Privacy
What Vigil collects, why it collects it, and what it deliberately does not. This is an informational notice, written to be checked rather than agreed to.
The short version
Vigil does not use advertising cookies, does not build profiles of readers, and does not sell or share data with advertisers. Reading Vigil requires no account and no personal information of any kind. The one place Vigil asks for something is the newsletter, and it asks for an email address and nothing else.
Vigil Dispatch — the newsletter
What is collected
Your email address. That is the whole subscriber record. Vigil does not ask for your name, your country, your employer, your job title, your age, your interests or which conflicts you follow, and there is nowhere in the signup form to provide them. There is one list, so there is nothing to segment you into.
Vigil does not send the newsletter provider your IP address, the page you subscribed from, or anything about what you have read. Those fields exist in the provider's interface and are deliberately left empty — the signup request carries the address alone.
Why
To send you Weekly Briefs, to send you significant Analytical Notes, and to manage your subscription status — confirming it, and ending it when you ask. It is not used for anything else.
Who processes it
Email delivery and subscription management are handled through Buttondown, a newsletter provider. Your address is stored there so that it can be sent to, and so that an unsubscribe can be honoured. Buttondown publishes its own privacy policy and terms; this page describes only what Vigil does and what Vigil sends.
Confirmation is required
Subscribing uses double opt-in. Submitting the form does not subscribe you: it sends one email asking you to confirm, and until you click the link in it you receive nothing further. If you did not ask to subscribe, ignoring that email is enough — no further mail follows it.
Unsubscribing
Every edition carries an unsubscribe link, and your mail client's own unsubscribe button works too. Unsubscribing takes effect without needing to give a reason, and you will not be asked to confirm it.
How long it is kept
Vigil has not set a fixed retention period, and states that rather than inventing one. Your address is held while your subscription is active. After you unsubscribe, the provider retains a record for the purpose of not mailing you again — a suppression record is how an unsubscribe is honoured, and deleting it entirely would make a later re-import able to undo your choice. To have your record removed altogether, write to the address below and it will be deleted through the provider's own deletion mechanism.
Tracking in the emails
Open tracking is off and click tracking is off. Vigil's editions contain no tracking pixel, so Vigil cannot tell whether you opened one, and links in them are ordinary links to Vigil pages rather than redirects through a tracking domain. The provider defaults both to off and Vigil leaves them off.
Links from an edition do carry campaign tags — see below. Those describe the link, not you.
Campaign attribution
When Vigil publishes a link somewhere — a YouTube Short, a post on X, an edition of the newsletter — that link carries campaign tags, and opening it records five fields:
- source — the channel the link was published on
- medium — the kind of publication it was
- campaign — which piece of Vigil content it was promoting
- content — optional, which of several links it was
- landing path — the Vigil page the link opened
A timestamp is added by the storage layer. That is the entire record, and it describes a link, not a reader.
What is not recorded, at any layer: no cookie, no browser storage of any kind, no visitor identifier, no session identifier, no fingerprint, no advertising identifier, no IP address as a stored field, no referrer, no user agent, no country, no full URL, and no name, email or account. There is nothing in the record that could be joined to a person, and nothing stored elsewhere to join it to. The tags are also removed from the address bar after the page loads, so a URL you copy and share is the clean one.
This is described in full, including the code that implements it, in Vigil's own attribution documentation. The two files are src/lib/attribution.ts and functions/api/campaign.ts.
Site analytics
Vigil uses Cloudflare Web Analytics for overall site usage — how many visits pages receive, and coarse aggregates such as path, referring host, country, device type, browser and operating system. It sets no cookies and does not follow visitors between sites.
It is configured to exclude visitor data in the EU: for visitors geolocated in the European Union, Cloudflare does not inject its measurement script at all, and those visits are not counted. This is a deliberate setting, and it means Vigil's own visit figures structurally undercount European readers.
Hosting
The site is served by Cloudflare Pages. As with any web server, requests reach Cloudflare's network and are handled there; Cloudflare's own processing is covered by its documentation, not by this page.
One detail worth stating because Vigil chose it: the subscription endpoint reads the connecting IP address to apply a rate limit, holds a shortened one-way hash of it in memory for a few minutes, and writes it nowhere. It is not stored, not logged, and not sent to the newsletter provider.
What Vigil does not do
- No advertising, and no advertising or analytics cookies.
- No selling, renting or sharing of reader data.
- No cross-site tracking and no third-party trackers embedded in pages.
- No profiles of individual readers, and no attempt to build one.
- No account system, and nothing that requires you to identify yourself to read.
Contact
Questions about anything on this page, or a request to delete a subscriber record: [email protected].
This notice describes what the software does. It is informational, and it is not a legal determination about which regulations apply to Vigil or to you.