handwritten.blog
sign in start your blog

Privacy

Last updated: 2 August 2026

handwritten.blog is run by Emile Silvis in the Netherlands. This page describes what the service actually handles, why it is needed, where it goes, and the controls available to you. Questions or privacy requests can be sent to hello@handwritten.blog.

What we collect

  • Account and security data: your email address, a one-way password hash, email-verification state, announcement preference and its last-change time. Signed-in sessions record an IP address and user agent so the service can authenticate requests and protect accounts.
  • Your blog: its address, title, description and optional custom domain; posts and pages; transcripts; original image or PDF uploads and derived display images; handwritten-link rectangles and destinations; publishing state; and the optional homepage-featured preference.
  • Email: addresses, message content, attachments and delivery metadata needed to send account mail and announcements you choose, or to receive post-by-email messages. The application keeps a Resend message ID and processing result for inbound mail so a retried webhook cannot publish the same message twice.
  • Service operation: request paths, times, IP addresses, browser or device information and error details may appear in hosting logs. Custom-domain setup also stores DNS and certificate state.

Marketing-page analytics

Public pages on the main handwritten.blog marketing site use Umami Cloud to count page views and understand which public pages are useful. Umami receives the page URL and title, referrer, browser, operating system, device type and approximate country. Its tracker does not use cookies, collect form contents or store personally identifying analytics data.

Umami does not run on registration, sign-in, password, dashboard, admin or webhook pages; on any author's blog or custom domain; inside RSS; or in a downloaded blog export. It is not used to build advertising profiles or an algorithmic feed.

Why we use it

We use this data to create and secure accounts, host and publish the blog you ask us to publish, deliver requested email, provide exports, configure custom domains, operate and troubleshoot the service, prevent duplicate or abusive requests, and understand aggregate use of the public marketing pages. We do not sell personal data or run ads.

Processors

  • Fly.io hosts the Rails application, SQLite databases, background jobs, operational logs, volume snapshots and custom-domain certificates.
  • Tigris, provisioned through Fly.io, stores page images, generated display variants and blog-export ZIP files in S3-compatible object storage.
  • Resend sends application and announcement email and receives mail addressed to handwritten.blog, including post-by-email messages and attachments.
  • Umami Cloud processes the anonymous, cookie-free marketing-page analytics described above.

These providers process data only where their part of the service requires it. Email may also reach the provider chosen by the sender or recipient.

Retention and deletion

  • Account and blog records stay while the account exists. Signing out deletes that session; a password reset deletes every existing session.
  • Deleting a blog removes its posts, pages, links and attached images. Deleting the account removes the account, sessions, blog and its content. Storage deletion runs in the background, and deleted database records can remain briefly in Fly.io's rolling volume snapshots, whose current default retention is five days.
  • Original uploads that back current sheets remain with those sheets so the portable export can include them. Failed uploads are kept for up to 30 days so you can retry; unattached uploads left by an interrupted request are eligible for cleanup after one day.
  • A generated blog export has a download link for 24 hours. The ZIP and its request record remain attached to the account until the account is deleted; deleting only the source blog does not delete an already generated export.
  • The minimal inbound-email delivery ledger (Resend message ID and result) and a custom-domain hostname awaiting certificate cleanup can outlive a deleted blog so retries remain safe and provider resources can be removed. The application does not keep the fetched raw inbound message in that ledger.
  • Operational logs and processor-side copies follow the processors' current operational retention. Umami analytics age out under the current Cloud plan or can be deleted from the service account. Resend's processing terms cover email content and metadata held to deliver and receive mail.

Your controls

From dashboard settings you can correct account and blog details, change announcement consent, remove a custom domain, and turn off homepage featuring. You can create a portable blog export containing blog metadata, posts and pages (including drafts), transcripts, original uploads, display images and handwritten links. It does not contain your password, sessions, account email or inbound-message ledger.

You can delete your blog or account in the danger zone. For access, correction, deletion or another privacy request that the dashboard cannot handle, email hello@handwritten.blog.

also scribbled here: about terms privacy hello@handwritten.blog