No ad tracking. Brain Vomit does not use advertising pixels or behavioral analytics.

No data sales. Personal information is not sold or rented.

You stay in control. You can unsubscribe or request access, correction, or deletion by email.

The short version

This policy explains how the Brain Vomit blog collects and handles information when you read a post, join the future newsletter, use the public comment thread, or contact me about the blog. “I,” “me,” and “my” refer to Chinmay Arora.

The blog is a personal publishing project. It does not run ads, build advertising profiles, or use analytics tools to follow readers across the web. Some basic technical information is still processed by the companies that host the site and deliver its fonts, scripts, and public-comment feature.

Information collected

Newsletter signups

If you join the future newsletter, the signup records your email address, submission time, the page where you signed up, a consent indicator, and an internal signup status. The form also contains an invisible anti-spam field; legitimate visitors are not expected to complete it.

Public comments and reactions

Post discussions are provided by Giscus and stored in this site’s public GitHub Discussions. If you participate, your GitHub username, profile information, comment, reactions, timestamps, and other information GitHub associates with that activity may be visible publicly. Do not include private or sensitive information in a comment.

Theme preference

If you switch between light and dark mode, the blog saves that choice in your browser’s local storage under blog-theme. It stays on your device and is used only to remember the display you selected.

Technical and network information

When you load the blog, hosting and content-delivery providers may automatically receive information such as your IP address, browser and device type, requested URL, referring page, and request time. GitHub states that it logs visitor IP addresses for security when a GitHub Pages site is visited. I do not receive a reader-level analytics dashboard from this blog.

Information you send directly

If you email me about the blog, I receive the address you use and whatever you include in the message. Please do not send sensitive personal information unless it is necessary for your request.

How the information is used

  • To maintain the newsletter interest list and send future issues or necessary list-related messages.
  • To display, moderate, and respond to public comments.
  • To remember your chosen color theme.
  • To operate, secure, troubleshoot, and protect the blog from spam or abuse.
  • To answer privacy requests or other messages you send.
  • To comply with legal obligations and protect rights, safety, and the integrity of the site.

Where data-protection law requires a legal basis, newsletter information is processed with your consent; requested interactions are processed to provide the feature you chose; and limited technical processing is based on the legitimate interest in operating and securing the blog. You may withdraw newsletter consent at any time.

Where information goes

Google

The newsletter form uses Google Apps Script and stores signup records in a private Google Sheet. Privacy emails sent to the listed Gmail address are also processed and stored through Google’s email service. Google handles related account, service, and network data under its own privacy terms.

Google Privacy Policy

GitHub and Giscus

GitHub Pages hosts the blog. Giscus connects public comments to GitHub Discussions. Your use of those services, including GitHub authentication, is also governed by GitHub’s privacy terms.

GitHub Privacy Statement

Google Fonts and jsDelivr

The blog requests fonts and open-source interface files from external content-delivery networks. Those providers receive the network information needed to deliver the requested files.

Google privacy · jsDelivr privacy

I may also disclose information if required by law, to respond to valid legal process, or when reasonably necessary to prevent fraud, abuse, or harm. I do not sell or rent personal information, and I do not share it for cross-context behavioral advertising.

Cookies, local storage, and tracking signals

The blog itself does not set first-party advertising or analytics cookies. It uses browser local storage only for the light/dark theme preference. Embedded or linked third-party services—particularly GitHub/Giscus—may use their own cookies or similar technologies according to their policies.

Because the blog does not sell personal information or use cross-site behavioral advertising, Global Privacy Control and “Do Not Track” signals do not change the blog’s behavior. Your browser can clear the saved theme preference at any time.

Storage, retention, and security

Newsletter records are stored in a private Google Sheet and retained while the list remains active or until you unsubscribe or request deletion, unless a longer period is reasonably necessary for legal, security, or recordkeeping purposes. Direct emails are kept only as long as needed to handle the conversation and any related obligations.

Public comments remain in GitHub Discussions until you delete them through GitHub, I remove them as a moderator, or GitHub removes them under its policies. Theme preference data stays in your browser until you clear it. Hosting and delivery providers set their own retention periods for technical logs.

I use reasonable safeguards appropriate for a small personal publication, including private access to the signup sheet and HTTPS in transit. No internet service or storage system can guarantee absolute security.

International processing

The blog is operated from the United States. Google, GitHub, Giscus, and content-delivery providers may process information in the United States and other countries where they operate. Those locations may have privacy rules that differ from those where you live.

Your choices and privacy rights

Depending on where you live, you may have rights to request access to, correction of, deletion of, restriction of, or a portable copy of personal information, and to object to certain processing. You may also withdraw consent where consent is the basis for processing.

  • Newsletter: email me to unsubscribe, update your address, or delete the signup record.
  • Public comments: edit or delete your comment through GitHub, or ask me to moderate the related discussion.
  • Theme: change the theme with the page control or clear this site’s local storage in your browser.
  • Complaints: you may contact your local data-protection authority where that right applies.

I may need to verify that a request concerns you before acting on it. Some information may be retained where legally permitted or required, including for security, dispute resolution, or legal claims. Exercising a privacy right will not result in discriminatory treatment.

Children’s privacy

The blog is intended for a general audience and is not directed to children under 13. I do not knowingly collect personal information from children under 13. If you believe a child has submitted personal information, contact me so I can review and delete it where appropriate.

Changes to this policy

This notice may be updated when the blog’s tools or information practices change. The effective date at the top will be revised, and material changes will be made visible on this page. Continued use after an update means the current notice applies to future interactions; it does not create retroactive consent where consent is legally required.

Questions or requests

Email [email protected] with the subject “Brain Vomit privacy request.” Include enough detail for me to locate the relevant signup or comment, but do not email passwords or identity documents unless I specifically explain why verification is necessary.