Privacy Policy
Last updated:
1. Short version
This is a small personal project with a deliberately minimal data footprint:
- No accounts, no logins, no user profiles.
- No cookies.
- No advertising or analytics trackers.
- No personal information is intentionally collected. If a comment appears to contain any, the whole comment is discarded rather than stored — and you're asked not to include it in the first place (see “Please don't share personal information” below).
2. What we don't do
- We do not use cookies. This is verified directly against this site's own source code and infrastructure configuration, not just asserted — the CloudFront distribution in front of this site is explicitly configured to forward none, and the frontend code contains no cookie-setting logic anywhere.
- We do not run any third-party analytics, advertising, or tracking scripts.
- We do not build profiles of individual visitors, or try to work out who you are from your use of this site.
3. What we do track: anonymous view counts
Each article has a public, anonymous view counter. Opening an article increments one shared counter for that article by one. This counter is not tied to your browser, device, or identity in any way — it's a running total, the same as a hit counter.
4. Feedback (votes and comments)
If you leave feedback on an article (a thumbs up/down, with an optional written comment), we store the vote, the comment text (if any, and only if it passed automated screening — see below), and when it was submitted. Stored feedback carries no IP address, browser fingerprint, account, or any other identifier.
A submission whose comment fails screening is not stored by the site at all: neither the comment nor the vote sent with it. Feedback that goes through normally is not written to the security logs either. The one exception is a submission the firewall blocks before it reaches the site, for example a comment containing code or script, which is logged as described in section 5.
Stored comments are used to improve future articles, and a person reviews that step before anything happens. Once a week, an AI model (see section 7) reads each topic's votes and comments from the past week and suggests one change to how BloggerBear writes about that topic. The suggestion is not applied automatically. The site operator reviews it and either rejects it or approves it. An approved suggestion becomes a piece of Gear, shown on the Stats page with a generated name and a short description of the writing guidance. Comments themselves are never shown on the site. The description is checked again with the same rules a comment goes through (links, personal information and so on) and is hidden if it fails.
5. Firewall and security logs
A web application firewall (AWS WAF) sits in front of this site and its public API. It blocks traffic that looks abusive: too many requests from one address, or requests that look like an attack, such as code or script in a comment. We make a best effort to keep personal information out of its logs:
- Only requests the firewall blocks or flags are logged. Ordinary browsing, and feedback that passes the firewall, are not written to these logs.
- A logged request records when it happened, its source IP address, the address it asked for (which can include an article's ID), which firewall rule acted on it, and the small part of the request that triggered that rule. For a blocked comment, that part can be a fragment of the comment's text.
- Request headers that can be used to fingerprint a browser, such as the user agent, referrer, accepted languages and browser client hints, are redacted before the log is written.
- The logs are kept in AWS CloudWatch Logs (in AWS's Sydney region for the API, and its US East region for the website's firewall) for 14 days, then deleted automatically.
- Only the site operator can read them, and only to investigate abuse or attacks and to tune the firewall. They are not used for analytics, or to identify or profile visitors.
- Separately, AWS's firewall keeps a small sample of recent requests (allowed and blocked) for up to 3 hours, which is how its console shows recent traffic. That sample is held by AWS and expires on its own.
6. Local storage on your device
This site uses a very small amount of your browser's local storage (localStorage) for exactly one purpose: remembering that you've dismissed the site notice banner, so it doesn't reappear on every visit. That preference lives only in your own browser — it is never sent to us, and clearing your browser data resets it.
7. Third-party AI processing
Article summaries and drafts are generated using Amazon Bedrock, a cloud AI service. Publicly available source data (trending repositories, news headlines, market prices) is sent to that service to generate content. The only visitor data ever sent there is comment text, for two purposes: to check a new comment (for personal information, abuse, spam and attempts to instruct the software) before deciding whether to store it, and, once a week, to read the stored comments and suggest writing guidance for the operator to review (see section 4). Votes are sent only as totals.
8. Data retention and deletion
Because this is a disposable, single-operator portfolio project (see the Terms of Service), the infrastructure behind everything described above — including this policy's own hosting — may be reset, rebuilt, or permanently deleted at any time, without notice. There is no guarantee any particular piece of content, feedback, or data will persist.
Stored feedback is kept until it is deleted by the operator or the project is reset. Suggestions built from it that the operator rejects are deleted after about a week. Nothing written from your comments, and no new Gear, is published without human review.
9. Changes to this policy
This policy may change as the project changes. Check back here for the current version.
10. Contact
Questions about this policy can be raised via the project's GitHub repository.