Uncharted Territories
[Privacy]

Privacy Policy

Last updated: August 10, 2026

Two different things live at this address: a public site where you read about the publication, and internal tools that only our own team can sign into. This page explains what data each one involves, why we have it, who else touches it, and what you can ask us to do about it. If we contacted you about a job, the separate candidate privacy notice covers that instead.

Who we are

The data controller is Uncharted Territories Inc., 2021 Fillmore Street, 55, San Francisco, CA 94115, USA — a Delaware corporation, the company behind Tomas Pueyo's Uncharted Territories publication. For anything on this page, including exercising your rights, write to david@unchartedterritories.co. A person reads that address.

If you are reading the site

There are no reader accounts, no comments, no advertising, and we do not sell personal data or share it for advertising of any kind. What we do collect is analytics, so we can see which pages land and which are broken. Through PostHog, on its United States infrastructure, we receive:

  • The pages you view and the links or elements you click.
  • Approximate location at the country level.
  • Standard technical information your browser sends: browser, operating system, device type, screen size, and the referring page.
  • Event timestamps and related analytics metadata. PostHog stores an identifier in your browser so repeat visits count as one visitor; we do not use it to work out who you are.

We also run Sentry, an error-monitoring service that records the technical details of crashes and failed requests, which can include IP addresses, so we can fix them. We use all of this to understand how the site is used, improve it, diagnose problems, and protect our systems. Where the GDPR applies, our legal basis is our legitimate interest in understanding, operating, securing, and improving the site, and you can object at any time (see Your rights).

If you are on the team

Only team members have accounts, behind Google sign-in restricted to an allowlist of company addresses. There is no public sign-up. What we hold: your name and email from your Google account, and the working record of what you do in the tools — drafts, reviews, approvals, what you published and when. That record is the point of the tools. Analytics for signed-in team members may include your first name so we can tell team traffic from reader traffic. Where the GDPR applies, we process this as necessary for our working relationship with you and for our legitimate interest in running the editorial tools and keeping an accurate record of editorial decisions.

If you connected your LinkedIn account

A team member may choose to connect their personal LinkedIn account through LinkedIn's standard OAuth 2.0 flow. LinkedIn shows you what the app is asking for; if you approve, LinkedIn gives us a token that lets our tools act for you in one narrow way. Connecting is optional, and nothing else about your work or your use of the tools depends on it.

The publishing permission we use is one LinkedIn describes as allowing an app to post, comment, and like on a member's behalf. Our integration uses it only to create posts and upload the images you approved; it has no facility for commenting or liking. We do not request permissions that read your feed, messages, connections, or engagement data, so the API does not return those things to us. Alongside the token we receive and store the member identifier LinkedIn requires for addressing a post to your account, with the basic sign-in profile information LinkedIn returns during authorization.

What we store, in full:

  • Your access token, encrypted at rest, on our servers only. It is never sent to a browser and never written into logs.
  • The member identifier and basic sign-in profile information described above.
  • A log of publish attempts: when we called LinkedIn, whether it succeeded, the response identifiers LinkedIn returned, and the URL of the resulting post.

Nothing publishes to your account without your explicit approval of that specific post and the schedule you chose. Not a batch approval, not a standing permission. One post, one approval, every time. That is a company rule, it is built into the tool, and we state it here so you can hold us to it.

LinkedIn tokens expire on their own after roughly 60 days; when yours expires, publishing stops until you reconnect, which is one click. You can also revoke the app at any time in LinkedIn's settings (Data privacy, permitted services), which stops API access immediately; revoking there does not by itself remove the stored copy of the token, so if you want it deleted as well as dead, ask us and we delete it and confirm. Posts already published stay on your LinkedIn account under LinkedIn's own terms and controls. Where the GDPR applies, the connection rests on your consent, which you can withdraw at any time by either route; withdrawing does not affect what was lawfully done before.

Who else touches the data

Service providers processing on our instructions under contract: Render (hosting, US), Supabase (database, US), Google Workspace (email, documents, team sign-in), PostHog (analytics, US region), and Sentry (error monitoring). None of them may use the data for their own purposes. When an account owner directs us to publish, we send the approved content and authorization to LinkedIn, which processes it under its own terms and privacy policy. We may also disclose data where reasonably necessary to comply with law or valid legal process, to investigate fraud, abuse, or security incidents, to protect the rights and safety of our team or others, or to establish, exercise, or defend legal claims.

No sale, no ad sharing

We do not sell personal data, and we do not share it for cross-context behavioral advertising as California law defines that term. The site carries no advertising. Because none of that happens, there is nothing to opt out of. California residents can exercise the access, correction, and deletion rights below at the same address, and we will not treat anyone differently for asking.

Where the data lives

We are a US company and we process data in the United States. For personal data from the EU or UK, we and our providers rely on the EU standard contractual clauses, with the UK addendum where applicable, or another lawful transfer mechanism. Write to david@unchartedterritories.co for details of the safeguards that apply to you.

How long we keep it

  • LinkedIn tokens: until they expire, are revoked, or the account disconnects, whichever comes first.
  • Editorial activity records: kept as the history of the content itself, because the record of who approved what is part of the work.
  • Publish logs: kept as the operational record of the account owner's own published posts.
  • Analytics and error monitoring: held under the providers' retention settings for our account, and only as long as reasonably necessary for the purposes above.
  • Everything else: only as long as reasonably necessary, including for security, legal compliance, and resolving disputes.

Security

Access to the internal tools is limited to an allowlist of company Google accounts. LinkedIn tokens are stored server-side and encrypted at rest. Traffic is encrypted in transit. Database access is limited to the people who need it, and operational logging helps us detect and investigate problems. No system is perfectly secure; if a breach affects your data we will notify you and the relevant authorities as the law requires, and if you believe your data or a connection may have been compromised, contact us promptly.

Your rights

Depending on where you live, you can ask us to give you access to the data we hold about you, correct it, delete it, restrict what we do with it while a question is settled, object to processing based on our legitimate interests (including analytics), give you a portable copy of what you provided, or act on a withdrawal of consent. Write to david@unchartedterritories.co. We answer within one month; where the law permits an extension for complex requests, we tell you within that first month. We may ask you to confirm you control the email address the request concerns, and nothing more. If you think we have handled your data unlawfully you can complain to your data-protection authority; we would rather you wrote to us first so we can fix it, but that is your choice, not a condition.

Children

The site and the tools are not directed to children and we do not knowingly collect children's data. If you believe a child has given us personal data, write to us and we will review and delete it.

Automated decisions

We use software, including AI tools, throughout the editorial process. No solely automated decision producing legal or similarly significant effects is made about you.

Changes

If we change how we handle personal data, we update this page and the date at the top. Material changes reach anyone with a connected LinkedIn account directly before they take effect.