Last reviewed: 2026-09-26

This is a static site. There is no account, no login, and no form anywhere on it. Below is what is set when you load a page, what stays on your own machine, and what leaves your browser.

Cookies

The site sets no cookies. No JavaScript here calls document.cookie, and the server sends no Set-Cookie header, so nothing on this domain can create one for you.

Two preferences are kept in your browser’s localStorage instead. They stay on your device, are readable only by scripts on this origin, and are never sent to me with a page view:

  • site-style - the theme you pick with the style switcher.
  • slides-presenter - whether presenter mode is on, in the slide viewer for a recorded talk.

Clearing site data for this domain in your browser removes both.

Analytics

Every page loads a small script from https://analytics.jaredrhodes.com/script.js. That is a self-hosted instance of Umami running on my own domain, not a hosted analytics vendor.

Umami is cookieless. It writes no cookie and leaves no durable identifier in your browser. Each page view records the page path, the site you came from, a coarse browser class (browser and operating system family), and your country, which is derived from the connection rather than from anything stored about you. The connection address is used to derive that country and to avoid counting the same view twice; it is not kept as a profile. Umami stores no personal identifiers, creates no profile, does not track you across other sites, and the data is not sold or shared. It exists so I can tell which posts get read.

Third-party embeds

Two things on this site load from a host I do not control:

  • The upcoming events page loads a Sessionize script from sessionize.com to render the current schedule. Opening that page contacts Sessionize, which may set its own cookies under its own domain. Its data handling is described in Sessionize’s privacy policy. The speaking page only links to a Sessionize profile and loads nothing from them.
  • One post, Interview with The Cube, embeds a YouTube video. The player is not requested until you scroll it into view, and at that point it contacts Google, which may set YouTube cookies in your browser. Nothing reaches YouTube before that.

Webmentions and pingbacks

Every page in the HTML head advertises this site’s Webmention and Pingback endpoints, which point at https://webmention.io/jaredrhodes.com/webmention and https://webmention.io/jaredrhodes.com/xmlrpc. Any tool that reads those links can send the URL of the page you are on to webmention.io and get a reply describing who linked to it, so webmention.io can see which pages of this site are pinged and by whom.

This site never sends a webmention or pingback out on its own, and it does not publish the replies it receives. If you would rather a page you read not be announced elsewhere, there is no opt-out I can offer: the endpoints are in the site configuration and can be removed if I decide the trade is not worth it.

Media and images

Photos, videos, and slide images in posts are served from this domain. There is no asset CDN and no advertising network anywhere on the site.

Requests for those files pass through a Referer-based hotlink guard. A request whose referer is neither this site nor a feed reader is refused with a 403, and the response varies on Referer, which splits shared caches per referring page. Requests with no Referer at all are deliberately allowed, so feed readers and privacy tools that strip the header keep working.

The exception is a set of older posts from 2018 to 2021 that hotlink screenshots still hosted on docs.microsoft.com. Opening those posts loads those images from Microsoft rather than from here, so Microsoft sees your IP address and the page you came from. Everything else is first-party.

Search runs entirely in your browser. The index is a set of static files generated when the site is built and served from this domain, so what you type is matched locally. No search term is sent to me or to any third party. Pressing / on any page moves focus to the search box.

Error tracking

Error reporting is configured but switched off. The DSN setting in the site configuration is empty, so no error-tracking code is served to your browser today. If it is ever enabled, the Sentry-compatible SDK would be loaded from Sentry’s CDN and would report the error message, the stack trace, the page URL, browser and operating system details, and your IP address to a GlitchTip instance I host. Enabling it would also require a server change, because the origins it needs are documented in the Content-Security-Policy but left inactive.

Server logs

The web server writes an access log entry for every request, containing your IP address, the user agent, the page requested, the referring page, and the forwarded address chain. Those logs live on the machine that serves this site and are used to diagnose errors and abuse. They are kept separate from the analytics counts described above.