The Owlery Works

This website

Privacy notice

Version 1.2 · effective 31 August 2026

Reading this site is anonymous. The only place you can give us anything is the support form, and even there an email address is optional.

Browsing

This site sets no cookies and runs no tracking script, tag, pixel or third-party code. Every font, image and script it uses is served from this domain; the site's own security policy forbids loading anything from anywhere else, so a tracker could not be added by accident.

Our web server keeps standard access logs — the requested URL, the time, the response code, the browser's user-agent string and the connecting IP address — for a fortnight, because a server that cannot see its own traffic cannot be defended or debugged. They are not used to build a profile of anyone and are not shared.

How visits are counted

We do count visits — from those logs, on our own server, and from nothing else. The counts say which pages were read and roughly by how many people, which site or search engine they came from, which country, what kind of device, and whether the link to the App Store was followed. They are kept for two years and contain no addresses, no names and no identifier of any kind.

To tell "one person, five pages" from "five people, one page each" without a cookie, the counter keeps — for the current day only — a hash of your IP address and browser string, made with a random key that is thrown away the next day. It cannot be reversed, it is never stored with a page view, and it is gone within two days; two visits on different days cannot be linked, by us or by anyone. This is the method the privacy-first counters use (Plausible, Fathom), except that ours runs here and sends nothing anywhere. Country is looked up in a public IP-to-country table kept on the server (DB-IP Lite, CC-BY 4.0), not asked of any service.

A link that brings you here with campaign tags in it (utm_…) is counted under that campaign. Links to the App Store leave through this site's own address (/go/…) so the click can be counted, and carry the campaign's name on to Apple so that App Store Connect can attribute the download to it — from there, Apple's privacy policy applies.

The support form

When you raise a case we store exactly what the form sends:

  • which app the case is about, and what kind of problem it is;
  • what you wrote in the description box;
  • the device and version line, if you filled it in;
  • your email address, only if you chose the "email me a reply" option;
  • anything you add to the case later through the follow-up box under it, and when you added it;
  • the case number, and the times the case was created and last updated.

Two more things are kept for 24 hours and then deleted, and both exist only so that pressing the button twice does not leave you with two cases (or one follow-up twice): a random token the page makes up for that one submission, and a short hash of the report itself. Neither identifies you — the token is meaningless, and the hash is calculated from the words you already sent us.

Not stored: your IP address, any browser or device fingerprint, any referrer, and any identifier that would let two cases be recognised as coming from the same person. The case service records none of those, by design and not by policy. The 24‑hour token above is deliberately not one of those either: a fresh one is made for every submission, so it cannot link two.

The anonymous path

If you take a case number instead of giving an email address, the number is the only link between you and the case. We cannot tell who raised it, cannot contact you, and cannot recover it for you if you lose the number. That is the trade the option is making, and it is why the number is shown large and asked to be kept.

The summary on the case page

Anyone holding a case number can read its page, so the page never shows the report itself. It shows a short summary instead, written on our own server by a small language model that runs on the same machine as the case service and sends nothing anywhere — no AI service is involved. The model is told to leave out names, addresses, numbers and anything quoted from a meeting, and email addresses, links and long numbers are removed from what it writes automatically. It is still written from what you typed, which is one more reason to keep personal details out of a report. The summary is stored with the case and deleted with it, and it is the one part of a case that leaves our server: it is included in the email that tells us a case was raised. See who else sees any of this.

If you give an email address

It is used to answer that case and for nothing else. It is not added to a list, because there is no list. It is deleted when the case is closed; the case itself remains, with the address removed.

How long any of it is kept

Cases are retained for 12 months after they are closed, so that a number you kept still resolves to something, and then deleted.

Please leave personal and sensitive details out of it

The support form is an ordinary web form and what you type in it reaches our server. Meeting Cue's own guarantee — that nothing from a session leaves your device — cannot cover text you paste into a browser.

So please keep names, addresses, phone numbers, account or card numbers, and anything said in the meeting out of the box. Describe the fault, not the content. If something like that does reach us, quote the case number through the form and ask for it to be deleted — or say nothing and it goes when the case does.

The "I’m ready to send" box

Ticking it asks our server for a short-lived pass that the report will not be accepted without. It is not a Google or Cloudflare CAPTCHA — no other company is contacted, nothing is scored, and nothing about how you moved your mouse is looked at. The pass is random, meaningless, used once and then forgotten; it is not stored with your case.

It is also the last prompt to keep personal and sensitive details out of the report. We would rather never receive them than have to look after them.

What this browser remembers

When you raise a case, the support page saves the case number in this browser's local storage so it can offer it back to you later. That is local storage, not a cookie: it is never sent with a request, never seen by our server, and never leaves this device. The "Forget them" button on the support page erases it, as does clearing your browser's site data.

For completeness, because "no cookies" should mean what it says: there is exactly one cookie this domain can ever set, and you will never be given it. It is the sign-in for a private page we use to read the visit counts described above — not part of this website, not linked from it, and reachable only by us. Reading this site, browsing it, or using the support form sets nothing, ever.

Who else sees any of this

There is no analytics provider, no email marketing platform, no CRM, no support desk product and no advertising network. The case service runs on our own server, and what you write in a report stays on it.

Three companies are involved in this website existing at all: the one that rents us the machine, the certificate authority that issues its TLS certificate, and the company that runs our mailbox. The first two are given no case content whatever.

The mail provider is there because a case that nobody notices is not support. When a case is raised, our server emails us to say so, and that email contains the case number, which app it is about, which of the four topics you chose, the time, and whether you left an address — plus the short summary described above, the same text the lookup page would show anyone holding the number. It does not contain your report, and it does not contain your email address. If you reported anonymously, nothing in that email could identify you, and the summary has already had names, addresses and phone numbers taken out of it.

We would rather it carried nothing at all, and it nearly does. But an email saying “a case exists” still passes through a company that is not us, and this page would be lying if it said otherwise.

Your rights

Under the Australian Privacy Act, and the GDPR or similar law if it covers you, you may ask what we hold about you, ask for it to be corrected, and ask for it to be erased. For a support case, quote the case number through the support form and say what you want done. For an anonymous case, the number is the only proof of ownership there is — which also means anyone holding it can make that request, so keep it to yourself.

Changes

If what this site collects ever changes, this page changes with it and the version and date above move. There is no archived earlier version to compare against; the git history of the site is the record.

Contact

The Owlery Works, Sydney, Australia. Through the support form, anonymously if you prefer. For what the apps themselves do, see Meeting Cue's privacy policy.