Privacy

This policy covers irvinebroque.com, its public services, and its private owner tools.

Effective

What is processed

The public service has no user accounts and does not ask for precise device location. It processes the page or MCP request you choose to send, including search or recommendation text and opaque item IDs, only to return the requested public content. Public MCP request bodies are not saved to the site’s D1, KV, or R2 storage.

The recommendation chat stores its active conversation in a separate, isolated Cloudflare Durable Object so you can exchange messages while the page remains open. Its anonymous token is held only in page memory; refreshing or closing the page discards access and starts a new conversation. The token expires after 24 hours in all cases. The agent receives only your messages and records returned by the anonymous public API; it has no access to owner authentication, private account data, or the site database. WhatsApp messages are also processed by Meta under its terms before verified deliveries reach the isolated agent.

The public ACP beta uses the same isolated recommendation agent. It stores the prompt text and public resource-link metadata you submit in an anonymous conversation, plus a session index and protocol state needed for reconnect and replay, for no more than 24 hours. An anonymous, signed ACP cookie is stored by the client for that period. The agent does not fetch linked resources, access a client filesystem or project, connect to client-provided MCP servers, or receive owner authority. Operational telemetry is content-free and records only protocol methods, outcomes, coarse counts, latency, and error classes.

The radio uses Cloudflare’s IP-derived city, region, country, timezone, and coordinates to choose local time and calendar context. The coordinates are sent to Open-Meteo only to retrieve current weather, and the country and year are sent to Nager.Date only to retrieve public holidays. The site sends the radio agent the resulting coarse labels, recent public item IDs, canonical affinity IDs, and thumbs preferences; it does not send the IP address or coordinates to the model. Playback uses an official anonymous Spotify Embed, so Spotify receives ordinary embed requests under its own policy; this site does not request a Spotify login, token, account status, or library access.

Optional radio tuning processes the music description you submit or the public personal-site URL you name. Text and public Markdown are normalized in a stateless, no-tools Workers AI request. A remote import makes a credential-free, bounded request to the named public origin and may read declared taste-profile JSON, that origin’s exact read-only taste.profile MCP tool, or Markdown. It does not crawl the site, send your cookies or authorization, or access private network targets. The editable profile remains in page memory until you clear it, reload, or close the page. Raw taste text, remote bodies, source URLs, hostnames, model prompts and responses, and affinity lists are not written to D1, KV, R2, analytics, traces, logs, or the durable station conversation. Content-free counts, coarse result bands, transport types, latency, model version, and error classes may be recorded to operate and protect the service. Because the profile is ephemeral and anonymous, the operator cannot identify or delete it after the page discards it.

Cloudflare processes ordinary network and request metadata to deliver and protect the service. Sampled Worker invocation logs contain request and response metadata, not MCP request bodies, and are retained for no more than seven days. The site also writes aggregate usage events to Cloudflare Workers Analytics Engine. These events include the public surface, normalized route, response status and latency, browser interaction type, public API operation or MCP tool name, and an opaque content ID when an item is opened, requested, or returned. Search events use only categorical scope, provider, result-count and latency bands, selected rank/source/type, and match or fallback outcome. They never include the search text, a search hash, titles, excerpts, result IDs, or destination paths. A returned item records exposure, not a confirmed human interaction. The Analytics Engine dataset does not include IP addresses, user agents, referrers, query strings, search text, MCP request bodies, response bodies, or OAuth and owner activity. Analytics Engine retains events for three months. When the private analytical-lakehouse pilot is enabled, allowlisted facts without browser visitor identifiers may also be written as append-only records to a private Cloudflare R2 Data Catalog. That pilot also records content type, publication state (including unpublished and archived records), canonical ID, and mutation version, plus bounded load counts; it does not copy titles, summaries, source payloads, or other D1 record bodies. Its recorded policy is to retain usage and load facts for no more than 396 days and content-version facts indefinitely. Snapshot expiration alone does not delete rows, so the pilot must add and test row deletion before representing the 396-day policy as technically enforced.

Sentry processes browser errors, stack traces, console logs, failed-request and browser reports, performance traces and metrics, trace-linked browser profiles, and Session Replay so client failures and performance can be diagnosed. Session Replay records every participating browser session, including interactions and canvas content, but masks page text and form inputs and blocks media by default. The site does not install Sentry’s user-feedback widget. Sentry’s default PII collection remains disabled. Query strings and URL fragments are removed from request and navigation URL fields before reports are sent. Global Privacy Control and browser “Do Not Track” disable Sentry reporting as well as browser analytics.

If you email for support, the email address and message you provide are used only to respond and are deleted within twelve months after the last support response.

The Feed email is a closed, invitation-only preview. If Brendan invites you and you accept in your browser, the site processes your email address, selected daily, weekly, or monthly frequency, invitation and unsubscribe state, and limited delivery metadata. The address is encrypted before it is stored in a dedicated Cloudflare D1 database separate from the site’s content, OAuth, and agent databases. Invitation and unsubscribe credentials are stored only as cryptographic hashes. Invitations expire after seven days and can be used once. A confirmed record is retained while the subscription is active; after unsubscribe, the suppression record is retained so the site does not resume sending without a fresh invitation. Messages are sent individually through Cloudflare Email Service, whose suppression controls also prevent delivery after qualifying bounces or complaints. The emails have no open pixels, recipient-level click tracking, or rewritten links, and never expose one subscriber to another.

Private Google account connections

The authenticated owner dashboard lets only the site owner connect a Google account for two optional intake features. YouTube intake requests read-only access to the owner’s YouTube account so it can identify the channel and liked-videos playlist, read playlist membership, and stage eligible public, embeddable videos for the owner’s private review. Google Calendar intake requests the owner’s basic Google identity and read-only Calendar access so the owner can choose an exact calendar allowlist and stage eligible concert and sports events for private review. These permissions do not let the site modify YouTube or Google Calendar data.

Google access and refresh tokens are stored in dedicated, access-controlled Cloudflare KV namespaces and are used only by the corresponding private intake Worker. The YouTube connection retains the channel identity, liked-playlist identity, collection checkpoint, and the minimum membership data needed to reconcile later unlikes. The Calendar connection retains the account identity, selected calendar identifiers, sync checkpoints, and scrubbed eligible event observations. Calendar event descriptions, attendees, organizers, conference details, attachments, private URLs, email addresses, phone numbers, street addresses, and access codes are discarded before review storage or model processing. Neither connection gives Google data to advertising systems, sells it, or uses it to train a generalized AI model.

Google account data is used only to provide and secure the owner-requested intake feature, consistent with the Google API Services User Data Policy, including its Limited Use requirements. Disconnecting a provider from the owner dashboard revokes the Google grant and removes the stored credential. To request deletion of retained Google-derived review or checkpoint data, contact brendanib@gmail.com.

How information is used and shared

Information is used to operate, secure, troubleshoot, and improve the service. It is not sold, rented, used for advertising, or used to build cross-session user profiles. Cloudflare processes limited data as the hosting, storage, remote-fetch protection, and AI provider. Sentry processes the browser observability data described above as the error, performance, and replay provider. Google processes the private OAuth authorizations and API requests described above under its own policies. Meta separately processes messages sent through WhatsApp. Spotify processes anonymous Embed playback, while a listener-named public site, Open-Meteo, and Nager.Date process the bounded requests described above under their own policies. An AI host such as ChatGPT or Codex separately processes what you send through that host under its own terms and privacy policy.

Taste Explorer may show links or media from third-party sites. Those services receive information only when your client loads their permitted resource or you choose to open their link, and their own policies apply.

Your choices

Do not include personal or sensitive information in a recommendation chat, ACP prompt, taste description, public MCP query, or personal-site profile. Use only public URLs you are authorized to submit. You may clear radio tuning at any time; reload or close the page to discard all in-memory profile and affinity state. You may also start a new anonymous browser chat at any time. Closing an ACP session cancels active work and releases its live connection; retained session and conversation state still expires within 24 hours. Discarding the anonymous ACP cookie prevents that client from resuming its prior sessions. Browser analytics uses a random identifier stored for up to 24 hours to estimate daily unique browsers; it is not connected to an account or used to build a profile. Global Privacy Control and browser “Do Not Track” disable browser analytics and Sentry reporting. You may block JavaScript or local storage without losing the public content, APIs, or MCP tools. Every digest has an unsubscribe link and supports email-client one-click unsubscribe; an unsubscribe takes effect immediately. To request deletion of a chat, support email, or digest record, contact brendanib@gmail.com.

Children and changes

The service is not directed to children under 13. Material changes to this policy will be posted here with a new effective date.

Contact

Questions about this policy may be sent to brendanib@gmail.com.