Privacy Policy
Effective date: July 14, 2026
This policy explains how The Human Playbook ("we," "us," "our") — the publisher of TheoHartley.com — collects, uses, and protects your personal information. "Personal information" means anything that identifies you or can reasonably be linked to you. We built this site to be light on data by design: no ads, no data sales, and we collect only what running a publication requires.
Who we are
The Human Playbook publishes educational content about patterns in human behavior. Theo Hartley, the voice of the publication, is a fictional persona created and operated by a human team. Questions about this policy or your data: matan@theohartley.com.
What we collect
- Email subscription data. If you subscribe to the weekly newsletter, we collect your email address and, over time, engagement data (opens, clicks) through our email platform. Subscribing is voluntary; every email includes an unsubscribe link that works immediately.
- Technical data. Like nearly every website, our hosting and content-delivery infrastructure (Amazon Web Services CloudFront) automatically logs requests — IP address, browser type, pages visited, timestamps — for security and performance. We do not use this to identify individuals.
- Analytics data — only with your agreement. If you accept analytics (see Analytics and cookies below), we collect which pages you view, which site referred you, an approximate location derived from your IP address (city/country level — never a precise position), your device and browser type, and a random visitor ID stored in your browser. We use this to see which articles land. It is never linked to your email address, and we do not use it to work out who you are.
- Correspondence. If you reply to a newsletter or email us, we keep the correspondence. Readers sometimes share personal stories or sensitive information about relationships, emotions, or mental health. You are never required to share this; anything you send is shared at your own discretion, and you can ask us to delete it at any time.
- Member account data (when membership launches). If you create a member account for full articles, we will collect your email and login credentials via our membership provider. This policy will be updated before that launches.
We do not knowingly collect data from children under 16. This site is intended for adults.
How we use it
- To send you the newsletter and content you asked for (legal basis: your consent).
- To operate, secure, and improve the website (legal basis: legitimate interest).
- To respond when you contact us (legal basis: legitimate interest / consent).
- To measure which articles resonate, so we write better ones (legal basis: your consent if you are in the UK or EEA; legitimate interest elsewhere).
We do not sell your personal information. We do not share it for cross-context behavioral advertising. We do not run ads.
Who we share it with
Only service providers who process data on our behalf, under their own contractual confidentiality obligations:
- Email platform (Beehiiv) — stores subscriber emails and sends the newsletter.
- Hosting and content delivery (Amazon Web Services) — serves the website and holds server logs.
- Email service (Microsoft 365) — handles our correspondence mailboxes.
- Analytics (PostHog) — measures site traffic, and only ever runs if you have agreed to it.
We may also disclose information if required by law, or to establish, exercise, or defend legal claims.
Where your data goes
We are a small publication using established providers, and some of them store data in the United States — including PostHog (analytics) and Beehiiv (newsletter). If you are in the UK or EEA, that means your data may be transferred outside your country to a jurisdiction whose privacy laws differ from your own. Where those transfers happen, they rely on the safeguards our providers put in place — principally the European Commission's Standard Contractual Clauses — and, for analytics specifically, on your consent, which you can withdraw at any time using the control below.
Analytics and cookies
We use PostHog to count pageviews and see which articles actually get read. That is the only analytics on this site. We run no advertising, we do not sell or share your data with advertisers, and we do not track you across other websites. We have deliberately left session recording switched off — we do not watch recordings of your visit.
If you are in the UK or EEA: analytics does not run until you press Accept on the banner. Press Decline and nothing loads at all — no analytics script, no analytics storage, no data sent anywhere. Refusing is exactly as easy as accepting, and if you ignore the banner we treat that as a no.
If you are outside the UK and EEA: analytics runs by default, and you can switch it off at any time using the control below. We honour that choice everywhere, regardless of where you live.
When analytics is on, it stores a random visitor ID in your browser so that a returning reader is not counted as a new person. It is not connected to your name or your email. This site sets no advertising cookies of any kind. We remember your answer to the banner in a single browser entry named thp_analytics_consent — that one is stored without asking, because it is the only way to honour your answer on the next page.
Member accounts
If you create a free member account, we collect your email address and a password. Accounts are stored and managed by Amazon Cognito (AWS, our infrastructure provider); we never see your password. Signing in stores an authentication token in your browser’s local storage so you stay signed in on this device. It exists only to keep you signed in, is not used for tracking or advertising, and is removed when you sign out. To delete your account, use the contact below and we will remove it. Members can post public responses to articles; the display name and text you submit are published with the article and stored with your account id. Contact us to remove a response. To power member features, we also keep with your account a record of which articles you have read and rated as a signed-in member.
How long we keep it
Subscriber data is kept while you are subscribed and deleted from active systems after you unsubscribe, subject to short backup-retention windows at our providers. Correspondence is kept as long as needed to handle it. Server logs rotate automatically. We delete or anonymize data once it is no longer needed.
Your rights
Depending on where you live (including under the GDPR and the California Consumer Privacy Act), you may have the right to access, correct, delete, or receive a copy of your personal information; to object to or restrict processing; to withdraw consent at any time (for analytics, use the on/off control in Analytics and cookies above — no email needed); and to complain to your local data-protection authority. We honor these requests regardless of jurisdiction where practicable, without discrimination. To exercise any of them, email matan@theohartley.com. Unsubscribing from the newsletter needs no email — use the link in any issue.
California residents: we have not sold or shared personal information as defined by the CCPA/CPRA in the preceding 12 months.
Security
The site is served exclusively over HTTPS, subscriber data lives with established providers, and access to it is limited to the small team operating the publication. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security; if a breach affecting you requires notification by law, we will notify you.
Changes
We may revise this policy as the publication grows (for example, when memberships or paid products launch). The current version always lives at this address; material changes will be flagged in the newsletter.