Privacy notice
Fernwrite collects as little as it can. This page lists all of it, in plain language.
Last updated 22 August 2026
The short version
This site runs no analytics and sets no trackers of its own. It does show adverts supplied by Google, which is the one third party that can see you were here. The only personal data we hold ourselves belongs to people with an author account, plus a log of sign-in attempts we keep for security.
If you are just reading
You don't need an account to read, and nothing is set to track you. Your light or dark preference is saved in your own browser and never leaves your device.
Each article counts how many times it has been read. That's one number per article. It isn't linked to you, your account or your IP address.
Adverts
Adverts on this site are served by Google AdSense. To do that, Google receives your IP address and information about the page you are on, and may read or write cookies in your browser. We never send Google your name, email address or anything from your account, and we do not see who you are from the adverts either.
You can review and change what Google uses at My Ad Center, and read what it collects in Google's notice for partner sites. If you are in the UK or the EEA you will be asked for consent before any advertising cookie is set, and you can change that answer at any time from the link in the footer of the consent notice.
If you have an author account
We create accounts by hand; there's no public sign-up. For each one we store:
- your name and email address, so you can sign in and be credited on what you publish
- a bcrypt hash of your password, never the password itself
- an optional bio and avatar image, if you add them
- the articles you write, including drafts, and any images you upload
Sign-in security log
We record every sign-in attempt, successful or not, along with the email address used, the outcome, the IP address, the browser user-agent and a timestamp. It exists to catch and slow down password guessing. That's the only thing it is used for; never analytics, never profiling.
Under the UK and EU GDPR our lawful basis for this is legitimate interest: keeping accounts secure. We keep these records for 90 days, then delete them.
Cookies
One cookie, set only after you sign in: a refresh token that keeps you signed in. It is httpOnly (unreadable by JavaScript), Secure, SameSite=Strict, and expires on its own. Signing out deletes it.
There are no advertising, analytics, or cross-site cookies, so there is no cookie banner.
Who else sees your data
Nobody buys it and nobody is given it. It passes only through the services we need to run the site: our host, our database provider and the object storage that holds uploaded images. Each of them works on our instructions and nothing else.
How long things are kept
- Account details: until the account is deleted
- Published articles: until you delete them, or close the account
- Sign-in security log: 90 days
- Sign-in sessions: they expire on their own, and end the moment you sign out
Your rights
If you live in the UK, the EU or somewhere with similar law, you can ask us for a copy of your data, correct it, have it deleted, or object to how we use it. Write to hello@fernwrite.com and we'll reply within 30 days. You can also complain to your local data protection authority if you'd rather.
Changes
If we change anything here that affects you, the date at the top changes and we tell account holders directly. You may also want our terms of use.