Privacy

What this site collects.

Plain language, no boilerplate. Last updated 20 August 2026.

This describes what devengaged.com collects and what happens to it. It is a plain description, not legal advice, and it should be reviewed by a qualified professional before anyone relies on it as such.

This site sets no cookies

Not one. There is no login here, so there is no session cookie, and the analytics set nothing. That is why there is no cookie banner — there is genuinely nothing to ask you about, and a dialog that exists only to be dismissed is not consent.

If that changes, you will get a real choice about it, not a banner engineered so that “accept” is the only easy button.

Reading the site

You can read every page here without giving us anything. Analytics run on a self-hosted copy of Umami — on our own server, not a third party’s. It is cookieless, it does not follow you to other sites, and it does not build a profile of you. What we see is aggregate: how many people opened a page, roughly where in the world they were, and what referred them.

How we know which link brought you here

Your browser keeps one entry in local storage, nv_attribution. It records only the campaign, referrer and landing page that brought you to the site — never who you are. It stays on your device, is never sent to a third party, and clearing your site data removes it. It exists so we can tell which writing and which links actually bring people here, instead of guessing.

Being precise about one thing, because it matters: on its own that entry is anonymous, but if you send the contact form, it is submitted with your enquiry and stored alongside it. At that point it is no longer anonymous — it tells us that the person who got in touch arrived from a particular link. If you would rather it did not, clear your site data before sending the form.

If you contact us

The contact form stores what you type: your name, email address, and message, plus the optional company, type of work, and budget range if you fill them in. We keep it so an enquiry cannot get lost, and so there is a record of what was discussed.

It is stored in our own CMS on our own server, copied into our internal pipeline for tracking the conversation, and it triggers a notification email so a real person sees it. It is never sold, never rented, and never passed to an advertiser.

If you run a site audit

The audit tool stores the URL you submit and the report it generates, so the report stays reachable at its own link. If you ask for the full report, we store the email address you give and send it there.

Your IP address is used, briefly and in memory only, to rate-limit the tool to five audits an hour. It is not written to a database and not used to identify you.

If you sign up for the newsletter

We store your email address so we can send it, and nothing else. You have to confirm the address by clicking a link before you are actually subscribed — an unconfirmed address is never mailed. Every email carries an unsubscribe link, and unsubscribing is immediate.

Who else sees any of this

As little as we can manage. Email is delivered through Resend, which necessarily sees the address a message goes to. DNS runs through Cloudflare. Everything else — the site, the CMS, the analytics, the audit reports — runs on our own server.

Getting it deleted

Email hello@devengaged.com and say what you want — what we hold about you, or all of it gone. You do not need to give a reason, and asking costs you nothing.