// Legal
The legally-required version is below, but the short answer: I don't sell your data, I don't run third-party trackers, and I don't email you unless you opted in. The rest is detail.
This site collects: anonymized analytics (Plausible — no cookies, no fingerprinting), your email onlyif you opt into the newsletter, and the contact form fields you submit if you submit them. That's it. I don't run Facebook, TikTok, or LinkedIn pixels. I don't load Google Tag Manager. I don't sell, rent, or barter your data.
Three categories, all opt-in or anonymized:
Analytics are used for one purpose: deciding what to write next. Newsletter emails are used to send the newsletter. Contact form submissions are used to reply to you and, if relevant, to send a follow-up SOW. None of these are used for retargeting, profiling, or sold to anyone.
The vendors involved in running this site, and what each one sees:
I have data processing agreements (DPAs) with each. Nobody else sees anything.
This site sets zero third-party cookies. The only first-party storage is a localStorage key remembering whether you've dismissed the cookie banner — which I don't have one of, so the key doesn't get set either. Plausible doesn't use cookies. There are no fingerprinting libraries. There is no GTM container.
Under GDPR, CCPA, and most of the alphabet of privacy regulations, you have the right to:
To exercise any of these, email privacy@yerainabreu.com. I respond within 5 business days.
Newsletter emails: kept until you unsubscribe, then deleted within 30 days. Contact form submissions: kept in my inbox for the duration of any related engagement, plus 24 months for tax-record purposes, then deleted. Analytics: aggregated anonymous data is kept indefinitely; nothing in it can identify you.
This site is served over HTTPS, sits behind Cloudflare with DDoS protection, and has no admin login on the public domain. Newsletter and form data are encrypted in transit and at rest. I use a password manager, hardware 2FA, and full-disk encryption on every device. I am not SOC 2 certified — I'm one person; the audit cost would be more than the website earns.
Privacy questions or requests: privacy@yerainabreu.com. Postal address: Yerain Abreu LLC, PO Box 318, Mount Vernon, WA 98273, USA.
If this policy changes materially, I'll post the diff at the top of this page and email anyone on the newsletter. The “last updated” date above is the truth.