about
Privacy
- Published
- Separator
- •
- Author
- rhizae
- Separator
- •
- Last updated
Who is responsible for this site, what it stores in your browser, what it asks other organizations for, how long any of it is kept, and what you can require of us.
Tags
- privacy
- data
- transparency
Who is responsible
rhizae Studio is the controller for everything described here. Write to hello@rhizae.studio with any question about it, including any of the requests listed under your rights. There is no data protection officer; the address above reaches the person who can answer.
This statement covers https://rhizae.studio and nothing else. Sites reached through links from here, including the one framed on the microsimulation page, are run by other people under their own terms.
What happens whether or not you choose anything
The pages are prerendered files served by Vercel, so Vercel receives the request data every web server receives: your IP address, the page requested, the time, your user agent, and the referring page if your browser sent one. That is processed on the basis of legitimate interests — serving the site at all, and being able to investigate abuse — and it is the minimum a site cannot avoid.
A small part of the site is not a prerendered file. Sign-in, sign-out and the internal document area run as server code, described under signing in. Everything a public visitor sees is a static file.
Site search runs entirely inside your browser. What you type into it is never sent anywhere.
What is stored in your browser
All of it is readable and removable by you, through your browser’s site data controls.
| What | Kind | Why | Kept for |
|---|---|---|---|
sidebar_state | Cookie | Whether the side panel is open | 7 days |
rhizae-theme-overrides | Local storage | Appearance, contrast and motion settings you set | Until you clear it |
rhizae-consent | Local storage | Your answer to the analytics question | Until you clear or change it |
None of these is sent to us, and none is used to recognize you. They exist
because the alternative is a site that forgets your contrast setting on every
page. The legal basis is legitimate interests, except for rhizae-consent,
which records a consent decision and is strictly necessary to honor it.
If you allow analytics, Google Analytics sets its own cookies as well. Declining means the script never loads, so those cookies are never set.
Five more cookies exist only for people who sign in to the internal area. They are listed below and are never set for a visitor who does not sign in.
What your browser asks other organizations for
Two, and only two:
- The framed microsimulation. The microsimulation explorer frames an application on
microsimulations.vercel.app, which is a separate deployment and therefore a separate origin. Loading that page connects your browser to it. The frame is sandboxed and sent withreferrerpolicy="no-referrer", so it is not told which page framed it. Nothing else on the site frames anything hosted elsewhere. - Formspree, but only if you use the pilot-inquiry form. What you type in it is sent to Formspree for delivery to rhizae. It is used to answer you and is not added to a marketing list. The basis is the steps you asked us to take before any agreement. You can email the address on the contact page instead, which involves no third party but your own mail provider.
Google is a third, and only after you say yes.
Everything else that came from somewhere else came from there when the site was
built, not when you visited. The follower count on the sidebar badge is read from
GitHub’s public API while the site is being assembled, so the number is already in
the page by the time it reaches you; GitHub is told that the site was built, never
that you loaded it. The PDF on the mortality-brief page is fetched from www.cdc.gov and the notebook on the music-recommendation page from raw.githubusercontent.com the same way, and both are then served to you as copies
from this domain. Your browser is never sent to any of these hosts, and none of them
is told that you exist.
Embedded documents are the stricter case: www.cdc.gov, raw.githubusercontent.com and microsimulations.vercel.app are the only hosts the
build is permitted to fetch one from at all.
Analytics, and the choice you get
This site uses Google Analytics 4, and only if you agree. Nothing is requested from Google until you do: the script is not on the page, so declining is not a setting that suppresses a request already in flight — it is the absence of the request. The legal basis is your consent.
If you allow it, five things are recorded. Nothing else is sent, because nothing else is defined:
- Page views. Which page, and its title.
contact_click. That someone used a contact link, email address, or the inquiry form. Not what they wrote.project_view. Which project page was opened, by the id already in its URL.theme_changed. Which appearance or accessibility control was changed and what it was set to. This is the one we most want, because it says which accessibility settings people actually reach for.external_link_click. The hostname a link led to, never the full address. A path can carry a search term or a token; a hostname answers the only question worth asking, which is where this site sends people.
Advertising storage, advertising personalization, sharing data for advertising purposes and any advertising identifier are refused permanently and regardless of your answer. This site runs no ads. Google Signals and advertising features are off in the property itself, so there is nothing to switch on.
Google Analytics 4 stores no IP addresses. The address is used in memory to derive
approximate location and then discarded, so there is no anonymization setting to
enable; the older anonymize_ip option does nothing in GA4.
Changing your mind
Open the theme panel — the Customize theme control in the header of every page — and use the Analytics setting at the bottom of it. Switching it to Decline stops the reporting immediately and tells Google’s consent mechanism to deny analytics storage. Switching it back to Allow starts it again.
Withdrawing is meant to be exactly as easy as agreeing was, which is why it is a
control on every page rather than an email to us. Your answer is remembered in
local storage under rhizae-consent; clearing your site data forgets it, and you
will be asked once more.
The banner needs JavaScript, like site search and the theme panel. Without JavaScript there is no banner, and there is also no analytics: nothing is recorded and nothing is assumed.
Signing in to the internal area
Browsing this site needs no account. The internal document area at /internal/ does, and it is for people who work on rhizae rather than for visitors. Signing
in is through GitHub, which tells us your GitHub username and whether you are a
current member of the organization, and tells GitHub that you signed in here.
Five cookies exist for it, all of them HttpOnly and Secure:
| Cookie | Why | Kept for |
|---|---|---|
rhizae_internal_session | The signed session itself | 8 hours |
rhizae_github_oauth_state | Blocks cross-site request forgery | 10 minutes |
rhizae_github_oauth_verifier | The PKCE verifier for the sign-in | 10 minutes |
rhizae_github_oauth_redirect | Where to return you after signing in | 10 minutes |
Google Analytics _ga and _ga_* | Only with consent, set by Google | Google’s own periods |
The three sign-in cookies are deleted the moment sign-in finishes, successfully or not. The session is a signed statement rather than a database row: there is no record of who signed in kept anywhere on the server. The basis is legitimate interests in controlling access to internal material.
How long anything is kept
The browser storage above is kept for the periods in that table. Vercel’s request logs follow Vercel’s own retention for the plan this site runs on. Analytics data is kept for the retention period set on the Google Analytics property, and that property is set to the shortest period Google offers. Anything you send through the inquiry form or by email is kept for as long as it takes to answer you and to keep a record of the enquiry, and you can ask for it to be deleted sooner.
Transfers outside the EEA and the UK
rhizae Studio operates from the United States, as do Vercel, GitHub, Google and Formspree. If you are in the EEA or the UK, everything above therefore involves a transfer to the United States. Each of those providers offers the EU Standard Contractual Clauses and the UK Addendum, and the first three are certified under the EU–US Data Privacy Framework.
Your rights
If data protection law applies to you, you can require us to give you a copy of what we hold about you, correct it, delete it, restrict what we do with it, or give it to you in a portable form. You can object to anything we do on the basis of legitimate interests. Where we rely on consent — which here means analytics and nothing else — you can withdraw it at any time, using the control described above, and doing so does not make what happened before it unlawful.
Ask through hello@rhizae.studio. If you are not satisfied with the answer you can complain to your supervisory authority: in the UK that is the Information Commissioner’s Office, and in the EEA it is the authority for the country you live or work in.
What is not done
No profiling. No automated decision-making of any kind, so nothing here produces a decision about you. Nothing is sold, and nothing is shared with anyone not named on this page. There is no tag manager and no advertising script. No special category data is collected, and nothing here is aimed at children.
Data from pilot projects
Any future project involving research data will require a separate agreement. The proposed standards for custody, retention, deletion, consent, and publication are set out in Governance and Research and data ethics.
Questions about any of this can go through the contact page or straight to hello@rhizae.studio.