secure and available website. We consider this proportionate because the data is not combined with anything else, is not used to identify you, and is not used to build a profile.
- Retention. These records live with our hosting provider and are retained according to its own log retention policy, which is short and measured in days. We do not export, copy, or keep our own separate archive of them.
2. Audience measurement
If analytics is enabled on this site, it is Cloudflare Web Analytics, which is cookieless: it sets no identifiers on your device, does not fingerprint your browser, and reports only aggregate figures such as page views and referrers. No individual reader can be singled out from it, by us or by anyone else.
- Purpose. Knowing which articles are read, so that time goes into subjects people actually use.
- Legal basis. Article 6(1)(f) — our legitimate interest in understanding aggregate readership. Because the measurement neither stores nor accesses information on your device, it does not require consent under Article 5(3) of the ePrivacy Directive.
- Retention. Aggregate statistics only. Nothing personal is retained.
3. Email you send us
If you write to contact@jsledger.com, we process your email address, your
name if you give it, and whatever the message contains.
- Purpose. Reading and answering you, and — if you send a correction — fixing the article.
- Legal basis. Article 6(1)(f), our legitimate interest in corresponding with readers; where your message concerns a request you have made of us, Article 6(1)(b) also applies.
- Retention. Up to 24 months after the exchange ends, then deleted. Ask us to delete it sooner and we will.
What is not processed
To be explicit, this site does not: set cookies of any kind; operate user accounts or logins; run advertising or an ad network; embed third-party comments, videos, social widgets, or tag managers; load fonts or scripts from a third-party CDN (fonts are served from this domain); build profiles; make automated decisions producing legal effects under Article 22; sell, rent, or share personal data with anyone for their own purposes.
Site search runs entirely inside your browser against an index downloaded with the page. What you type into it is never transmitted anywhere.
The only thing stored on your device is a single localStorage entry recording
your choice of light or dark theme, written only if you use the theme toggle.
It is not a cookie, it is never sent to a server, and it contains no identifier.
See the Cookie Policy.
Processors and international transfers
Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) hosts this site, serves it through its content delivery network, and provides the optional cookieless analytics described above. It acts as our processor under Article 28 on the basis of its Data Processing Addendum.
Because the network is global, technical data may be processed on servers outside the European Economic Area, including in the United States. Those transfers are covered by the European Commission’s Standard Contractual Clauses incorporated in that addendum, together with the supplementary measures set out there.
We use no other processor. There is no other recipient of your data.
Your rights
Under the GDPR you have the right to: obtain confirmation of whether we process data about you and a copy of it (Article 15); have inaccurate data corrected (Article 16); have data erased (Article 17); have processing restricted (Article 18); receive data you provided in a portable format (Article 20); and object at any time to processing based on our legitimate interests, including the technical and analytics processing described above (Article 21).
To exercise any of these, email contact@jsledger.com. We answer within one month, as Article 12(3) requires. Exercising them is free, and we will not treat you differently for it.
You also have the right to lodge a complaint with a supervisory authority, under Article 77 — normally the authority in the EU or EEA country where you live or work. You do not need to contact us first.
Note one practical limit: for the technical data in section 1 we hold no way of linking an IP address to you. Where we genuinely cannot identify you from the data, Article 11(2) applies and we may be unable to act on an access or erasure request without additional information from you that would make identification possible.
Security
The site is served over HTTPS only. It is static output: there is no database, no application server, and no code executing on the host when you request a page, which removes most of the surface where reader data could be exposed in the first place.
Children
This site is written for professional software developers and is not directed at children. We do not knowingly process the data of anyone under 16.
Changes to this policy
When this policy changes materially, the date at the top changes with it and the change is described in the site’s public record of decisions. Adding any third-party embed would be such a change, and this page would say so before it happened.
Questions about anything above: contact@jsledger.com.