somehowfunctional.com ("we," "us," "the site") Last updated: July 12, 2026
The short version
What you log in our tracking tools stays on your device. We never receive it, and no ads or analytics scripts load on any page that is part of a tracker.
That is not the same as being invisible. Our server sees that you requested a page, the same way every website's server does. It never sees what you logged. Section 2 draws that line exactly.
The blog and other general pages of the site use cookieless analytics, and may carry advertising in the future. We do not put advertising on pages that reveal what substance you're tracking or what you're struggling with — the revenue isn't worth what it would leak about you.
The long version is below, because "trust us" isn't good enough. You should be able to check.
1. Who we are
somehowfunctional.com is currently operated by an individual, headquartered in Maryland, United States. There is no separate legal entity yet; the operator is the controller of any personal data described here. If and when a formal entity is created, this section will be updated with its name, registered address, and contact details.
For anything in this policy, please use our contact form.
2. The zones of this site, and what runs where
This policy covers everything at somehowfunctional.com: the blog, resources page, landing pages, the tracking tools, and the wrapper pages around them. There are two zones, and the line between them is the most important thing in this document.
Zone A — Tracker pages. This means both the tracker interface (the screen where you log drinks, sessions, doses, and view your charts and history) and the wrapper page that frames it (header, tool description, navigation, footer). We treat these as a single protected zone.
In Zone A:
- Your entries stay on your device (Section 3).
- No advertising scripts load. Not on the tracker, not on the wrapper around it.
- No analytics scripts load. Not on the tracker, not on the wrapper.
- No third-party JavaScript of any kind is loaded, other than what is strictly required to serve the page.
Zone B — General pages. The blog, landing pages, and resources page. These use cookieless analytics (Section 5) and may carry advertising in the future (Section 6), subject to the restrictions in Section 7.
Why the wrapper is inside the protected zone, not outside it. The wrapper and the tracker are served from the same origin. In a browser, a script running on a page can read data belonging to the same origin — including data inside a same-origin iframe. If we put an ad or analytics script on the wrapper page, that script would sit in a position where it could, technically, reach the tracker's stored data, regardless of whether it actually does. We don't want our privacy promise to depend on a third party's good behavior when we can instead make it a property of the architecture. So nothing third-party loads there at all.
What Zone A does not mean. It does not mean your visit is invisible. Serving you a page requires a server to receive a request for it, so our host and CDN (Cloudflare) process the request — your IP address, the URL requested, your user agent, and a timestamp — on tracker pages exactly as on every other page, and exactly as any website would. This means infrastructure logs reflect that a tracker page was requested from your IP address. What they do not contain is anything you logged inside the tracker, because that never leaves your browser. Section 9 covers this in full. We would rather state it here, next to the promise, than let you find it later and feel misled.
If you'd rather skip the wrapper entirely: each tracker is currently reachable directly at its own address, without loading the wrapper page first. This is an accurate description of how the site is built today, not a permanent guarantee; if it changes, we will update this section rather than leave a stale claim standing.
Each tracker also has its own in-app "About this tool" / Sources & Corrections section covering anything specific to it.
3. Data in the tracking tools
- Every entry you make in a tracker — logs, sessions, doses, timestamps, profile fields used for calculations, notes — is stored in your browser's local storage (
localStorage), on your own device. - We do not receive this data. There is no account system and no server-side database behind these tools. The trackers are static files; there is no endpoint for your entries to be sent to.
- This data is stored unencrypted at rest on your device, in the same way most browser-based apps store data. Anyone with access to your device, your browser profile, or your unlocked browser can read it. If your browser has sync enabled, your browser vendor may replicate it to your other devices. We are telling you this plainly rather than letting "local-only" imply "protected."
- Where a tracker offers encrypted backup/export, the encryption key is derived from a password you choose, using authenticated encryption (AES-GCM with a PBKDF2-derived key). We never see that password and cannot decrypt your backup for you if you lose it.
- If you clear browser data, uninstall, or switch devices, entries do not carry over automatically — see Section 9.
4. What "local-only" cannot protect you from
Our promise covers what we do: we do not collect, transmit, or see your tracker data, and the connection to this site is encrypted (HTTPS).
That promise cannot protect you from software running on your own device or network:
- Employer-managed devices. If your device has employer management software (MDM), monitoring, or DLP tooling, assume your employer can see what you type and view — including inside these tools.
- Networks that inspect encrypted traffic. Corporate, school, and some public networks run "break and inspect" TLS proxies. Where your device has been configured to trust such a proxy, HTTPS does not hide page contents from it.
- Malware, spyware, stalkerware, screen recording, parental controls. All can capture what HTTPS protects in transit.
- Shared devices. Anyone with access to the browser profile can open a tracker and read your local data.
- Your ISP, mobile carrier, VPN provider, and DNS resolver. HTTPS hides what's on a page from the network, but not which site you connected to. Your DNS resolver sees the domain you looked up, and your ISP or carrier can see the domain you connected to (via the TLS handshake) along with the IP address and timing. In plain terms: they can generally tell that you visited somehowfunctional.com. They cannot see which page you read, what you typed, or what you logged. Encrypted DNS (DoH/DoT), a VPN you trust, or Tor changes who sees which part of that, but somebody in the chain always sees something.
- Anyone with legal process. We hold almost nothing, but our host does hold infrastructure logs (Section 9), and your ISP holds connection records. We can only refuse to hand over what we don't have — which, for your tracker entries, is all of it.
If what you're tracking is sensitive — and given what these tools track, it probably is — use a personal device you control, on a network you trust.
5. Analytics
Zone B (general pages) only. We use Cloudflare Web Analytics, which does not set cookies, does not use localStorage, and does not fingerprint visitors. It does not track you across other sites and sends nothing to Google or any ad platform.
- It runs on general pages only. It does not run on any tracker page or wrapper (Section 2).
- We use it only in aggregate — page views, referrers, approximate country, device class.
- Legal basis (EEA/UK): we rely on legitimate interests in understanding aggregate usage of our own site, on the basis that the tool is cookieless and does not process data that identifies you individually. We consider this defensible; we are not asserting it as a settled legal conclusion, and if we're told otherwise by a regulator, we will gate it behind consent or drop it.
- Retention: Cloudflare retains Web Analytics data on a rolling basis (currently up to six months); we do not export or retain a separate copy.
- Cloudflare's processing: Cloudflare Privacy Policy.
You can block it with any content blocker; the site works fine without it.
6. Advertising
Current status as of the date above: no advertising is running on this site. We are describing our intended approach in advance so it's on the record before anything ships, not after. When ads do go live, this section will be updated to say so, and the "Last updated" date will change.
Where ads will and will not appear. If we introduce advertising, it will appear on general pages only (Zone B). Our restrictions on ourselves:
- No ads on any tracker page or wrapper, for as long as the tracker and its wrapper share an origin. See Section 2 for why this is an architectural constraint and not just a preference. If we ever separate them onto distinct origins — such that a script on the wrapper is genuinely incapable of reaching the tracker's stored data, enforced by the browser rather than by our good intentions — we may reconsider advertising on the wrapper chrome, and we will update this section to say so before doing it. The tracker interface itself will not carry advertising under any architecture.
- No ads on pages whose URL, title, or content reveals a specific substance, condition, medication, biomarker, or diagnosis. A blog post about alcohol biomarkers, cannabis tolerance, or a mental-health experience will not carry advertising. The page you land on shouldn't tell an ad network what you're dealing with.
- Ads, where they appear, will be on general and editorial pages that don't disclose that kind of interest.
What advertising would mean, stated honestly. Any third-party ad network we use would receive standard ad-serving data from the pages it serves on: IP address, device and browser details, the page URL, and ad interactions. It would be governed by that provider's privacy policy, not ours. That is exactly why we are keeping ad code away from tracker pages and substance-specific content — not because a consent banner makes it fine, but because the page-level signal is itself the sensitive thing.
If we use Google AdSense (our current expectation for general pages):
- Google and its partners set cookies and use identifiers to serve, cap, and measure ads. This includes non-personalized ads, which still use cookies for frequency capping, fraud prevention, and reporting. Consent obligations therefore may apply to non-personalized ads as well, and we will not imply otherwise.
- In the EEA, UK, and Switzerland, Google requires publishers to use a Google-certified Consent Management Platform for ad traffic. Google Consent Mode is a signaling mechanism, not a consent interface, and is not by itself sufficient. We will implement a certified CMP before serving ads to those regions, or we will not serve ads there.
- Google's processing: Google Privacy Policy. You can opt out of ad personalization at Google Ad Settings and aboutads.info.
Ads are not endorsements. We do not select individual advertisers. Given our subject matter, we're aware ad networks sometimes serve things this audience should not be pitched — miracle cures, fear-marketed "recovery" products, predatory treatment brokers. We will block what the platform lets us block. Report anything that gets through via the contact form.
We may change approach. If we adopt a different revenue model — direct sponsorship, donations, contextual advertising that transmits no page-level data — this section will be updated to describe what's actually running.
7. Sensitive information and health inferences
We want to name this directly rather than bury it.
The private entries in a tracker never leave your device, so no third party can profile them through us. But the fact that you loaded a particular page can itself suggest something about you — that you're interested in alcohol biomarkers, or cannabis tolerance, or a mental-health topic. Page-level information like that can support an inference about health or substance-use interests even when the underlying entries are untouched. Regulators have treated exactly this kind of page-level sharing as health-data sharing.
Our response is structural, not cosmetic: we keep advertising and analytics off the pages where that inference would be strongest (Section 2 and Section 6), rather than collecting the signal and asking you to consent to it.
Washington residents (My Health My Data Act) and similar laws: to the extent this site processes consumer health data as defined by such laws, the protections described in this policy apply, and we do not sell consumer health data. If we ever process consumer health data in a way that triggers the Act's requirements, we will publish a separate, prominently linked Consumer Health Data Privacy Policy as required.
8. Contact form
If you submit the contact form, we receive what you type, plus your email address if you provide one, and basic technical metadata associated with the submission (such as submission timestamp and IP address, used for spam prevention). Spam filtering may be applied to submissions.
- We use it only to respond to you. We do not add you to any mailing list or share it with third parties.
- Retention: submissions are deleted within 12 months of resolution, and sooner where practical. Backups may retain a copy for up to a further 90 days.
- The contact form is not monitored continuously and is not a crisis service. If you are in crisis, see the Disclaimers and the Resources page.
- The form provider and the exact fields collected will be documented here once the form is live; if that provider processes data outside your country, Section 12 applies.
9. Hosting, CDN, and security logs
Separately from analytics, our hosting and CDN provider (Cloudflare, via Cloudflare Pages) processes request data as an inherent part of delivering the site and protecting it from attack. This typically includes IP address, requested URL, user agent, timestamps, and security/bot-management events. This happens on all pages of the site, including tracker pages, because it is how the page reaches your browser at all — there is no way to serve a website without the server seeing a request for it.
- This is standard infrastructure logging, not tracking or profiling, and we do not use it for advertising.
- It is retained per Cloudflare's operational retention periods and is not exported into any other system by us.
- This applies to tracker pages too, and we want that stated plainly rather than tucked in a footnote. The fact that your IP address requested a given tracker page, at a given time, is present in infrastructure logs. The contents of that tracker are not, and never can be, because they are never transmitted. If the existence of the request is itself the thing you need to hide, no promise we make about our own code can help you with that — see Section 4.
10. Backups, export, and import
Trackers let you export your data (plaintext or encrypted) and re-import it later. This is a manual action you take. Exported files live wherever you save them, and we have no visibility into or control over them. A plaintext export is readable by anyone who opens the file. Losing an encrypted backup's password means losing that backup; we cannot recover it.
11. Children's privacy
This site is intended for adults (18+). The tools deal with substance use directly and are not designed for or directed at minors. We do not knowingly collect personal information from anyone under 18 (or under 13 for COPPA purposes). If you believe a minor has submitted personal information to us via the contact form, use the contact form and we will delete it.
12. International transfers
Our providers (Cloudflare for hosting/CDN/analytics, and any ad or form provider we adopt) may process data in the United States and other countries. Where personal data of EEA/UK individuals is transferred, we rely on our providers' transfer mechanisms, including Standard Contractual Clauses and, where applicable, participation in the EU-U.S. Data Privacy Framework. If we are unable to rely on a valid transfer mechanism for a given provider, we will change providers rather than proceed.
13. Your rights and choices
For tracker data: the tracker is your control panel — export, delete, or clear it in-app, or clear the site's data in your browser settings. We cannot access, correct, or delete it for you, because we never have it.
For data we or our providers process (contact form submissions, analytics, infrastructure logs, and advertising identifiers if ads launch), your rights depend on where you live:
- EEA/UK (GDPR): access, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint with your supervisory authority. Our legal bases are: consent (advertising cookies, if applicable); legitimate interests (site operation, security, aggregate analytics, responding to your messages); and legal obligation where applicable.
- California (CCPA/CPRA): rights to know, delete, correct, and to opt out of sale/sharing for cross-context behavioral advertising. We do not sell personal information. If we launch advertising that constitutes "sharing," you will be able to opt out via the consent interface and via a Global Privacy Control (GPC) browser signal, which we will treat as a valid opt-out request for the browser that sends it. Because we currently run no advertising and no cross-site tracking, there is presently nothing to opt out of.
- Other US state laws (Virginia, Colorado, Connecticut, Maryland, and others): comparable access, deletion, correction, and opt-out rights apply where those laws cover us.
How to make a request: use the contact form and tell us what you want. We will respond within 45 days, and may extend once where permitted, telling you why. Because we have no accounts, we may need to ask for information to verify that a request relates to you — typically, matching it to a message you sent us. If we cannot verify a request, we will say so rather than act on it. Authorized agents may submit requests with proof of authorization. If we deny a request and your state provides an appeal right, you may appeal via the same contact form, and we will respond within the timeframe your state requires.
We do not discriminate against you for exercising privacy rights.
14. Data breach
There is no central database of tracker data to breach. For data we do hold (contact form submissions) or that our providers hold on our behalf, if a breach occurs we will notify affected individuals and relevant authorities as required by applicable law.
15. Changes to this policy
If this policy changes in a way that affects how data is handled — particularly anything that would move tracker data off-device, introduce advertising, or change the Zone A/Zone B boundary — we will post a visible notice on the site and update the date above. We will not quietly loosen this policy and hope nobody checks.
16. Contact
Questions, concerns, or "this doesn't match what the site is actually doing" reports: contact form. That second kind of message is genuinely welcome. If our code and our policy disagree, we want to know.