Privacy Policy
What We Collect
Only what the service needs to function: your email address and your
notification preferences (products, versions, and whether you want security
patches only). Nothing else - no names, no analytics, no tracking pixels.
How Your Email Address Is Stored
- Your address is encrypted at rest. It is decrypted only at the moment an
email is sent to you.
- Lookups (such as signing in) use a keyed one-way hash of your address, and
our send log stores only that hash - never the address itself.
- Sign-in links are single-use and expire after a short time; they are stored
only as hashes.
How Your Email Address Is Used
Solely to send you the patch notifications you asked for, plus the
confirmation and sign-in links that operate your subscription. Your address is
never sold, shared, or used for anything else. Delivery goes through our email
provider, as with any email service.
No Advertising, No Marketing
- The site carries no advertising, no ad networks, and no remarketing or
audience-building of any kind.
- You will never receive marketing email from us. The only emails sent are the
patch notifications you subscribed to and the operational messages needed to run
your subscription (confirmation and sign-in links).
- Your email address is never used to build advertising audiences on other
platforms, and never disclosed to advertisers - we could not do so even in
principle without decrypting it, which happens only at the moment a requested
email is sent.
Retention and Deletion
- Clicking the unsubscribe link in any email, or deleting your subscription
from the preferences page, removes your address and preferences immediately.
- Signups that are never confirmed are deleted automatically after 7 days.
- Send-log entries (hashed, for abuse prevention) are deleted after 30 days.
Cookies and Local Storage
A short-lived session cookie is set only when you open the preferences page
via a sign-in link, and expires after about 30 minutes. Your light/dark theme
choice is kept in your browser's local storage. There are no advertising or
third-party cookies.
GDPR and Your Rights
For subscribers in the UK/EU, the service is operated in line with the
principles of the General Data Protection Regulation; for New Zealand
subscribers, the Privacy Act 2020 applies in the same spirit.
- Lawful basis - processing is based on your consent,
given explicitly when you confirm your email address (double opt-in). No
notifications are ever sent to an unconfirmed address.
- Withdrawal of consent - withdraw at any time via the
one-click unsubscribe link in every email or the delete option on the
preferences page. Removal is immediate, not queued.
- Data minimisation - only the data strictly needed to
operate the service is held: your email address (encrypted) and your chosen
preferences. There is no profiling and no automated decision-making.
- Right of access and rectification - the preferences
page (reached via a sign-in link) shows everything held about you and lets you
change it.
- Right to erasure - unsubscribing erases your data
immediately; there is no soft-delete or marketing archive. Backups age out in
the normal course of operation.
- No transfers, no sharing - your data is not sold,
shared with third parties, or used for any secondary purpose. The only
processor involved is the email delivery provider used to send your
notifications.
Contact
Questions, complaints, or data requests: contact Ope.
If you believe your data has been mishandled you also have the right to complain
to your local supervisory authority.