Who is responsible for this data
The data controller for this site is Ives François Laurent Noriega, an author known publicly as Yves Laurent, who also runs the editorial imprint Stones Don't Lie Press. Contact address in Mexico City.
Direct contact for anything related to personal data: [email protected]. I answer personally within ten business days at the latest.
What we collect
Listed by concrete origin. If it isn't on this list, we aren't storing it.
Newsletter subscription
When you enter your email in any form on the site, we store: your email address, your name if you typed one, the page you subscribed from, the language (Spanish or English) and the subscription date. Also the subscription state (active or cancelled) and the cancellation date if you opted out.
Chat with the virtual assistant (Petra)
When you talk to the chat widget we store: a unique session identifier, an irreversible hash of your IP address (never the original IP), your browser user agent, the page you started the chat from, the messages you sent, the answers you received, and a set of signals extracted automatically from the content to understand the conversation (mentioned interests, apparent sentiment, level of engagement, whether you shared an email or a name). The chat is capped at five messages per session and only answers on-topic questions about the book.
Article statistics
Each visit to a blog page records: the article identifier, a hash of your IP so we can count unique visitors without identifying you, your browser user agent, the referring page, and how long you spent on the page if your browser reports it. The IP hash is one-way; the original address cannot be reconstructed from the stored hash.
Interactions (favourites, shares)
If the site ever asks you to create an account to bookmark or share, it would store your email, an optional name, and your interactions. This functionality is designed but currently not enabled for general public use.
Why we use the data
- To send you catalog updates from Stones Don't Lie Press when you subscribed to the newsletter. No third-party advertising ever.
- To respond in the chat when you open the widget, and to improve reply quality by reviewing aggregated conversations without identifying you.
- To understand which articles get read and which don't, so we can adjust the editorial work.
- To detect technical abuse (rate limiting, filtering of instruction-injection attempts against the chat).
We do not sell your data. We do not hand it over for advertising purposes. We do not profile for price discrimination or political segmentation.
Third parties that process or see anything
External services involved in running the site, and therefore with technical access to some part of the data. Listed without decoration.
- Cloudflare (United States): CDN and server protection. Sees every HTTP request to the site, including your real IP address, before it reaches our server. Cloudflare may set a technical cookie
_cf_bmfor bot management. - Google Analytics 4 (Google, United States): visit statistics. Receives information about pages you visited. You can block it with your browser's DNT signal, an extension like uBlock Origin, or the consent settings your browser provides.
- Google Fonts (Google, United States): the site's typefaces are served from
fonts.googleapis.com. Loading a font tells Google that you visited a page that uses it. - Anthropic (Claude, United States): processes the messages you type into the chat to produce replies, and processes article HTML when translating a blog post to English. Anthropic receives the textual content you send to the chat, and the HTML of the article when it is translated.
- Self-hosted Ollama (author's own server, home network): the local chatbot model runs on a server the author owns. Chat messages pass through it via the Cloudflare tunnel.
- Synology MailPlus (author's own mail server): sends welcome emails and blog notifications. It sees your email address and the message content that gets sent to you.
- Giscus (blog comments): if you comment on an article, your comment is stored in a public GitHub repository and shows your GitHub avatar and username. We do not control that data: GitHub's privacy policy applies.
- Buy Me a Coffee: external links. If you click and enter data there, that data is processed by Buy Me a Coffee under its own policy.
- Amazon (Amazon KDP + Amazon Author Central): links from the site to the book's Amazon listing move you into Amazon's policy.
- Goodreads: links to the author profile move you into their policy.
None of the author's internal automation systems (n8n, MongoDB, PostgreSQL, Qdrant, LightRAG) are third parties: they are owned infrastructure. They are listed for transparency because they process data, but nothing is shared outward from them.
Cookies and local storage
- Browser localStorage: the chat stores a
yl_chat_sessionkey holding your session identifier, your conversation history and whether you already finished. It lets the chat restore itself if you close and reopen the widget. You can delete it from your browser's settings. - Cloudflare technical cookies: may appear for anti-bot handling, not commercial tracking.
- Google Analytics 4 cookies: unless you block them with extensions or browser configuration, GA4 may set first-party cookies for statistics.
No first-party advertising cookies. No Facebook Pixel, no TikTok Pixel, no ad retargeting tags.
How long we keep the data
- Newsletter subscription: for as long as you are subscribed. When you cancel, your record is marked inactive (so we don't re-subscribe you by mistake) but can be deleted entirely on request.
- Chat with Petra: sessions and messages are kept indefinitely to review the assistant's quality. You can ask for them to be deleted by email, providing the session identifier or the approximate date.
- Article statistics: aggregated per article, kept indefinitely. Individual entries (with IP hash and user agent) can be purged by year on request.
Your rights
Under Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP), you have the right to:
- Access: request a copy of everything we store about you.
- Rectification: request correction of inaccurate or outdated data.
- Cancellation: request that we delete your data.
- Objection: request that we stop processing your data for a specific purpose.
If you are in the European Union, the General Data Protection Regulation (GDPR) also applies: access, rectification, erasure, restriction of processing, data portability and objection.
To exercise any of these rights, write to [email protected] with the subject ARCO or GDPR and a short description of what you are asking for. Receipt is confirmed within two business days, and the request is executed within ten business days at the most.
If the answer feels inadequate, in Mexico you can turn to the National Institute for Transparency, Access to Information and Personal Data Protection (INAI). In the European Union, to the data protection authority of your country.
Newsletter opt-out any time
Every newsletter email includes an Unsubscribe link at the bottom. That link removes you immediately, with no further confirmation or questions. If you lost it, write to [email protected].
Minors
The site is not intended for anyone under eighteen. If a minor subscribed to the newsletter or interacted with the chat, any person with parental responsibility can request immediate deletion of that data by writing to the contact address.
Changes to this policy
If anything material changes, the date at the top of this page is updated and a note goes out through the newsletter. Minor changes (typos, updates to the third-party list) are applied silently and reflected in the last-updated date.
This policy aims for literal compliance with Mexico's LFPDPPP and in spirit with the European GDPR. If anything reads confusing or incomplete, write in. It is an editorial policy more than paperwork: when something doesn't fit, we fix it.