Matt Murphy

Fine print

Privacy

What this site collects, where it’s kept, and what you can do about it. I wrote it to match what the site actually does.

Last updated: 4 October 2026

What this site collects

In short:

  • the details you choose to send through the inquiry form;
  • aggregate page-view counts, recorded without cookies;
  • which “Who is Matt?” cards you’ve found, kept only in your own browser;
  • an unsent message you’re writing, kept only in your browser tab until you send it or close the tab.

There are no accounts and nothing to sign in to, for visitors or for me. The site doesn’t set cookies.

Inquiries

When you send the inquiry form, the site stores:

Inquiries are stored in the site’s Postgres database. When the site runs locally for development, a file-based development database is used instead. Inquiries are kept until I delete them. There’s no automatic deletion or retention schedule.

Keeping out spam

The form includes a hidden field that people don’t see but automated scripts tend to fill in, and a signed, time-limited form token. Submissions are rate-limited using a salted, one-way hash of your IP address. The raw IP address isn’t stored, and these rate-limit records are short-lived: once they’re a day old, they’re deleted the next time the form is used. Your browser’s user agent isn’t stored. To catch the same message being sent twice, each inquiry is also stored with a one-way fingerprint of its email address and message.

The emailed copy

When email is configured, each new inquiry is also emailed to one fixed address of mine: your whole message and the details listed above, with its short reference code. That email is how I read your message. The site has no inbox page.

It’s delivered by Resend, an email-delivery service, so the contents of your message pass through Resend on the way to my mailbox. Resend may keep its own records of the emails it delivers, under its own policies. The copy stays in my mailbox until I delete it.

Nothing you type in the form can change who receives that email. The address you give is set as its reply-to, so I can answer you by replying.

The site records whether each email went out (pending, sent, failed or skipped), how many attempts were made, and the last error if there was one.

Analytics

When the site is hosted on Vercel, it uses Vercel Web Analytics, which doesn’t use cookies and records aggregate page views. I can switch it off in the site’s configuration.

Before anything is sent, each address is cut down to the page path, so anything after a “?” or “#” is dropped.

A small, fixed set of aggregate events can also be recorded, but only if I switch them on separately:

These carry only a short identifier, such as a project’s slug (for example “pathway-builder”), a service area or a card id. They never include message contents, names or email addresses.

Storage in your browser

The site remembers one thing in your browser’s local storage. It stays on your device and is never sent anywhere:

You can clear it with “Start over” on the About page, or by clearing this site’s data in your browser.

The contact form uses session storage, which this tab forgets when it’s closed:

Hosting & logs

Like any website, this one runs on a hosting provider. The hosting provider may keep standard server logs, such as IP address and request details, under its own policies.

The typefaces are served from this site too, so your browser doesn’t contact Google or any other font service to show a page.

Your choices & deletion

  • The inquiry form is optional. You can read the whole site without sending anything.
  • To have an inquiry deleted, send a new message through the contact form asking me to delete it. Using the same email address helps me find it.
  • To clear the cards you’ve found, use “Start over” on the About page. To drop an unsent draft, close the tab. Clearing this site’s data in your browser removes both.

Changes

If what the site collects changes, this page will be updated to match, and the “Last updated” date at the top will change with it.