PRIVACY
POLICY
This site is a place to listen to records and buy them. It is built to need as little about you as possible, and this page says exactly what that means.
the short version
- No account is needed, and none can be created.
- No cookies are set for visitors, so there is no consent banner to dismiss.
- No advertising, no third-party analytics product, no tracking pixels, no social embeds. The visitor counting is the site’s own; the one thing sent anywhere else is an IP address, to be turned into a city name for a map — see below.
- Nothing about you is sold, rented or shared for anyone else’s marketing.
- Buying a download goes through the payment provider, who need what they need to take a payment. This site is never given your card details, and never asks you for an address to put on a mailing list.
who is responsible
xJAH operates xjah.dev and decides what is recorded here and why — in data-protection terms, the controller. You can reach a person through the contact form.
what is recorded, and why
Visits
Every page view is counted so the operator knows which records people are actually listening to. That count is deliberately built not to identify anyone: there is no cookie and no stored IP address. Your address and browser string are combined with a server-side secret and today’s date, hashed, and only the hash is kept — the address itself is never written down, the hash cannot be turned back into it, and because the date is part of it, the same person tomorrow is simply a different number. Alongside it the site keeps the page path, the referring site if your browser sent one, a coarse city and country, and a coarse device class — “mobile, safari, ios” and nothing more precise. That is enough for a map, not enough for a doorstep.
How the city is worked out
Where the network in front of this site supplies a location, that is what gets used and nothing leaves the building. Where it does not — which is the case on the hosting this site currently runs on — your IP address is sent to a geolocation service, which answers with a city and a country. That is the one thing about you that reaches a third party, it is asked at most once per visitor per day, the answer is all that is kept, and the address itself is still never written down here. It is used for a dot on a map in the operator’s dashboard and for nothing else — no profile is built, and nothing is sold or shared onward. The operator can switch this off entirely, in which case the map simply shows fewer places.
Plays and downloads
When a track is played or a file is taken, that event is recorded against the track, not against you, so the site can show how many times a record has been downloaded.
Payments
Downloads are paid for, and payments are handled entirely by Polar, who take the card details and any billing information they need on their own systems — this site never sees or stores a card number. What comes back and is kept here is the amount, the currency, the status, and the provider’s reference for the order, so a download can be attributed and a receipt makes sense. Their own privacy policy covers what they hold; a link to it sits at the checkout.
Messages
If you use the contact form, what you type is stored so it can be read and answered: your name, your email address, the subject and the message itself, plus the coarse country described above. It is not forwarded to a mailing list, and there is no mailing list to forward it to.
The Control Room
The operator’s own sign-in sets a single session cookie. It exists only for the person administering the site and is never set for a visitor.
how long it is kept
the legal basis
Where the UK GDPR and the EU GDPR apply, the site relies on legitimate interests for counting visits and downloads — a deliberately anonymous count is a low-impact way to know whether anyone is listening — and on performance of a contract for processing a payment you have made to make. Answering a message you sent relies on legitimate interests too: you started the conversation.
Because no cookies or similar identifiers are stored on your device for analytics, the UK PECR and EU ePrivacy consent requirements are not triggered. That is a design decision, not an oversight.
who else touches it
These providers process data on the operator’s behalf, under their own terms and security obligations. Nobody else receives anything.
Some of these operate outside the UK and EEA. Where that involves a transfer of personal data, it is covered by the providers’ standard contractual clauses.
your rights
If the UK or EU GDPR applies to you, you can ask for a copy of anything held about you, ask for it to be corrected or deleted, object to it being processed, or ask for the processing to be restricted. If you are in California, you can ask what is collected and ask for deletion, and you can be certain of the answer to the third question: nothing here is ever sold or shared for cross-context advertising.
Write through the contact formand you will get an answer within 30 days. One honest limitation: because visit statistics carry no identifier tied to you, there is usually no way to find “your” rows in them, and no way to delete them individually. Messages and payment records can always be found and removed.
If you think this has been handled badly you can complain to your data protection authority — in the UK, the Information Commissioner’s Office.
children
The site is not directed at children under 13 and does not knowingly keep anything about them. There is nothing to sign up for, so there is nothing for a child to hand over.
security, and its limits
Traffic is served over HTTPS, media is delivered from object storage over signed or public URLs, and the Control Room sits behind a password with rate-limited sign-in. No system is perfect, and this one is run by one person; if you find a problem, the contact form reaches them directly.
changes
If this policy changes, the date at the top changes with it. Material changes will be noted on the site rather than slipped in quietly.
This page describes how xjah.dev works today. It is written to be accurate and readable rather than exhaustive, and it is not legal advice.
