Last updated 14 August 2026
Privacy & essential cookies
faded loads the beehiiv signup form only after you explicitly choose to open it. The current deployment uses optional, consent-gated Google Analytics and essential cookies for sign-in and security; it does not include advertising trackers.
Who controls the data
The data controller for faded is Matias, operator of the faded Workshop. For privacy questions or requests, email matias@faded.email.
What happens before you open the signup form
The beehiiv form, its iframe, and its third-party storage are not loaded until you select the button to open the signup form. If you explicitly change the site language, faded stores that preference as faded:lang in your browser’s localStorage. This preference is not used to track you.
Email signup and beehiiv
After you choose to open it, the secure form is loaded from subscribe-forms.beehiiv.com. Your purchase intent response and marketing consent are stored by beehiiv together with your email address, subscription and confirmation status. beehiiv also receives UTM attribution parameters from the page URL and technical security data needed to provide the form and prevent abuse. The form may use cookies or localStorage on the beehiiv origin for essential form and bot-protection functions.
Subscriptions use double opt-in. Nothing is purchased or reserved by subscribing. You can unsubscribe through any newsletter email.
After confirmation, beehiiv sends faded a subscription-confirmed webhook. Cloudflare stores an opaque beehiiv subscription identifier, active status, event identifier, limited campaign attribution, and a keyed HMAC-SHA-256 matching value derived from the confirmed email; the raw webhook email is not stored. To request Telegram access, your browser sends the email you enter to the bridge, which derives the same keyed value and discards the raw request value. The site then creates a short-lived random Telegram claim and stores only its SHA-256 hash. When you open the claim in Telegram, the bridge receives an HMAC-pseudonymized fingerprint instead of your raw Telegram user ID. The bot stores the subscription identifier and attribution together with your Telegram user ID, book access, and reading progression. A subscription identifier alone cannot create a claim or grant access.
Web reader
The reader at read.faded.email shows the opening of each book to everyone. To unlock full books you request a private sign-in link: the site checks the keyed HMAC value of the email you enter against the confirmed subscription and sends a link that is valid for 15 minutes; the bridge persists its SHA-256 hash rather than the link token. Opening the link sets an essential faded_reader session cookie (HttpOnly, Secure, SameSite=Lax, 30 days) for read.faded.email that proves an active subscription when full book content is served. The current reader stores reading position in your browser’s localStorage (faded-reader-progress); the analytics event schema does not include saved games or reading-position contents.
Optional Google Analytics 4
On read.faded.email, Google Analytics 4 (Measurement ID G-WLWTJ1P75N) loads only after you give analytics consent in the reader. If allowed, Google may receive the page URL, IP address and browser/device information and may set analytics cookies; faded sends configured events for catalogue views, reading starts, story completion and sharing. The event allowlist excludes story commands, saved games, email addresses, reader-link tokens and payment details. The faded GA4 property is currently configured to retain event data for 2 months and user data for 14 months.
You can refuse analytics when first asked. To change or withdraw a saved choice later, select Analytics ⚙ in the reader and then No analytics. The reader then stops optional event collection and removes Google Analytics cookies accessible to the site; data already received remains subject to the retention periods above. Do Not Track and Global Privacy Control prevent the Google tag from loading.
Google explains its processing in How Google uses information from sites or apps that use its services.
Cloudflare analytics and security
Cloudflare Web Analytics helps us understand aggregate traffic and page performance. Cloudflare describes this service as privacy-first and states that it does not collect or use visitors’ personal data.
Cloudflare also protects faded and the beehiiv form from automated abuse and runs the confirmation-to-Telegram claim bridge described above. When a request appears suspicious, security cookies such as __cf_bm or cf_clearance may be set. These are essential security cookies, not advertising cookies, and may be accompanied by an automatic browser check or Managed Challenge.
Lawful bases
Where UK or EU data-protection law applies, faded relies on consent for marketing email and optional first-party and Google Analytics; steps taken at your request and provision of subscribed reader access for private links and the reader session; legitimate interests in securing the service, preventing abuse and maintaining reliable subscription state; and legal obligations where records must be kept for compliance or suppression purposes. You may withdraw consent without affecting processing that took place before withdrawal.
Retention
The private reader link is valid for 15 minutes and the reader session cookie for 30 days. First-party product analytics records are assigned a 90-day expiry and expired rows are deleted during subsequent collector activity. The GA4 property retains event data for 2 months and user data for 14 months. Subscription and suppression records are retained while the subscription is active and afterwards where needed to honour unsubscribe state, prevent stale webhook events from restoring access, resolve disputes or meet legal obligations. Provider-held data follows the provider’s own retention rules and account settings.
Providers and international processing
faded uses Cloudflare for site delivery, security, first-party storage and analytics; beehiiv for the signup form and newsletter; Google for consent-gated Analytics; Titan for email delivery; and Telegram when you choose the bot. These providers may process data in countries outside your own under their applicable safeguards.
beehiiv Privacy Policy · Cloudflare Privacy Policy · Google Privacy Policy · Telegram Privacy Policy
Your choices and contact
Depending on your location, you may have rights to access, correct, erase, restrict or object to processing, and receive a portable copy of personal data. You may withdraw marketing consent with the unsubscribe link in an email and analytics consent through Analytics ⚙ in the reader. To make a request, contact matias@faded.email. faded does not use personal data for solely automated decisions that produce legal or similarly significant effects.
You may also lodge a complaint with the data-protection supervisory authority in the country where you live or work, or where you believe an infringement occurred.
