The paperwork
Privacy policy
We collect almost nothing, and the delete button is real. Last updated 3 September 2026.
What we collect
When you order: the villain's first name, the villain type, your one-line grievance, an optional gift note, and your email address. That is the whole list. There are no accounts, no passwords, and no profiles.
What we never see
Your payment details. Checkout happens entirely on Stripe's hosted page; card numbers never touch our servers. Stripe's own privacy policy governs what they process.
What happens to the name
The first name on your slip is written onto the paper effigy, used in the ritual, and burned with it at the bridge. A copy stays in your private space (below) so you can see what you ordered. Once the ritual is done, "Burn the page" there erases the name, the grievance and any gift note from our records permanently; there is no undo and no backup we keep. Order confirmations containing your email are kept as business records, as required for accounting.
The public notebook
The free notebook at /notebook stores everything in your own browser (localStorage) and sends nothing to us. Not a copy, not a word count. Clearing your browser clears it. Pages only reach our database if you later sign into your space and they move into the synced notebook.
Your space
The space holds your order history, a one-week check-in per delivered ritual (three possible answers, stored so you can see them later), and the synced notebook. Synced pages are stored for your eyes; we don't read them, and burning one deletes it from our database permanently, the same way "Burn the page" works on an order. There are no passwords: we email a short-lived code to the address from your order, and after a payment you are signed in automatically. Signing in sets one cookie, strictly necessary for the space to work: it holds a signed session for your email address, nothing else, and expires after 30 days or when you log out. Records live in a database at Cloudflare (D1).
Who processes data for us
Stripe (payment and checkout), Resend (delivery, notification and login-code email), Cloudflare (hosting and the order database), and PostHog (analytics, described below). Each receives only what it needs to do its job.
Cookies and analytics
Browsing this site sets no cookies; the register's session cookie (described above) appears only when you sign in, and it is the only one we set. We use PostHog to see which pages get read and whether visitors reach the order form, using local browser storage rather than a cookie. PostHog never receives the villain's name or your one-line grievance: the only order-related detail it sees is the villain type (for example "toxic boss"), attached to no name and no email. We do not run session recording and we do not auto-capture what you type. If your browser sends a Do Not Track signal, we turn PostHog off for that visit. Stripe's checkout page sets its own cookies for fraud prevention, on Stripe's domain, outside our control.
Your rights
Email us to ask what we hold about you, to correct it, or to have it deleted. Since we delete the sensitive part on our own after delivery, most requests are already done before they arrive.