Skip to content
The Point of Failure

Privacy

This site does not need to know who you are.

It is a set of static pages about how systems fail. Reading them requires no account, no consent, and no transaction in which your attention is the payment. What follows is an exact account of the little that is collected, and a longer account of what is not.

In effect from

Section 01. The short version

There is no account to create, no form to fill in and no newsletter to join, so nothing on this site asks for your name, your email address or anything else about you. The pages are static files.

What remains is the unavoidable exhaust of serving a web page (a request log at the hosting layer) and a video player that stays inert until you press play. There is no analytics on this site today; if that changes it will be the cookieless kind, on the terms set out below, and this page will say so first. Nothing is sold, shared with advertisers, or used to build a profile of you. There is no cookie banner because there is nothing to consent to.

That is the summary. The sections below are the actual policy.

Section 02. What this site collects

Directly, from you: nothing. There is no sign-up, no comment box, no contact form, no search that reaches a server, and no tracking pixel in an email, because there is no email list.

Automatically, as a consequence of serving pages: the server logs in section 04, and nothing else. section 03 covers the measurement this site does not currently do, and the terms it would be held to. If you choose to write to us, section 07 covers what happens to that.

Section 03. Analytics

There is no analytics on this site. No counter, no measurement script, no third-party tag: the only record that a page was read is the request log in section 04.

That may change (knowing whether an episode is read is worth something), and if it does, this section will be rewritten before the change ships rather than after. These are the terms any such service would have to meet, published in advance so that they can be held against us:

  • no cookie may be set, and nothing may be written to your browser
  • no cross-site identifier, advertising ID or persistent device fingerprint may be created
  • your IP address may be used only in transit (to derive a country, and as one input to a daily hash that tells one visit from another), and never stored
  • that daily hash must be discarded when the day ends, so the same browser tomorrow is a new visit and cannot be joined to today
  • the data that can be seen must be aggregate: page, referrer, country, browser family, and counts

No view of it in which a single visitor could be singled out, no way to follow one person from page to page over time, and no connection to any advertising system. It would exist to answer one question: is this being read, and by way of which links? Nothing beyond that.

Section 04. Server logs and hosting

The site is served by a hosting provider, which records what any web server records in order to deliver a page and defend itself against abuse: IP address, timestamp, the URL requested, the response code, the user agent, and the referring page.

These are operational records held by the host on our behalf, on the host’s own short retention schedule: days, not years, and set by the host rather than by us. They are not used to identify visitors and not compiled into reports. They are looked at when something is broken or under attack, and otherwise expire unread. They are not indexed in a way that would let us find, extract or delete one person’s entries.

Section 05. Cookies and browser storage

This site sets no cookies, and writes nothing to localStorage or sessionStorage, unless you press play on an episode video, which loads YouTube’s player and lets Google store data in your browser under its own domain. section 06 explains exactly what that involves.

That is why there is no consent banner and no preference to manage. The only storage this site can cause is storage you start yourself, by pressing a button that does nothing else.

Section 06. The video player

An episode page does not contain a video player. It contains a still image and a play control. Until you click it, your browser makes no request to YouTube or to any other Google service. The still itself is served from this domain, so even the thumbnail does not announce you to a third party.

When you press play, an embedded player loads from youtube-nocookie.com. From that moment your browser is talking to Google, and what happens is governed by Google’s privacy policy, not this one. The embed runs in YouTube’s no-cookie mode and the referrer sent with it is limited to this site’s origin, which reduces what is shared. It does not eliminate it, and the player is granted the device permissions an embedded video player is normally granted.

If you would rather not load it, do not press play. Every episode’s full transcript, sources and incident record are on the page as text, and the site is built so that reading it is a complete experience.

Section 07. If you write to us

Write to us about a correction, a rights request or anything at all, and we receive your address and whatever you put in the message, held with our email provider. We delete correspondence within twelve months of the matter it concerns being closed, unless we are required to keep it longer.

Where a message leads to a correction, the change is noted on the relevant episode page. The note records what was corrected, not who reported it, unless you ask to be credited.

Please do not send sensitive personal information. There is no purpose for which this site would need any.

Section 08. What this site never does

Some of this is already implied above. It is set out plainly because the absence of a practice is worth stating as clearly as its presence. Before you press play, and whether or not you ever do, there is:

  • no advertising, retargeting or conversion pixels
  • no personal data sold, rented or shared with data brokers
  • no social-network tracking scripts, share widgets or like buttons that call home
  • no fonts, scripts or stylesheets loaded from a third-party CDN; they are served from this domain
  • no device or browser fingerprinting by this site
  • no attempt to link your visits into a profile, across sites or over time

Two exceptions, stated so that the list above can stay absolute. We will disclose what we hold if we are legally compelled to, and we will say so publicly where we are permitted to. And if the series is transferred to another operator, correspondence and the records described here transfer with it, subject to this policy until the new operator publishes its own.

Section 09. Legal basis, and your rights

Zof AI, the operator of The Point of Failure, is the data controller for the limited processing described above. Where UK or EU data protection law applies, the lawful basis is legitimate interests under Article 6(1)(f): keeping the site online and secure, and knowing in aggregate whether it is being read. That interest is narrow, and the processing has been designed down to the minimum that satisfies it. For correspondence, the basis is our legitimate interest in answering you.

Depending on where you live, you may have the right to access, correct, delete, restrict or port the personal data an organisation holds about you, to object to its processing, and to complain to a regulator. For most visitors we hold nothing that could be linked to you, so an access request will return nothing. That is the design, not an evasion. Where we do hold something, such as an email you sent, write to privacy@thepointoffailure.com and we will respond within 30 days. If a request is complex, or if we need to establish who you are first, we may take longer than that, up to the period the applicable law allows, and we will tell you inside the 30 days that we are doing so, and why.

California

The categories of personal information this site collects, in the terms the CCPA uses: identifiers and internet activity (an IP address, a user agent, the page requested and the referring page). They are collected automatically from your browser when it requests a page, for the purpose described in section 04, and are disclosed only to the service provider that hosts the site. Retention is as set out in that section. If you write to us, we also hold the contents of your message and your email address, for the period in section 07.

We do not sell or share personal information as the CCPA and CPRA define those terms, and have not in the preceding twelve months. We do not use or disclose sensitive personal information for inferring characteristics. We honour the Global Privacy Control signal, though on this site it has nothing to switch off; there is likewise no tracking here for a Do Not Track header to disable. You may use an authorised agent to make a request. Exercising a right will never cause you to be treated differently here; there is no service to degrade.

UK and EEA

If you are not satisfied with how we answer, you may complain to your supervisory authority, which in the UK is the Information Commissioner’s Office.

Section 10. Where this is handled

The site is hosted on infrastructure in the United States, and our email provider is US-based. If you visit from outside the United States, the request data described above is processed there.

The United States is not covered by a general adequacy decision under UK or EU data protection law. Where our providers process the data of UK or EEA visitors, we rely on the safeguards those providers offer for transfers of this kind: certification under the EU-US Data Privacy Framework and its UK Extension, or the European Commission’s Standard Contractual Clauses with the UK Addendum. Write to privacy@thepointoffailure.com and we will tell you which mechanism applies to which provider.

Section 11. Children

This site is not directed at children under 13 and does not knowingly collect personal information from them; there is nothing here to sign up for. If you believe a child has sent us personal information, write to privacy@thepointoffailure.com and we will delete what we hold once we can confirm the request is genuine. Server logs at the hosting layer expire on their own schedule and cannot be searched or deleted entry by entry.

Section 12. Changes to this policy

When this policy changes, the date at the top of the page changes with it. If a change is material (new collection, a new category of processor, a new purpose), we will say what changed rather than silently reissuing the page. A series about things being quietly altered and nobody noticing is in no position to do that to its own policy.

Section 13. Contact

Zof AI, operator of The Point of Failure. 1 Ferry Building, San Francisco, CA 94111.

Privacy and data protection: privacy@thepointoffailure.com
Everything else, including rights in material used in an episode: legal@thepointoffailure.com, covered by the terms of use.

Terms of use

What you may do with the episodes, the transcripts and the research, including quoting, citing and training on them.

Read it →