Skip to the writing

ThePorchlightJournal

Plain notes on breathing easy
and looking after the ones we love


Kept by Sophia Williams
North Carolina

Privacy policy

What this site does and does not do with information about you, written in plain English, including the one page on this domain that uses cookies and advertising measurement.

Kept by Sophia Williams, North Carolina


Last updated August 13, 2026.

Who is responsible for this site

The Porchlight Journal is an independent publication, written and published by Sophia Williams in North Carolina, United States. It is not affiliated with any hospital, university, government body, medical association or charity.

In the language of privacy law, The Porchlight Journal is the controller of the information described in this policy. Where this policy says "we", "us" or "our", it means The Porchlight Journal. Where it says "you", it means anyone who visits any page on theporchlightjournal.com.

You can reach us at any time at sophia@theporchlightjournal.com. Put the word "privacy" in the subject line and it lands in the right place.

What the journal pages do, and what they do not do

Every editorial page on this site, which means the front page, the four entries, the about page, the contact page and these notices, behaves the same way. Those pages:

  • set no cookies of any kind, not for advertising, not for analytics, not for preferences
  • run no analytics and no visitor counter
  • load no advertising pixel and no conversion script
  • carry no social media buttons, no embedded video, no comment system, no chat widget, no advertisements
  • have no forms, no login, no account, no newsletter signup, so there is nothing on them for you to fill in
  • load no images or files from any other company

That is not a promise you have to take on trust. These pages are delivered with a content security policy that permits the browser to contact exactly one outside address, the web font host described below. A browser reading a journal page is not permitted to reach an advertising company or an analytics company at all, even if a script were added to a page by mistake.

Two ordinary technical things still happen when any web page is delivered, and it would be dishonest to leave them out.

Our web host

This site is hosted on Cloudflare Pages, a service of Cloudflare, Inc. Like every web host, Cloudflare handles the request your browser makes and keeps standard server records for security, reliability and abuse prevention. Those records ordinarily include the internet address the request came from, the time, the page requested and the browser identification string. That processing is Cloudflare's, under its own terms. We do not receive a report of who read which article, and we never build a reader profile from it.

The web font host

The typefaces on this site are served by fonts.bunny.net, a privacy oriented alternative to Google Fonts. When your browser fetches a font file, that request necessarily includes your internet address, in the same way any request for any file does. The service sets no cookies and states that it does not log personal data or track visitors. We chose it for exactly that reason. We receive nothing back from it.

The one exception: our advertising landing page

Some of the writing on this site is promoted with paid advertising on platforms such as Facebook and Instagram. An advertisement does not lead to the journal. It leads to a separate landing page on this domain, outside the journal, which carries a sponsored presentation from an independent company that sells a product.

We are not that company. On that landing page we do not take the order, we do not run the checkout, we do not ship anything, and we never see or store your payment card details at any point.

If you arrive on that landing page, here is exactly what happens.

Cookies and identifiers set on that page

  • a session identifier and a visitor identifier, both randomly generated values with no name attached to them, so that repeat visits from the same browser can be recognized as one visit
  • standard Meta advertising cookies, which record the click identifier attached to the advertisement you followed and a browser identifier used by Meta for measurement

These are first party cookies, set by this domain, and they last up to 400 days unless you clear them. They are set only on that landing page. Nothing sets them on the journal.

What is recorded about that visit

  • the internet address the visit came from
  • the browser identification string, which indicates the browser, the operating system and whether the device is a phone
  • the address of the page that referred you
  • the full address of the landing page, including any campaign parameters attached to the advertisement
  • the date and time, and whether the visit reached certain points in the presentation

That information is written to a database we control, hosted with Cloudflare. It is used to understand which advertisements work and to connect a sale back to the advertisement that led to it.

The advertising pixel and the server side measurement

That landing page loads the Meta advertising pixel, which reports page views and similar events to Meta Platforms, Inc. In addition, we send the equivalent events to Meta directly from our own server, which the industry calls server side conversion measurement and Meta calls the Conversions API. It is the same handful of events, sent by a second route, because browsers and privacy tools frequently block the first one.

Meta uses this to report on advertising performance and may use it for its own purposes, including audience building, under its own privacy policy. You can review and change what Meta does with advertising information in the ad preferences of your own Facebook or Instagram account.

If you buy something from the seller

The checkout belongs to the independent seller, on the seller's own website, under the seller's own privacy policy and terms. Your name, address, email address and payment details are given to that seller and its payment processor, not to us.

When an order is completed, the seller notifies us so that our referral can be credited. That notification typically includes the order identifier, the referral identifier our landing page generated, the order amount and the commission, and customer contact details consisting of a name, a telephone number, and an email address in hashed form, which means scrambled into a fixed string that we cannot read back into an address.

We use that notification for two things. First, to check that the commission we are owed matches the sales that actually happened. Second, to send a purchase event to the advertising platform, including the hashed identifiers, so that the platform can match the sale to the advertisement without either side handing over a plain email address. This is the point at which purchase information is shared with the advertising platform, and it is the plainest way we know to say it.

A small script served from this domain may also run on the seller's checkout page. It carries the referral identifier across, so the sale can be credited. It carries nothing else about you.

The categories of information involved

Taking everything above together, the categories are:

  • Identifiers. Random session and visitor identifiers, cookie identifiers, advertising click identifiers, internet address.
  • Internet and device activity. Pages requested, referring page, campaign parameters, browser and device identification string, events on the landing page.
  • Commercial information. That an order was placed, its identifier, its amount, and the commission attached to it.
  • Contact details received from the seller. Name, telephone number, and a hashed email address, received after a purchase and only after a purchase.
  • Anything you choose to write to us. Your email address and whatever you put in your message.

We do not collect your name or address from any page on this site. We do not collect payment card details, government identification numbers, precise location, biometric information, or medical records. We do not buy information about you from data brokers, and we do not add anything to what is described here from any outside source.

We do not ask you about your health anywhere on this site, and nothing you read on the journal is recorded. The fact that a landing page visit happened is recorded as part of that visit, as set out above. We do not build health profiles, and we do not use any of this to make decisions about anybody's access to anything.

Why we use it

  • to deliver the pages and keep the site secure and available
  • to measure honestly whether our advertising is working
  • to connect a sale to the advertisement that led to it, and to confirm the commission owed to us
  • to spot fraud, bot traffic and refunds
  • to answer the emails you send us
  • to meet legal, tax and accounting obligations

Legal bases, for readers in Europe and the United Kingdom

Our advertising is directed at readers in the United States, and we do not intentionally advertise in the European Economic Area or the United Kingdom. Anyone can read the journal from anywhere, and the journal collects nothing. If the UK GDPR or the EU GDPR applies to you, our legal bases are these:

  • Consent for advertising cookies and advertising measurement on the landing page, where consent is required. You can withdraw it at any time by clearing cookies in your browser and by writing to us, and withdrawal does not affect anything that happened before it.
  • Legitimate interests for delivering and securing the site, preventing fraud and abuse, and reconciling commission owed to us. Our interest here is running a small publication honestly, and we balance it against your privacy by collecting as little as the job allows.
  • Legal obligation for records we are required to keep, such as tax and accounting records.

Who we share information with

  • Cloudflare, Inc. Hosting, security, the database behind the landing page, and the email forwarding that carries mail sent to our address. Cloudflare acts as our service provider.
  • Meta Platforms, Inc. The advertising platform. It receives the measurement events described above, including a purchase event with hashed identifiers when a sale happens.
  • The independent seller. Our landing page passes a referral identifier to the seller's checkout so the sale can be credited. We do not send the seller anything else about you. The seller sends us the order notification described above.
  • Professional advisers and authorities, where we are required by law to disclose something, or where we need advice about a legal matter.

We do not sell your information for money, and we do not give it to data brokers. If this publication were ever transferred to somebody else, the records described here could transfer with it, and this policy would go with them.

How long we keep it

  • Cookies set by the landing page: up to 400 days, or until you clear them, whichever comes first.
  • Visit and measurement records: up to 24 months, then deleted.
  • Order notification records: up to 24 months, except for the commission and accounting figures, which we keep for as long as tax law requires.
  • Emails you send us: for as long as it takes to answer you and a reasonable while after, and we will delete them sooner if you ask.

How it is protected

Every page on this domain is served over an encrypted connection, and browsers are instructed to refuse an unencrypted one. Access to the database is restricted to the operator of the site. Email addresses received from the seller arrive hashed rather than in plain text. We never hold payment card details, because they never come near us. No method of storing or sending information over the internet is perfectly secure, and we will not pretend otherwise, but we keep as little as the work allows, which is the only real protection there is.

Where information is processed

This site, its database and its measurement are operated in the United States, and our service providers are United States companies with a global infrastructure. If you are in the European Economic Area or the United Kingdom and information about you reaches us, it is processed in the United States. Our providers rely on the Standard Contractual Clauses approved by the European Commission and the United Kingdom addendum for such transfers.

Links to other websites

Where a page links out to somebody else's website, that site is not ours and this policy does not cover it. Once you are there, you are in their hands and under their terms. It is always worth reading the privacy policy of any site you buy anything from.

Your choices in your own browser

  • On the journal, there is nothing to opt out of, because nothing is set and nothing is recorded.
  • On the landing page, you can block or delete cookies in your browser settings, and you can use private browsing. Blocking them does not stop you reading anything.
  • You can change what the advertising platform does with advertising information in the ad settings of your own account with it.
  • Global Privacy Control: our measurement runs partly at the server and does not read that signal today. We would rather tell you that than claim a compliance we do not have. If your browser sends the signal, please also send us an email and we will apply the opt out to whatever we hold.

Your rights in California

If you live in California, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you the rights set out below. In the past twelve months we collected the categories of personal information listed earlier on this page, from you and your device, from our web host, and from the independent seller after a purchase. We collected them for the business purposes listed earlier, and we disclosed them for a business purpose to the service providers named above.

Sale and sharing

We do not sell personal information for money. The advertising measurement we send to the advertising platform, including the purchase event, counts as "sharing" for cross context behavioral advertising under California law, and under some state definitions it may count as a "sale". We disclose that plainly rather than argue about the label. That sharing happens only in connection with the landing page and a purchase that follows it. It never happens on the journal.

Sensitive personal information

We do not collect sensitive personal information as California defines it, and we do not use or disclose any information for purposes beyond those described here, so there is nothing for a limitation request to restrict. The right to limit is listed here anyway, because it is yours whether or not we happen to hold anything.

Your rights

  • the right to know what personal information we have collected, the sources, the purposes, and the categories disclosed or shared
  • the right to a copy of the personal information we hold about you
  • the right to have it deleted
  • the right to have inaccurate personal information corrected
  • the right to opt out of the sale or sharing of your personal information
  • the right to limit the use and disclosure of sensitive personal information
  • the right not to be discriminated against for exercising any of these rights. We treat every reader the same, and there is nothing to withhold from anyone, since the journal is free and asks nothing of you

Do Not Sell or Share My Personal Information

To opt out, send an email to sophia@theporchlightjournal.com with "Do Not Sell or Share My Personal Information" in the subject line. We will stop sending advertising measurement connected to you and delete the records we hold about you, and we will confirm by reply. Clearing the cookies in your browser at the same time makes the opt out stick on your end as well.

How to make a request, and how we verify it

Send any request to sophia@theporchlightjournal.com with "California privacy request" in the subject line. We will respond within the time the law allows, which is ordinarily 45 days, and we will tell you if we need longer.

Because there is no account on this site and we hold no name against the journal, the practical way to find your records is an order identifier from a purchase, or the cookie values from your browser. If we cannot reasonably connect a request to any record we hold, we will tell you so plainly instead of asking you for more information than we started with.

Authorized agents

You may use an authorized agent to make a request for you. We will ask for written permission signed by you, and we may ask you to confirm directly that the agent is acting on your behalf.

We do not knowingly sell or share the personal information of anyone under 16 years of age.

Your rights in Europe and the United Kingdom

If the EU GDPR or the UK GDPR applies to you, you have the right:

  • to be told what we hold and to have a copy of it
  • to have inaccurate information corrected
  • to have information erased
  • to have our use of it restricted while a question is settled
  • to receive it in a portable form, or have it sent to another controller, where that applies
  • to object to processing carried out on the basis of legitimate interests, and to object at any time to processing for direct marketing
  • to withdraw consent at any time, where we rely on consent, without affecting anything done before you withdrew it
  • not to be subject to a decision made solely by automated means that has a legal or similarly significant effect. We make no such decisions
  • to complain to your data protection supervisory authority. In the United Kingdom that is the Information Commissioner's Office. In the European Economic Area it is the authority in the country where you live

Write to sophia@theporchlightjournal.com to exercise any of these. We will answer within one month, and tell you if we need longer.

Children

This site is written for adults, and nothing on it is directed to children. In the terms of the Children's Online Privacy Protection Act, this is not a website directed to children under 13, and we do not knowingly collect personal information from a child under 13. There is nothing here for a child to sign up for, and our advertising is not aimed at children.

If you are a parent or guardian and you believe a child under 13 has given us personal information, please write to sophia@theporchlightjournal.com and we will delete it promptly. You may also ask us to confirm what was collected and to stop any further collection.

Changes to this policy

If this policy changes, we will update the date at the top of the page and describe the change in plain words. If a change is significant, we will say so on this page rather than hope nobody notices. We will not apply a change backwards to information already collected under an earlier version.

How to reach us

Write to sophia@theporchlightjournal.com. It is read by a person, and it is the same address for every kind of request on this page. We are in North Carolina, in the United States. We do not publish a street address or a telephone number, and we would rather say so than print one that goes nowhere.

One last thing, since it belongs on every page here. We cannot answer medical questions, and we would not try. Those go to your own doctor, who knows the history.