The Blog Story
Last updated: August 2026
This policy explains what information The Blog Story collects when you read, write or comment here, why we collect it, how long we keep it, and the controls you have. It describes the platform as it actually works — if a practice is not described here, we do not do it.
Reading is open to everyone. You only need an account to write, comment or save posts.
To create an account we ask for an email address, a password, a handle (your @name) and a display name. We also record that you accepted the Terms & Conditions and confirmed you meet the minimum age, together with the version of the policies you accepted.
Passwords are never stored in readable form. They are hashed with Argon2, and nobody — including our staff — can recover the original password from what we store.
Your profile is optional beyond the basics. You may add a bio, avatar, cover image, personal website, social links, a support or patron link, and a theme for your author page. Anything you put on your profile is public. Profile privacy options let you limit what is displayed.
Posts (drafts, scheduled and published), post revisions, excerpts, featured images, SEO metadata, categories and tags, comments, uploaded media and its alt text, publications you create, and imported content. Drafts and private posts are visible only to you and to staff with the relevant permissions; published public posts are visible to everyone and may be indexed by search engines.
When you use the contact form we store the name, email address, topic, subject and message you submit, so we can reply and keep a record of the request. Reports and appeals you file are stored with their reason and any details you write.
If you subscribe to updates we store the email address, what you subscribed to, and whether you confirmed it. Subscribing requires you to confirm the address from a link we email you, and every email includes a one-click unsubscribe link.
When you sign in we create a server-side session and store the approximate device information your browser sends (user agent), the IP address the sign-in came from, and when the session was last active. You can review and revoke every session from your active sessions. We also count failed sign-in attempts so we can lock an account temporarily after repeated failures, and we apply rate limits to sensitive endpoints to blunt abuse.
Our analytics are first-party and deliberately minimal. For a page view we record only which post or path was viewed, the domain of the referring site (never the full referring URL), and a timestamp. For reading depth we record the post and a percentage. We do not record your IP address, your user ID, or any device fingerprint alongside these events, so no analytics row can be traced back to a person. Raw events are rolled up into daily totals, which is what authors and administrators see.
Our servers keep operational access logs (request method, path, response status, timing and a request ID) needed to run and debug the service.
We do not sell your personal data, and we do not share it with third parties for their own marketing.
You may sign in with Google where the operator has enabled it. When you do, we receive your Google account identifier, email address, name and profile picture, and store a link between that identifier and your account. We do not receive your Google password and cannot act on your Google account. An existing account is only linked automatically when the provider confirms the email address is verified. You can also create a password and sign in without the provider.
We set one essential cookie to keep you signed in. Non-essential technologies — including advertising — load only after you accept them in the consent banner. Full detail is in our Cookie Policy.
Some pages may show advertising. House ads are served by us and involve no third party. Where the operator has configured a Google AdSense account, approved posts may also show a Google ad unit — that script is loaded only after you accept non-essential cookies, and Google may then set its own cookies under its own privacy policy. Declining consent means no advertising script is loaded at all. See the Cookie Policy for details.
Passwords are hashed with Argon2. Sessions use an HTTP-only cookie that JavaScript cannot read, restricted to same-site requests and served over HTTPS in production. You can add TOTP two-factor authentication with recovery codes from security settings. Sign-in attempts are rate-limited and repeated failures lock the account temporarily, with an email to you. We apply standard browser protections including a content security policy, clickjacking protection and cross-origin request checks. No system is perfect, but we take this seriously and act on reports quickly.
Accounts are for people who meet the minimum age, which you confirm at registration. We do not knowingly collect information from children below that age. If you believe a child has created an account, tell us and we will remove it.
Your data is processed on the infrastructure that runs this site and by the service providers needed to operate it — hosting, database, object storage for uploads, and email delivery. They act on our instructions and only for the purposes described here.
We may update this policy. The date at the top always shows the current version. When a change is significant we increase the policy version, which asks you to review and re-accept the policies the next time you sign in.
For any privacy question, or to exercise a right described above, contact us: