PRIVACY
This page states exactly what Timory stores, why, how long it is kept and how to have it removed. It describes what the code actually does — if you find a gap between this page and our behaviour, that is a bug and we want to hear about it.
§ 01
| Data | When | Purpose | Retention |
|---|---|---|---|
| Email address (plus the market description you type, for a market watch) | Only when you subscribe to a brief, unlock full evidence chains, or create a free market watch | Sending the emails you asked for, and nothing else | Until you unsubscribe or ask us to delete it |
| Anonymous page event: path, referrer and a daily visitor hash | Every page view on this public site | Counting page views and daily unique visitors | 90 days |
| Raw IP address, full user-agent string and IP-derived country, with path and referrer | Every page view on this public site | Traffic forensics: telling real readers from crawlers and abuse. Readable only by the site owner through an authenticated admin view; never published, never shared, never used for advertising or profiling | 30 days, then deleted automatically |
The daily visitor hash is sha256(daily rotating salt + IP + user-agent), truncated. The salt changes every day, so the hash cannot be linked across days or reversed. It is a per-day counter, not a persistent identifier.
BEING PRECISE
Because we store the raw IP address alongside that hash, we do not claim this site is anonymous. An IP address is personal data under the GDPR and the PIPL. The list above is complete, and the 30-day limit is enforced by a scheduled job, not by a promise.
§ 03
You only receive email you asked for: the weekly evidence brief, or the market watch you created. Market watches use double opt-in — the watch stays inactive until you click the confirmation button yourself. Every email carries a one-click unsubscribe link and the standard one-click unsubscribe headers, and unsubscribing takes effect immediately. We do not sell, rent or share your address, and we send no advertising on behalf of anyone else.
§ 04
To stop emails, use the unsubscribe link at the bottom of any email — it takes one click and needs no account. To have your stored data deleted, or to ask what we hold about you, reply directly to any email you have received from Timory. We handle these by hand and confirm when it is done. Access logs age out on their own after 30 days, so a request made after that has nothing left to erase.
§ 05
Evidence excerpts on this site come from publicly visible posts and comments in developer and founder communities. Copyright stays with the original authors and platforms; we publish short excerpts with a direct link back to the source, and excerpt limits vary by source. We do not republish private messages, private groups or anything behind a login. If you are the author of a quoted post and want it removed, reply to any email you have received from Timory and we will take it down.
§ 06
There is no Google Analytics and no advertising network on this site; visit counting is done on our own server. Outgoing email goes through our email provider, which necessarily sees your address. Search engines receive publication pings for new public pages only — never anything about you. If you create a market watch, the market description you type is sent to the language-model provider we use (a third party, possibly processing outside your country) so it can be matched against the dossiers we already track. Your email address is not sent to the model.
§ 07
If we start collecting something new, this page changes in the same release. Retention periods shown above are read from the running configuration, so the numbers on this page are the numbers the system enforces. See also our methodology and terms of use.