Skip to content
lainlog

Privacy

This page tells you what lainlog collects, where it lives, and how you control it. Plain English, no marketing. Last updated May 2026.

What we collect#

When you sign in. Your OAuth provider (GitHub or Google) hands us your name, email, profile image, and a provider account id. We auto-generate a username from your name. We seed your reading preferences with sensible defaults. We store acreatedAt timestamp and a lastSeenAt timestamp that updates on each sign-in. Your bio is optional and starts empty.

Convex Auth manages a few internal tables on our behalf — sessions, refresh tokens, rate-limit counters. We don’t read or write them in our own code.

When you read articles. We send a domain-only page-view ping to GoatCounter. No IP storage, no fingerprinting, no personal data. Anonymous reading collects only that.

Cookies and local storage#

The site uses a small set of cookies and localStorage keys. Each one is functional — none track you across sites.

  • __Host-convex-auth-jwt, __Host-convex-auth-refresh — your sign-in session. Signed-in only. The JWT expires after 30 days; the refresh token rotates silently.
  • theme— your light / dark / system preference. Survives sign-out so the page doesn’t flash on reload.
  • lainlog:audio — your sound on/off preference.
  • lainlog:audio:prompt-dismissed— whether you’ve dismissed the first-visit “you can mute the site” tooltip.
  • lainlog:dotfield — your opt-out for the cursor-reactive dot field on course landing pages.
  • lainlog:consent-dismissed — the date you dismissed the cookie banner.

Where it lives#

  • Convex. Our backend holds your account and preferences.
  • GoatCounter.Anonymous page-view counts live here. They’re a privacy-respecting alternative to Google Analytics.
  • Vercel. Our hosting platform serves the site and receives standard request logs.

Your control#

You own the data. Three controls cover everything we store.

  • Edit your profile. /me/settings → Profile. Name, bio, and avatar.
  • Edit your reading preferences. /me/settings → Reading. Theme, audio, font size, course visibility, show-notes default.
  • Delete your account. /me/settings → Account → Delete my account. We soft-delete with a 30-day window: signing back in within 30 days recovers the account. After 30 days, your data is permanently removed.

Dismissed the cookie banner and want it back? Reset it here. The banner reappears at the bottom of the page so you can review the notice or follow the link to this policy again.

What we don’t do#

  • No marketing emails. There is no email program.
  • No tracking pixels beyond GoatCounter. No Google Analytics, no Facebook pixel, no Hotjar, no Mixpanel.
  • No advertising cookies. No retargeting.
  • No browser fingerprinting.
  • No selling, sharing, or licensing of data to third parties.

Updates to this policy#

We’ll re-version this page if our practices change. The updated-at date in the intro tells you when.