Last updated July 29, 2026

Privacy

This notice explains what the public site and its service providers may process, why it is used, and the choices available to visitors.

Scope

This notice covers the public Version Record website and its embedded editor area. Public visitors do not need an account. Site editors authenticate with the separate Sanity and GitHub services, which process editor account information under their own terms and privacy notices.

Version Record is an independently operated website based in the United States. Its controller and operator is Bradley Fosler. The site operator controls the editorial dataset, analytics configuration, and the purposes described in this notice. Hosting, analytics, content-management, domain, and project providers may act as service providers or as independent controllers under their own notices.

Information processed to operate the site

Like most hosted websites, the infrastructure serving this site may process request and diagnostic information such as an IP address, requested URL, date and time, browser or device details, referrer, response status, and security signals. This information is used to deliver pages, prevent abuse, diagnose failures, and understand service performance.

Vercel hosts the application. Cloudflare manages the site’s domain and may also process requests when its proxy or security features are enabled. Sanity hosts the editorial release dataset and editor workspace.

Vercel Web Analytics

Vercel Web Analytics is active on the public site so the operator can understand overall traffic and which pages are useful. It records a page-view timestamp, the cleaned page URL or dynamic path, the referring page, coarse geographic information, operating system, browser, device type, and the version of Vercel’s analytics script. Version Record removes query strings and fragments from the visited URL before the page-view event is sent.

Vercel uses request information to create an anonymized hash for counting visits without setting a cookie. That hash changes each day, so it is not a persistent identifier. Vercel Web Analytics does not create a persistent cross-site visitor profile. The resulting reports are aggregated, and the site does not use this service to collect names, email addresses, credentials, or free-form visitor text.

The /studio editor area is excluded from Vercel Web Analytics. The public site does not link into Studio.

Google Analytics 4 is dormant

The site retains an implementation of Google Analytics 4 for possible future use, but production Google Analytics is currently disabled. The Google tag does not load, no Google Analytics preference panel is shown, and no page views or events are sent to Google Analytics.

If Google Analytics is reactivated, it will be optional. Consent Mode will initially deny analytics storage, advertising storage, advertising user data, and ad personalization. The Google tag will remain unloaded until a visitor selects “Accept analytics.” Accepting will grant analytics storage only; advertising settings will remain denied. A saved choice will be changeable later through an analytics-preferences control.

After opt-in, Google Analytics may process page URLs and titles, referrers, general device and browser information, approximate location, engagement data, and identifiers used to distinguish visits. Structured product events may describe actions such as viewing a release or forecast, filtering a platform, exporting a calendar entry, or interacting with a timeline. Event properties will be limited to product context rather than visitor-typed content.

The /studio editor route will remain excluded from Google Analytics if it is reactivated.

Google Search Console

Google Search Console provides the site operator with search and indexing reports, such as queries, impressions, clicks, ranking position, and crawl issues. It does not require a separate analytics tag on this site. Google independently controls the information it processes when people use Google Search.

Why information is processed

  • Requests, security signals, and diagnostics are processed as reasonably necessary to deliver, protect, and maintain the site and to pursue the legitimate interest in operating a reliable public reference.
  • Cookieless Web Analytics is used to understand aggregate traffic and improve the public reference. It does not use analytics cookies or a persistent cross-site visitor identifier.
  • If Google Analytics is reactivated, it will be processed only after opt-in and that choice will be changeable through “Analytics preferences.”
  • Public corrections and feedback are processed because the sender chose to submit them and because reviewing the public dataset is a legitimate editorial interest.
  • Information may also be processed when necessary to comply with a legal obligation or protect the rights and safety of the site, its operator, or others.

These descriptions are intended to explain the site’s practices, not to limit rights that apply under a visitor’s local law.

Advertising status

Advertising is not currently active. The site does not currently load Google AdSense, Google Ad Manager, or another advertising tag. The presence of this notice or an ads.txt file alone would not mean that ads are running.

If advertising is introduced, this notice will be updated before activation to name the provider and explain the information used. Required consent and opt-out controls will be added for applicable regions, and paid placements will be labeled. Advertising will not be used to alter the historical dataset or forecast calculation.

Privacy choices and rights

Depending on where a visitor lives, applicable law may provide rights to request access, correction, deletion, portability, or restriction of personal information; to object to certain processing; to withdraw consent without affecting earlier processing; and to complain to a local data-protection authority.

Vercel Web Analytics does not set an analytics-choice cookie or provide an on-site preference panel. Visitors can use browser content-blocking controls if they do not want the analytics script to load. If Google Analytics is reactivated, its on-site control will handle the opt-in choice without requiring a request. For another privacy request, use the private role address shown below when configured. A request may require enough information to identify the relevant record and verify that the requester is entitled to it. Version Record cannot directly fulfill requests for information controlled independently by Google, GitHub, Vercel, Cloudflare, Sanity, or another provider.

Contact and correction submissions

Sourced release additions and corrections can be submitted through the private editorial form. The report, evidence links, optional email, and optional public credit are stored in a dedicated private Sanity dataset that is separate from public site content and research exports. Nothing is published automatically. Reports opened in GitHub remain public.

Privacy questions that require a private reply can be sent to business@bradleyfosler.com.

Service providers and disclosures

Information is processed by service providers only as needed for hosting, domain delivery and security, editorial content, cookieless traffic analytics, any future consented Google Analytics, and project communication. Those providers may process information in countries outside the visitor’s own. They maintain their own privacy notices and legal obligations.

Information may also be disclosed when reasonably necessary to comply with law, protect the site or its users, investigate abuse, or complete a legitimate transfer of the project. There is currently no advertising-data sale or cross-context behavioral advertising program on the site.

Retention

Vercel’s anonymized request hash changes daily. Aggregated Web Analytics reports are retained under the site’s Vercel plan and provider settings. If Google Analytics is reactivated, its saved choice will remain in local browser storage until it is changed or site storage is cleared, and its user-level event-data retention will be configured to two months; aggregated reports may remain available longer. Operational and security records are retained under provider settings for as long as reasonably needed to deliver, secure, and troubleshoot the service.

Raw private submissions and contact details are scheduled for deletion or anonymization within 180 days, normally sooner after resolution. Approved public credit may remain on a release record with the submitter’s consent. Public GitHub submissions and their revision history can remain visible after an issue is closed. Editorial source records are retained while useful to document and correct the public dataset. Legal, fraud-prevention, or security needs may require a longer period.

Children

The site is a general technical reference and is not directed to children under 13. It does not ask public visitors to create an account or submit a birth date. If a future feature intentionally collects visitor contact information, this notice and the feature design will be reviewed before launch.

Changes to this notice

This notice may change as the site adds features, vendors, or advertising. The date at the top will change when a material update is published. Continued availability of an old cached copy should not be treated as the current notice.