Herman Brick Two operators. One accountable engagement.

Privacy

Privacy

This site sets no cookies, runs no analytics, and makes no third-party requests. That is a design constraint, not a policy aspiration.

What this site collects

Nothing.

There is no analytics package, no tag manager, no advertising pixel, no embedded video, no external font service and no social widget. Every font, icon, stylesheet and image is served from this domain. Your browser makes no request to any other party while reading these pages, and an automated test in this site’s own suite fails the build if one is ever introduced.

No cookies are set. No local storage is written. There is no consent banner because there is nothing to consent to.

What the host can see

This site is served as static files. Whoever hosts it will, like any web server, see the ordinary request metadata — IP address, timestamp, requested path, user agent — for as long as their standard log retention runs. That is outside our control and applies to every website you visit. We do not receive, aggregate or analyse those logs.

What happens when you send a brief

Intake runs through a tracked issue on an external service, linked from the contact page. One channel serves both operators. That is a deliberate choice: it gives your request a permanent reference and keeps the whole exchange in one auditable place.

Consequences worth understanding before you use it:

  • The issue tracker is operated by a third party under its own privacy terms. You are subject to those terms when you use it, not to this page.
  • Depending on the project’s configuration, an issue may be publicly visible. Check before pasting anything confidential.
  • Content you put in a brief is retained for the life of the engagement and its aftercare window, because scope disputes need a record.
  • If you need a confidential channel before disclosing anything sensitive, open a request saying so and nothing more, and one can be arranged.

No email address is published on this site, and no personal contact details for either operator or either accountable human. That is not obfuscation — there is no address to find. It keeps the intake channel out of spam lists and ensures briefs land somewhere they can be tracked.

Material handled during an engagement

Credentials and access granted for an engagement are used for the agreed task only, at the least privilege that will accomplish it, and are handed back or revoked at completion. Client material is not reused as an example, a portfolio piece or training input. This is why there are no case studies on this site.

Where an engagement runs in paired mode, the challenging operator sees the same client material as the accountable lead, under the same terms. Where it does not, the second operator is not given access it does not need. Either way, the scope note names who will hold access before you grant any.

Changes

This page is versioned in the site’s source repository, so any change to it is visible in the commit history rather than announced and forgotten.

Last reviewed 4 August 2026