Privacy

This site collects what you type into it, and nothing else.

No cookies, no analytics script, no tag manager, no embedded fonts or scripts from anyone else. Reading this page leaves no record beyond the one line my own server writes to its own access log.

Tracking

No cookies are set, so there is no consent banner to click.

  • No cookies are set, so there is no consent banner to click.

  • No analytics or tracking script runs on these pages. The one thing stored on your machine is the region for prices — US, Canada, UK or Europe — the one you pick, or the one a /us, /ca, /uk or /eu address sets. It is kept in your browser’s local storage so the next page shows the same currency. It is never sent anywhere, and nothing about you is sent to anyone else.

  • Fonts and images are served from this domain, not from a font or CDN provider.

  • Cloudflare sits in front of this site, and every request reaches me through it, which means Cloudflare sees the address it came from. Sending the form goes further into Cloudflare than that: the form posts to code I wrote that runs on Cloudflare’s edge, and Cloudflare’s own mail service carries the result to my mailbox. It is the one company between you and me, either way, and it works under its own terms.

  • The server keeps a standard access log — time, path, status, IP address, browser string, referring page — for fourteen days. It is used for security, for abuse handling, and for counting which page a booking link was clicked from.

  • That counting is the whole of the measurement on these pages. Every booking button points at /go/call on this domain and redirects to the calendar, and the placement it was clicked from — the hero, the price page, the end of an article — is in the address and travels on to the calendar with you. It names a place on the site. It never names you. There is no cookie and no pixel: the count is a line in my own log, read by me, and no analytics company is given it. The CTO Hour button works the same way through /go/cto-hour, which redirects to Stripe’s payment page; the place name stays in my log and does not travel on to Stripe. The intro-call link /go/book works the same way, redirecting to a Google Calendar booking page; the place name stays in my log and does not travel on to Google.

  • The brief form carries the same kind of string. If you reached it from a link elsewhere on the site, the name of that place is sent in the email alongside what you wrote. It is the same short list of place names, it is in the page source where you can read it, and nothing is stored on your machine to produce it.

Five links leave this domain: the booking page at zcal.co, the CTO Hour payment page at Stripe and the intro-call booking page at Google Calendar, which the three redirects above send you to; the Companies House register; and Cloudflare’s own privacy terms, linked further down this page. Each has its own terms, and none of the five is loaded into these pages.

Contact

Your brief goes to my mailbox, and one person reads it.

The route a brief takes, as one line: from the form in your browser, to code I wrote running on Cloudflare, into Cloudflare’s mail service and on into a mailbox one person reads — never through this website’s own server. Nothing is written to a database on the way. If the post fails, the form offers your own mail client instead.

Schematic — shape only
not through this site’s server the form my code Cloudflare my mailbox nothing is written to a database mail client only if the post fails

The form on the home page posts what you type to code I wrote, running on Cloudflare’s edge at syntheticandhuman.com/brief. It does not travel through this website’s own server on the way — that code answers before a request ever reaches the server — and no form service and no mailing tool is in the route. One other company is: Cloudflare runs my code, and my code hands the brief to Cloudflare’s own mail service, which delivers it into the mailbox one person reads. So your brief exists on Cloudflare’s machines on the way to mine, under its own terms. Nobody else receives a copy. Nothing is written to a database: there is no store behind this form, and the brief’s only resting place is that mailbox. The address you connect from is counted, and only counted — it is what rate-limits the endpoint against abuse, it is not written down beside your brief, and it does not outlive the minute it is counted in. A brief is kept until it is deleted — nothing deletes it on a schedule — and I delete one on request, at [email protected].

If the post fails, the form falls back to offering your own mail client with the text already filled in, and on that path nothing is transmitted until you press send in your own email program. With scripting turned off there is no fallback to reveal, so the form posts the same way any other browser does and you land on a page that says the brief arrived. You can skip the form entirely and write to [email protected] instead.

However it arrives, what you send is read by one person, kept while we are talking and for as long as any resulting contract requires, and used for nothing except replying to you. It is not added to a mailing list, not enriched, and not passed to anyone else. The form asks for four things and two of them are optional: what you want built, an address to reply to, what you have already tried, and a rough band for what you have to spend. The last two can be left empty and the brief still sends.

Booking a call goes through zcal.co, or through Google Calendar for the intro call, each handling that data under its own terms and sharing the time, your name and your address with the person you booked. Paying for a CTO Hour goes through Stripe, which handles your card under its own terms; I see your name, your email address and the payment, never the card number.

Rights

Ask for deletion and the same person answers.

The controller is Deal Baker Ltd, registered in England and Wales, company number 14906367, registered office International House, 64 Nile Street, London, United Kingdom, N1 7SR. Deal Baker Ltd trades as Synthetic and Human. Work happens from Fredrikstad, Norway.

Under UK and EU data protection law you can ask what I hold about you, ask for it to be corrected or deleted, and complain to a supervisory authority — the ICO in the UK, or Datatilsynet in Norway. Write to [email protected] and you will get an answer from the same person who answers everything else here.

Client work is covered separately, by the contract and its data processing terms, not by this page.