Privacy

Privacy & cookies

What Amplified Thinker collects, why, who else can see it, and what you can do about it.

Last updated 26 August 2026

The short version

  • Every page is free to read without an account, and nothing is stored about a guest's reading — not on our side, and not in their browser.
  • An account holds four things: your email address, your first name, a hash of your password, and your position in the primers and plans you open.
  • Nothing is sold or shared for marketing. There are no advertising cookies, no social pixels, and no cookies of any kind.
  • Two emails come with the account and cannot be switched off. Updates about new skills and features are opt-in, and turning them off never affects the two you asked for.
  • You can delete your account yourself, immediately, and no copy is kept.

1.What's in this policy?

This policy says what personal information Amplified Thinker collects, why, who else can see it, and what you can do about it. It is written for the UK, under the UK GDPR and the Data Protection Act 2018.

The whole site works without an account, and this policy covers you either way. If you are only reading, nothing about your reading is stored anywhere — no account, no profile, no history, and nothing written to your browser. What does exist is the ordinary server logs any website produces, and an anonymous page-view count. Sections 3 and 4 cover both.

If you create an account, we additionally hold your first name, your email address, a hash of your password, and your position in the primers and plans you open. That is the whole list. There is no advertising, no marketing list, and no profile built about you.

Each section says which of the two it applies to wherever that differs.

2.Who is responsible for my information?

The data controller — the person responsible for your information — is Sing Chen, an individual rather than a company. Amplified Thinker is a personal project, not a business, so the way to reach us is by email: contact@amplifiedthinker.com. That is a monitored address and the right one for any question, request or complaint about your information, including the rights in section 12. There is no Data Protection Officer; the site is small enough that one is not required.

3.What information do you collect about me?

Technical information — everyone, including visitors with no account. Our hosting and database providers keep the standard server logs any website produces: IP address, browser user-agent, timestamps, and which pages were requested. These exist for security and diagnostics. We do not try to work out who you are from them, and in practice we could not.

An anonymous page-view count — everyone. Every page includes Vercel Web Analytics. It sets no cookie and writes nothing to your browser. Visitors are told apart by a hash derived from the request, which is discarded after 24 hours, so it cannot follow you from one day to the next, let alone to another site. What is recorded with a page view is the time, the page address, the referring page, the country, region and city, the device type, and the browser and operating system version. No IP address is stored and no identifier is kept that could reconstruct your session.

Until 26 August 2026 the site was also published at sing-chen.github.io/amplifiedthinker, which carried no analytics at all. That address has been retired and no longer serves the site, so this is now the only place page views are counted.

Your account details — only if you sign up. Your first name and your email address, which you give us at sign-up, whether you asked for site-update email, a password stored only as a salted cryptographic hash, and — if you have ever answered either way — when you last changed that email preference. We never hold, and could not recover, the password itself — which is why a forgotten password is reset rather than looked up. Your first name is used to address the email the site sends, and to greet you on your account page.

Your progress — only if you sign up. Per primer and per plan: the slide or section you are on, which ones you have opened, your quiz answers and expanded sections, and when you started and finished. There is no record of which other pages you looked at, and no analytics identifier tied to your account.

What you save and what you write — only if you sign up. On the News page you can save a story, pin one story to the top of your own list, and write a private note against a story. We hold which stories you saved, which one is pinned, and the note itself — free text of up to 500 characters, stored exactly as you typed it. It is shown back to you and to nobody else, and it is never used to train AI models. Please keep sensitive personal information, about yourself or anyone else, out of a note — it is a place to record why a story mattered to you, not a file on a colleague.

Anything you email us — only if you choose to. If you write to the address above we hold your email address and whatever you write, for as long as it takes to deal with it. There is no contact form anywhere on the site, so nothing you send is written to our database.

4.Why do you use it, and what is your legal basis?

The first four rows apply to everyone, account or not. The rest apply only once you have an account — a contract is a basis we can rely on only where there is one, and reading the site is not a contract.

What forOur legal basis (UK GDPR Article 6)
Serving you the website at all, which necessarily involves your device's IP address reaching our providers Legitimate interests — Article 6(1)(f). We cannot deliver a page to you without it. Weighed against your rights and considered proportionate: it is the minimum a web request requires, and the data is not used to identify or profile you.
Keeping the site secure, available and free of abuse — including the bot check on the sign-in form Legitimate interests — Article 6(1)(f). Running a site that stays up and whose sign-up form is not used to send mail to strangers.
Counting page views, anonymously and in aggregate Legitimate interests — Article 6(1)(f). Knowing which pages are read at all, in order to decide what to write next. Limited to aggregate figures that cannot identify or re-identify anyone, and you have the right to object (section 12).
Replying to you if you email us Legitimate interests — Article 6(1)(f). Answering someone who has chosen to get in touch. Applies whether or not you have an account.
Creating your account and signing you in Performance of a contract — Article 6(1)(b)
Storing your position in the primers and plans, and giving it back to you on any device Performance of a contract — Article 6(1)(b)
Keeping the news stories you saved, the one you pinned and the notes you wrote, and giving them back to you on any device Performance of a contract — Article 6(1)(b)
Addressing you by name in the two emails, and on your account page Performance of a contract — Article 6(1)(b)
Sending the service email you have asked for — confirming your address, resetting your password Performance of a contract — Article 6(1)(b)
Sending you occasional updates about new skills and new features, if you opted in Consent — Article 6(1)(a), and Regulation 22 of PECR. Asked for at sign-up, never assumed, and withdrawable at any time from your account page, or from the unsubscribe link every such message will carry. No such message has been sent yet — see section 8. ⚠️ Withdrawing it has no effect on the account email above, which is not sent on this basis.
Telling you if this policy changes in a way that affects information you have already given us Legal obligation — Article 6(1)(c), read with the transparency duty in Articles 12–14. Not marketing, and not covered by the consent above.
Checking a password you have just chosen against a database of passwords exposed in past breaches Legitimate interests — Article 6(1)(f). Stopping an account being created behind a password already known to attackers. See section 7 for how it works without your password leaving the browser.

Consent is relied on for exactly one thing — the site-update email, and only if you asked for it — so that is the one thing there is to withdraw, and withdrawing it changes nothing else. Where we rely on legitimate interests you have the right to object; section 12 explains how. Nothing here involves automated decision-making or profiling that produces legal or similarly significant effects.

5.Does Amplified Thinker use cookies?

No. The site sets no cookies of any kind — not advertising cookies, not analytics cookies, not even a "strictly necessary" one. There is nothing here for you to accept or reject, which is why you have not been shown a cookie banner.

That is unusual enough to be worth explaining rather than just asserting. Most sites need a cookie to remember who is signed in; this one keeps that in your browser's local storage instead (section 6). Local storage is not a cookie, but the law treats the two the same — the Privacy and Electronic Communications Regulations govern storing any information on your device, whatever the mechanism. So the question that matters is not "is it a cookie?" but "what is stored, and is it necessary?"

Answered in the next section: everything stored on your device is either strictly necessary for something you asked for, or a setting you chose yourself. Page-view counting stores nothing on your device at all, which is why it does not need consent either — the regulations are not engaged by it.

6.What is stored on my device?

Up to four things, all written by your own browser and none of them readable by anyone else. The first happens whether or not you have an account:

ItemWhat it isHow long
theme Light or dark, as you set it. Read before the page paints, which is what stops the screen flashing the wrong colour. Written only at the moment you change the setting, and it never leaves your device — including for account holders, since nothing syncs it. Until you clear it
sb-…-auth-token Your sign-in session, written by our authentication provider. Strictly necessary: without it you would be signed out on every page. Removed when you sign out. The session
amplified_pw_recovery A timestamp, written only while you are part-way through a password reset, so that reloading the page does not drop you out of it. Nothing about you is in it. 30 minutes
amplified_… Leftovers. An earlier version of the site saved reading position in the browser for guests. That was removed, and any old entries are deliberately left untouched and unused rather than deleted behind your back. Until you clear them

None of it is shared with anyone, none of it follows you to other websites, and clearing your browser storage removes all of it. There is no third-party storage of any kind — with one exception, which is the subject of the next section.

One more thing touches storage for a fraction of a second and is named here for completeness rather than because it holds anything: on a page that talks to our authentication provider, its library writes a randomly-named value and deletes it immediately, purely to find out whether storage works in your browser at all. Nothing about you is in it and nothing is left behind.

7.What happens on the sign-in page?

Two things happen on the sign-in page and nowhere else on the site. Both exist to protect the account, and both are worth stating plainly.

A bot check. The form is protected by Cloudflare Turnstile, which usually resolves without you doing anything. It loads from challenges.cloudflare.com, so that host sees your IP address, and it may store data of its own on your device for the check. Cloudflare describes the signals it collects as strictly necessary for telling humans from bots; it does not use cookies to identify you and does not track you across sites. Without it, the sign-up form is an open invitation to send mail to strangers.

A check against known breached passwords. When you choose or change a password, your browser checks it against the Have I Been Pwned database of passwords exposed in past breaches. Your password is never sent anywhere. The check hashes it in your browser, sends only the first five characters of that hash, and receives back a list of matching hash endings to compare locally. Nobody at the other end can work out your password, which account it belongs to, or who you are. If the service is unreachable the check is skipped rather than guessed at, and you are told so.

8.What email will I get?

Three kinds, and only the first two are sent whether you want them or not.

  • Account email, always sent. A confirmation when you sign up, and a reset link when you ask for one. Both are triggered by you and neither can be turned off, because without them the account cannot be used.
  • Site updates, only if you ask for them. Occasional messages about what is genuinely new here — a skill added to the library, or a feature such as the learning tracker going live. You choose at sign-up whether to receive these, you can change your mind at any time on your account page, and every one of them will carry an unsubscribe link. We rely on your consent for these and you can withdraw it whenever you like.
    ⚠️ None have been sent yet, and none can be. The tickbox records your preference; the machinery to send to more than one person does not exist at the time of writing. If you have opted in and heard nothing, that is why — not an oversight, and nothing has been sent on your behalf.
  • A material change to this policy. If we change how we use information you have already given us, we will tell account holders rather than rely on you noticing. Covered in section 15. It is not marketing and is not affected by the choice above.

Turning site updates off never affects the first or third kind. That separation is deliberate: unsubscribing from news about the site must not be able to stop a password reset from reaching you.

All of it carries no open tracking and no click tracking. There is no invisible pixel reporting that you read a message, and links are not rewritten to record the click — which also means a reset link goes where it says it goes. Your address is never sold, rented, or used to send anything on anyone else's behalf.

9.Who else sees my information?

We do not sell your information and we do not share it for marketing. The site is run by one person, so a handful of services do the work that would otherwise need a server room. Each does one job:

ServiceWhat it doesWho it affects
SupabaseThe database, sign-in, and the accounts themselvesAccount holders
ResendDelivers the two account emails, and carries replies we send from the contact addressAccount holders; anyone who emails us
VercelHosts and delivers the site, and counts page viewsEveryone
CloudflareThe domain's DNS and email routing, and the bot check on the sign-in pageEveryone; the bot check, sign-in visitors only

Those services act under a data processing agreement and may not use your information for their own purposes. We may also disclose information where the law requires it.

One other is not our processor, and is called out separately for that reason.

  • Have I Been Pwned. Contacted only when you choose a password, and only ever sent the first five characters of a hash. See section 7.

Typefaces are served from this domain. Until 23 August 2026 every page loaded its fonts from fonts.googleapis.com and fonts.gstatic.com — a request your browser made on its very first visit, before you had done anything, and whether or not you ever created an account. Those servers saw your IP address as a result. The font files are now served from amplifiedthinker.com alongside the rest of the site, so that request is no longer made and no third party is involved in showing you the page.

10.Does my information leave the UK?

It may. Your account and the two account emails are handled in Ireland. Our hosting, DNS and bot-check providers operate internationally, so technical information such as an IP address may be processed outside the UK, including in the United States.

Where that happens the transfer is covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or another safeguard permitted under Article 46 of the UK GDPR, as set out in each provider's own agreement.

11.How long do you keep it?

Your account and your progress are kept for as long as your account exists. There is no expiry, no dormancy sweep and no archive.

Deletion is immediate and permanent. You can close your account yourself at any time from your account page. It asks for your password and then for your email address, because it cannot be undone. When it runs, the account, the profile, every progress record, every saved story and every note go together, in one operation. We keep no copy — there is no grace period and nothing we can restore afterwards. If you would rather ask us, email us instead.

The only residue is technical: any routine database backup the provider happens to hold ages out on its own schedule, server logs follow our providers' standard retention — measured in days to months rather than years — and mail already delivered sits in your own inbox, where you control it.

Email you send us is kept while we deal with it and for a reasonable period afterwards, in case the conversation continues, then deleted. It is never added to a mailing list, because there is no mailing list.

12.What are my rights?

Under the UK GDPR you have the right to see the information we hold about you; to have it corrected if it is wrong; to have it deleted; to restrict or object to how we use it; and to receive it in a portable, machine-readable format.

If you have an account, some of this you can do yourself without asking. Your first name can be changed on the account page, any note you have written can be edited or deleted from the story it is on, and the same page will close your account outright, which covers erasure. There is no self-serve export yet, so for a copy of your data, email us and we will put it together by hand — that is a limitation of the site, not of your right, and we will respond within one month.

If you do not have an account, the only information we hold that could relate to you is a server log entry containing your IP address. You have the same rights over it, including the right to object to our relying on legitimate interests. There is a limit worth being straight about: we have no way of telling which log entries are yours, so we cannot act on a request unless you can give us something that identifies them — and the UK GDPR does not require us to collect more information about you purely so that we can find you (Article 11). If you want to raise something, email us and we will do what we can.

If you are unhappy with how we have handled your information you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first, so we have a chance to put it right.

13.How do you keep it safe?

Everything travels over HTTPS. Your account is protected by access rules enforced by the database itself rather than only by the website, so one account cannot read another's progress, saved stories or notes even if the site were at fault. Passwords are stored only as salted hashes, a password already known to have been exposed in a breach is refused outright, and changing your password signs out every other device.

There is one limit we would rather state than let you assume away. Notes are private between accounts, and there is deliberately no page anywhere on this site — including any page only we can reach — that lists what people have written. But whoever runs a database can reach what is stored in it, and that is true here as it is everywhere: the person who administers this site could open the table directly. What is ruled out is a feature that surfaces your notes; what cannot be ruled out is administrative access to the database itself. Notes are not read for any purpose, and they are not used to train AI models.

No service is perfectly secure and we do not claim otherwise. If you think your account has been compromised, reset your password and tell us straight away.

14.What about children?

Amplified Thinker is written for working adults and is not intended for children under 13. We do not knowingly collect their information. If you believe an account has been created by a child, please get in touch and it will be removed.

15.How will I find out about changes?

If this policy changes we update the date at the top, and list anything material in What's New. Where a change affects how we use information you have already given us, we will tell account holders by email rather than relying on you noticing. That is the one message outside the two named in section 8, and it is not marketing.

16.How do I contact you?

Any question about this policy, or about your information: contact@amplifiedthinker.com. It reaches a person, not a ticket queue.

Still deciding whether to create an account? What an account actually gets you sets out the difference in one table. The rules of using the site are on the terms of use page.