Privacy Policy

How andrewconnell.com collects, uses, and protects your information — including cookies, analytics, comments, and the newsletter.

This site, andrewconnell.com, is operated by Andrew Connell. This policy explains what information is collected when you visit, how it’s used, and the choices you have.

Information collected automatically

When you visit this site, standard web-server and analytics processing records non-personal technical information: browser type, operating system, approximate geographic region, referring page, and the pages you view. This is used to understand what content is useful and to keep the site working properly.

Information you provide

You only provide personal information when you choose to. That happens in a few places:

  • The contact form — your name, email address, subject, and message, used solely to reply to you. Submissions are verified with Cloudflare Turnstile (a bot-detection check) and sent via Azure Communication Services; they are not added to any mailing list.
  • The newsletter — your email address, managed through Kit (formerly ConvertKit). Every newsletter includes a one-click unsubscribe.
  • Article comments — comments are powered by giscus, which stores them as discussions in a public GitHub repository under your GitHub identity. Commenting is governed by GitHub’s privacy policy.

Your information is never sold, leased, or shared with third parties for their own marketing.

Cookies and analytics

Four analytics services run on this site:

ServicePurposeCategory
Ahrefs Web AnalyticsAggregate traffic reporting - cookieless, stores nothing on your deviceStrictly necessary
Azure Application InsightsFirst-party diagnostics and error trackingAnalytics
Google Analytics 4Aggregate traffic and content reportingAnalytics
Microsoft ClarityAggregate interaction and usability analysisAnalytics

The consent banner is part of this site. There’s no third-party consent platform behind it, no consent vendor’s script on the page, and nothing about you is sent anywhere to make it work. Your answer lives in a first-party cookie, ac_consent, that only this site reads.

Whether you’re asked at all depends on where you’re browsing from. Cloudflare tells the site the broad region a request came from, and the site keeps that in the ac_region cookie. From the EU, EEA, and UK, and from anywhere the region can’t be worked out, you get the banner and you decide. From everywhere else there’s no banner, and you can still switch analytics off at any time from Cookie settings in the footer.

The banner offers two categories, Necessary and Analytics, because those are the only two that mean anything here. This site carries no advertising, personalizes nothing, and never grants advertising signals to any of the services above.

Analytics here are opt-out. They’re on until you turn them off, so before you answer the banner every service in the table above is running:

  • Ahrefs Web Analytics runs either way, because it stores nothing on your device and can’t identify you.
  • Azure Application Insights sets its ai_user and ai_sessionaccom cookies from the first page load, and stops setting them once you decline. Its diagnostics run whatever you choose, with those cookies or without them, because that’s what keeps errors and slow pages visible for the visitors who decline everything else.
  • Google Analytics and Microsoft Clarity are switched on from the page head. Google Consent Mode declares “denied” before the tag loads, and the site upgrades that to “granted” for anyone who hasn’t declined; Clarity is told its state explicitly on every page load, granted or denied. Advertising signals stay denied in both, always.

Let me be clear about what that costs, since it’s your data: if you’re in the EU, EEA, or UK, analytics start before you’ve answered the banner rather than after. That’s a considered choice, not an oversight. It’s also why every one of them stops the moment you say no, and why the banner treats accepting and declining as equally easy.

To change your mind, use the Cookie settings link in the site footer. Withdrawing analytics stops Google Analytics and Microsoft Clarity right away, on the page you’re already on. Azure Application Insights stops setting its cookies on the next page you load, because it’s configured once when a page starts. Cookies already on your device stay there until they expire or you clear them in your browser.

Your answer to the banner is also recorded, because consent isn’t worth much if it can’t be demonstrated. The record is a random identifier, the categories you picked, whether you accepted, rejected, customized, or withdrew, the broad region, and the time the site received it. It holds no IP address, no user agent, and no fingerprint, and it’s deleted automatically after 24 months.

What this site stores in your browser

Here’s everything this site stores on your device under its own name, including the items that aren’t cookies but do the same job. Nothing scans the site to produce this list, so it’s maintained by hand alongside the code that sets each item. If your browser shows something for andrewconnell.com that isn’t listed here, tell me and I’ll get it corrected.

NameSet byStored asCategoryPurposeKept for
ac_consentandrewconnell.comcookienecessaryStores your cookie-consent choices so you're not asked again.180 days
ac_regionandrewconnell.comcookienecessaryRecords the broad region your request came from so the site knows whether a consent prompt is required; it holds no identifier.24 hours
themeandrewconnell.comlocalStoragenecessaryRemembers whether you picked the light or dark appearance.Until you clear this site's browser storage
ai_userAzure Application InsightscookieanalyticsIdentifies your browser across visits so diagnostic telemetry can be correlated.1 year
ai_sessionaccomAzure Application InsightscookieanalyticsGroups the pages you view into a single visit.30 minutes, extended on each page view, up to 24 hours total
accom_AI_buffer_1Azure Application InsightssessionStorageanalyticsHolds diagnostic telemetry that hasn't been delivered yet so it can be retried.Until you close the browser tab
accom_AI_sentBuffer_1Azure Application InsightssessionStorageanalyticsTracks diagnostic telemetry already sent but not yet acknowledged, so a retry doesn't duplicate it.Until you close the browser tab
_gaGoogle Analytics 4cookieanalyticsTells one visitor apart from another.2 years
_ga_<measurement-id>Google Analytics 4cookieanalyticsKeeps Google Analytics session state for this site's measurement ID.2 years
_clckMicrosoft ClaritycookieanalyticsPersists a Clarity identifier so repeat visits are attributed to the same browser.1 year
_clskMicrosoft ClaritycookieanalyticsJoins the pages you view into one Clarity session.1 day
__sl-fingerprintSparkLoopcookiefunctionalDevice fingerprint the newsletter recommendation widget uses to attribute referrals.30 days
ckidKitlocalStoragefunctionalIdentifier Kit's newsletter forms use to recognize a returning visitor.Until you clear this site's browser storage

Items in the necessary category are always active. The analytics items follow your choice in the banner, and run until you make one. The functional items are set by the newsletter sign-up and recommendation widgets, which the banner’s analytics toggle doesn’t currently control.

Embedded content

Pages here load content and scripts from other services: YouTube and Wistia for video, Senja for testimonials, Kit for newsletter forms, SparkLoop for newsletter recommendations, giscus for article comments, and Cloudflare Turnstile on the contact form. Embedded content behaves as if you had visited that service directly. A YouTube embed, for instance, sets cookies against youtube.com as soon as the page loads, well before you press play. Anything a provider stores against its own domain belongs to that provider rather than to this site and is governed by their privacy policy, which is why those aren’t in the table above; where one of these scripts stores something under andrewconnell.com, it is in the table.

Controlling your information

You can ask what personal information is held about you, ask for it to be corrected, or ask for it to be deleted. Use the contact form and the request will be handled promptly.

Newsletter subscribers can unsubscribe at any time through the link in every email, which removes you from future mailings immediately.

Children age 13 and under

This site is not directed at children under 13, and no information is knowingly collected from them. If you believe a child has provided personal information, use the contact form and it will be deleted.

This site links to external websites that are not under my control. This policy does not apply to them; review the privacy policy of any site you visit.

Security

Reasonable measures are taken to protect information collected through this site, including encryption in transit (HTTPS) across the whole site. No method of transmission or storage is completely secure, so absolute security cannot be guaranteed.

Changes to this policy

This policy may be updated from time to time. The policy was lasted updated August 12, 2026.

Contact

Questions or concerns about this policy? Use the contact form.