teahubery Sign in

Privacy

What each surface records.

teahubery is not one website. It is a small set of separate surfaces, and they behave differently. This page says what each one does, in the terms the code actually uses. Last checked against the running system on 13 August 2026.


This page and the sign-in page

The public pages here set no cookie and make no request to any other host. If you use the light and dark toggle, one value is stored in your browser's local storage so the choice survives a reload. Nothing is sent anywhere when you do.

Signing in sets a session cookie, because that is what a session is. It is restricted to this site, marked HttpOnly and Secure, and it ends when the session ends. Sign-in is for the operator of the estate. There is no self-registration.

Published note, document and slide releases

Releases served from the note, document and slide surfaces are fronted by an access-recording layer. For each visit it records: the time, which release was opened, the kind of event (opened, decrypted, decryption failed, downloaded, printed, closed, or blocked by policy), your IP address, a salted one-way hash of that address, the country, region and city the network reports, the network operator and its number, your browser's user-agent string, the host that referred you, and any label the sender attached to the link. A visitor cookie named tvid is set for one year so repeat visits from the same browser can be counted as one visitor rather than many.

These records are kept in a database in the operator's own Cloudflare account. There is no third-party analytics service, no advertising identifier, and nothing is shared with anyone outside the operator. There is also no automatic deletion: records persist until the operator removes them.

The thesis reader

The thesis surface does not carry the access-recording layer. If a reviewer signs in with a name and an access code to leave comments, then their name, their comments, and the passage each comment is anchored to are stored, along with the time. Comments are for the author to read.

The quotations reader

No access recording, and no cookie beyond the light and dark preference in local storage.

What is never recorded

Published material is encrypted before it is uploaded, and its decryption key travels only in the fragment of a link, the part after the #. Browsers do not send fragments to servers, so the key is never received, never logged and never stored. The recording layer additionally refuses any submitted value shaped like a key, so an accident cannot put one in the database.

The host stores ciphertext. It cannot read what it serves.

Asking about your data

Every teahubery link is shared deliberately by a person. If you hold one and want to know what has been recorded against it, or want it removed, ask whoever sent it to you: they can reach the operator, and the operator can answer for that release specifically.