Last updated 14 August 2026

Privacy & essential cookies

faded loads the beehiiv signup form only after you explicitly choose to open it. The current deployment uses optional, consent-gated Google Analytics and essential cookies for sign-in and security; it does not include advertising trackers.

Who controls the data

The data controller for faded is Matias, operator of the faded Workshop. For privacy questions or requests, email matias@faded.email.

What happens before you open the signup form

The beehiiv form, its iframe, and its third-party storage are not loaded until you select the button to open the signup form. If you explicitly change the site language, faded stores that preference as faded:lang in your browser’s localStorage. This preference is not used to track you.

Email signup and beehiiv

After you choose to open it, the secure form is loaded from subscribe-forms.beehiiv.com. Your purchase intent response and marketing consent are stored by beehiiv together with your email address, subscription and confirmation status. beehiiv also receives UTM attribution parameters from the page URL and technical security data needed to provide the form and prevent abuse. The form may use cookies or localStorage on the beehiiv origin for essential form and bot-protection functions.

Subscriptions use double opt-in. Nothing is purchased or reserved by subscribing. You can unsubscribe through any newsletter email.

After confirmation, beehiiv sends faded a subscription-confirmed webhook. Cloudflare stores an opaque beehiiv subscription identifier, active status, event identifier, limited campaign attribution, and a keyed HMAC-SHA-256 matching value derived from the confirmed email; the raw webhook email is not stored. To request Telegram access, your browser sends the email you enter to the bridge, which derives the same keyed value and discards the raw request value. The site then creates a short-lived random Telegram claim and stores only its SHA-256 hash. When you open the claim in Telegram, the bridge receives an HMAC-pseudonymized fingerprint instead of your raw Telegram user ID. The bot stores the subscription identifier and attribution together with your Telegram user ID, book access, and reading progression. A subscription identifier alone cannot create a claim or grant access.

Web reader

The reader at read.faded.email shows the opening of each book to everyone. To unlock full books you request a private sign-in link: the site checks the keyed HMAC value of the email you enter against the confirmed subscription and sends a link that is valid for 15 minutes; the bridge persists its SHA-256 hash rather than the link token. Opening the link sets an essential faded_reader session cookie (HttpOnly, Secure, SameSite=Lax, 30 days) for read.faded.email that proves an active subscription when full book content is served. The current reader stores reading position in your browser’s localStorage (faded-reader-progress); the analytics event schema does not include saved games or reading-position contents.

Optional Google Analytics 4

On read.faded.email, Google Analytics 4 (Measurement ID G-WLWTJ1P75N) loads only after you give analytics consent in the reader. If allowed, Google may receive the page URL, IP address and browser/device information and may set analytics cookies; faded sends configured events for catalogue views, reading starts, story completion and sharing. The event allowlist excludes story commands, saved games, email addresses, reader-link tokens and payment details. The faded GA4 property is currently configured to retain event data for 2 months and user data for 14 months.

You can refuse analytics when first asked. To change or withdraw a saved choice later, select Analytics ⚙ in the reader and then No analytics. The reader then stops optional event collection and removes Google Analytics cookies accessible to the site; data already received remains subject to the retention periods above. Do Not Track and Global Privacy Control prevent the Google tag from loading.

Google explains its processing in How Google uses information from sites or apps that use its services.

Cloudflare analytics and security

Cloudflare Web Analytics helps us understand aggregate traffic and page performance. Cloudflare describes this service as privacy-first and states that it does not collect or use visitors’ personal data.

Cloudflare also protects faded and the beehiiv form from automated abuse and runs the confirmation-to-Telegram claim bridge described above. When a request appears suspicious, security cookies such as __cf_bm or cf_clearance may be set. These are essential security cookies, not advertising cookies, and may be accompanied by an automatic browser check or Managed Challenge.

Lawful bases

Where UK or EU data-protection law applies, faded relies on consent for marketing email and optional first-party and Google Analytics; steps taken at your request and provision of subscribed reader access for private links and the reader session; legitimate interests in securing the service, preventing abuse and maintaining reliable subscription state; and legal obligations where records must be kept for compliance or suppression purposes. You may withdraw consent without affecting processing that took place before withdrawal.

Retention

The private reader link is valid for 15 minutes and the reader session cookie for 30 days. First-party product analytics records are assigned a 90-day expiry and expired rows are deleted during subsequent collector activity. The GA4 property retains event data for 2 months and user data for 14 months. Subscription and suppression records are retained while the subscription is active and afterwards where needed to honour unsubscribe state, prevent stale webhook events from restoring access, resolve disputes or meet legal obligations. Provider-held data follows the provider’s own retention rules and account settings.

Providers and international processing

faded uses Cloudflare for site delivery, security, first-party storage and analytics; beehiiv for the signup form and newsletter; Google for consent-gated Analytics; Titan for email delivery; and Telegram when you choose the bot. These providers may process data in countries outside your own under their applicable safeguards.

beehiiv Privacy Policy · Cloudflare Privacy Policy · Google Privacy Policy · Telegram Privacy Policy

Your choices and contact

Depending on your location, you may have rights to access, correct, erase, restrict or object to processing, and receive a portable copy of personal data. You may withdraw marketing consent with the unsubscribe link in an email and analytics consent through Analytics ⚙ in the reader. To make a request, contact matias@faded.email. faded does not use personal data for solely automated decisions that produce legal or similarly significant effects.

You may also lodge a complaint with the data-protection supervisory authority in the country where you live or work, or where you believe an infringement occurred.

Обновлено 14 августа 2026 года

Конфиденциальность и необходимые cookie

faded загружает форму подписки beehiiv только после того, как вы явно решите её открыть. Текущая версия использует необязательную Google Analytics только с согласия и необходимые cookie для входа и безопасности; рекламные трекеры в неё не включены.

Кто отвечает за данные

Контролёр данных faded — Matias, оператор faded Workshop. По вопросам конфиденциальности и для запросов напишите на matias@faded.email.

Что происходит до открытия формы

Форма beehiiv, её iframe и third-party storage не загружаются, пока вы не нажмёте кнопку открытия формы. Если вы явно меняете язык сайта, faded сохраняет эту настройку как faded:lang в localStorage браузера. Она не используется для отслеживания.

Подписка и beehiiv

После явного открытия защищённая форма загружается с subscribe-forms.beehiiv.com. Ответ о намерении приобрести книгу и маркетинговое согласие сохраняются beehiiv вместе с email, состоянием подписки и подтверждения. beehiiv также получает UTM-параметры атрибуции из URL страницы и технические данные безопасности, необходимые для работы формы и защиты от злоупотреблений. На origin beehiiv форма может использовать cookie или localStorage для необходимых функций формы и anti-bot защиты.

Используется двойное подтверждение подписки. Подписка ничего не покупает и не резервирует. Отписаться можно по ссылке в любом письме.

После подтверждения beehiiv отправляет faded webhook о подтверждённой подписке. Cloudflare сохраняет непрозрачный идентификатор подписки beehiiv, активный статус, идентификатор события, ограниченную атрибуцию кампании и ключевое HMAC-SHA-256 значение, полученное из подтверждённого email; исходный email из webhook не сохраняется. Для запроса доступа в Telegram браузер передаёт введённый вами email bridge, который вычисляет такое же ключевое значение и не сохраняет исходное значение запроса. Затем сайт создаёт короткоживущий случайный Telegram claim и хранит только его SHA-256 hash. При открытии claim bridge получает HMAC-псевдонимизированный fingerprint вместо исходного Telegram user ID. Бот сохраняет идентификатор подписки и атрибуцию вместе с вашим Telegram user ID, доступом к книгам и прогрессом чтения. Один идентификатор подписки не может создать claim или выдать доступ.

Веб-ридер

Ридер на read.faded.email показывает начало каждой книги всем. Чтобы открыть книги полностью, вы запрашиваете приватную ссылку для входа: сайт сверяет ключевое HMAC-значение введённого email с подтверждённой подпиской и отправляет ссылку, действующую 15 минут; bridge сохраняет её SHA-256 hash вместо исходного токена. При открытии ссылки устанавливается необходимая сессионная cookie faded_reader (HttpOnly, Secure, SameSite=Lax, 30 дней) для read.faded.email. Текущая версия ридера сохраняет позицию чтения в localStorage браузера (faded-reader-progress); схема аналитических событий не содержит сейвы или содержимое позиции чтения.

Необязательная Google Analytics 4

На read.faded.email Google Analytics 4 (Measurement ID G-WLWTJ1P75N) загружается только после согласия на аналитику в ридере. При согласии Google может получить URL страницы, IP-адрес и сведения о браузере/устройстве и установить аналитические cookie; faded отправляет настроенные события просмотров каталога, начала и завершения чтения и публикаций. Allowlist событий исключает команды истории, сейвы, email, токены reader links и платёжные данные. В ресурсе GA4 сейчас установлено хранение event data 2 месяца и user data 14 месяцев.

При первом запросе можно отказаться. Чтобы позже изменить или отозвать сохранённый выбор, нажмите Analytics ⚙ в ридере, затем Без аналитики. Ридер прекращает необязательный сбор событий и удаляет доступные сайту cookies Google Analytics; уже полученные данные остаются до окончания указанных сроков. Do Not Track и Global Privacy Control блокируют загрузку Google tag.

Google описывает обработку на странице Как Google использует информацию с сайтов и приложений, использующих его сервисы.

Аналитика и безопасность Cloudflare

Cloudflare Web Analytics помогает понимать агрегированный трафик и производительность страниц. Cloudflare называет сервис privacy-first и указывает, что он не собирает и не использует персональные данные посетителей.

Cloudflare также защищает faded и форму beehiiv от автоматизированных злоупотреблений и выполняет описанный выше bridge между подтверждением и Telegram. Для подозрительного запроса могут быть установлены необходимые security cookies __cf_bm или cf_clearance, а браузеру может быть показана автоматическая проверка или Managed Challenge. Это не рекламные cookies.

Правовые основания

Когда применяются правила защиты данных Великобритании или ЕС, faded опирается на согласие для маркетинговых писем и необязательной first-party и Google Analytics; действия по вашему запросу и предоставление доступа подписчику для приватной ссылки и reader session; законный интерес в безопасности сервиса, предотвращении злоупотреблений и сохранении достоверного статуса подписки; а также юридические обязанности, когда записи нужны для compliance или списка отписавшихся. Отзыв согласия не влияет на обработку, выполненную до отзыва.

Сроки хранения

Приватная reader link действует 15 минут, cookie reader session — 30 дней. First-party события получают срок 90 дней; просроченные строки удаляются при последующей работе collector. В GA4 event data хранится 2 месяца, user data — 14 месяцев. Записи подписки и отписки хранятся во время активной подписки и после неё, когда это необходимо, чтобы учитывать отписку, не позволять старым webhook-событиям восстановить доступ, разрешать споры или выполнять юридические обязанности. Данные у провайдеров хранятся по их правилам и настройкам аккаунта.

Провайдеры и международная обработка

faded использует Cloudflare для доставки сайта, безопасности, first-party storage и аналитики; beehiiv для формы и рассылки; Google для Google Analytics с согласия; Titan для доставки email; Telegram — если вы выбрали бота. Эти провайдеры могут обрабатывать данные за пределами вашей страны с применением предусмотренных ими гарантий.

Политика beehiiv · Политика Cloudflare · Политика Google · Политика Telegram

Ваши права и контакты

В зависимости от вашей страны вы можете иметь право на доступ, исправление, удаление, ограничение обработки, возражение и переносимую копию персональных данных. Маркетинговое согласие отзывается ссылкой в письме, согласие на аналитику — через Analytics ⚙ в ридере. Для запроса напишите на matias@faded.email. faded не использует персональные данные для полностью автоматизированных решений с юридическими или сопоставимо значимыми последствиями.

Вы также можете подать жалобу в надзорный орган по защите данных в стране, где вы живёте или работаете либо где, по вашему мнению, произошло нарушение.