Privacy policy
What this site collects, where it is kept, who else sees it, and how to get rid of it. Last updated 20 September 2026.
The Kept Journal (thekeptjournal.net) is a personal travel journal, written and run by one person in Bangkok, Thailand. This page is written in plain English because it is short enough not to need anything else.
The short version
- Reading the journal, the entries, the trip pages and the ledgers needs no account, and signed out the site sets no cookie of its own.
- The Travel Hacker atlas is open too — all 4,099 trips, signed in or not. An account lets you save the ones you like.
- There are no advertising cookies, no analytics cookies, and no tracking script of any kind.
- If you make an account I store your email address, a short list of facts about the account, and nothing you didn’t hand over. You can download all of it, and delete all of it, from your account page.
- The private backoffice connects to my own YouTube channel through Google. That is described in full below, because Google requires it and because you deserve to know what happens to a comment you leave on a video.
Reading the site
You can read every entry, trip page and ledger here without telling me who you are. Signed out, the site sets nothing in your browser — not for advertising, not for analytics, not for “preferences”. There is no Google Analytics, no Meta pixel, no Plausible, no Sentry and no third-party tag anywhere on it. Everything a page loads comes from this site’s own domain — the two typefaces included, which are served from here rather than fetched from Google — with one exception: the embedded YouTube player on an entry that has a video.
That includes the Travel Hacker atlas, which today is open to everyone: all 4,099 trips, prices, itineraries and all, with no account and no cookie. If that changes, the paragraph under “The atlas sample” below changes with it on the same day.
Accounts
An account exists for two reasons: so the atlas can remember which trips are yours, and so I can tell you when something is published, if you ask me to. It is free, and it is optional.
There is no password, and there is nothing to reset. You type your email address, I email you a link, and clicking that link signs you in. The link works once and for fifteen minutes. An emailed link is the only way in today; if I ever add another — signing in with Google is the one I am considering — this page will describe it before it ships, not after.
An account holds:
- Your email address, and whether it has been confirmed by clicking a link.
- The plan it is on. There is one plan today and it is free.
- Which page you were on when you signed up, and that you came through the sign-in form.
- When you created it, when you last signed in, and roughly when you last used it.
- The trips you have saved, and any note you wrote on one.
- Whether you asked for the news email, and when you asked or stopped.
- A record of what you agreed to and when — the purpose, the date, and which version of this page was in force. That is the evidence a data controller has to be able to produce.
- A fixed 32-character value worked out once from your email address, which decides which trips would be yours if the atlas is behind an account. It is the same value for the same address forever, so deleting an account and making it again gives you back the same trips.
- A one-way hash of your IP address at sign-up and at sign-in. It cannot be turned back into an address. It exists only so that one person cannot make hundreds of accounts or have sign-in links mailed at somebody else, and it is never shown, in the backoffice or anywhere else. The address itself is not stored.
There are no passwords here to steal, no analytics, no profile built from what you read, no open or click tracking in anything I send, and no payment data — nothing on this site costs money.
Cookies
Signed out, none. Signing in sets two, and both are deleted when you sign out:
tkj_user— the session itself. A long random value; only its SHA-256 is stored here, so the copy in your browser is the only copy that exists. HTTP-only, so no script on the page can read it. Good for 30 days and renewed while you keep visiting. Signing out deletes it and revokes the record behind it; “sign out everywhere” on your account page revokes every one of them at once.tkj_signed_in— the single character1, and nothing else. It carries no authority and proves nothing; it exists so the header can say “Account” instead of “Sign in” without asking the server. Same lifetime.
The backoffice — the private area only I can log in to — has its own login cookie, tkj_admin, and creates ten-minute security cookies while I am connecting a platform such as Google. Those are mine and a reader is never given one.
The atlas sample
Today there is no sample: the atlas is open, and every visitor sees all 4,099 trips whether they have an account or not. An account adds saving and nothing else.
The account does carry the value described above, ready for the day I put the atlas behind a free account — 24 trips for everyone, about 123 for a free account, chosen across all five landscape tiers. That day is a switch, not a new kind of data: nothing further would be collected about you, and this paragraph changes to describe it on the same day the switch is flipped.
There is no sign-up form in the footer any more. The way to hear from me is an account, and there are exactly two kinds of message.
- The sign-in link. Sent because you asked to sign in, and never for anything else. It carries no unsubscribe link, because switching it off would lock you out of your own account.
- The news email. A separate box on the sign-in page, never pre-ticked, and a switch on your account page: one message when a journal entry or a trip pack is published, and occasional news about the atlas. A few times a month at most. Every one of them carries a one-click unsubscribe that works without signing in, and the switch on your account page does the same job.
Ticking that box makes no difference to whether you can sign in, and leaving it alone costs you nothing. Nothing I send carries a tracking pixel or a remote image, and I do not record whether a message was opened or a link in it clicked. The list is never sold, rented, shared or handed to an advertiser.
Who else sees it
Four companies are involved in running this site, and no others. None of them is an advertiser or a data broker, and none of them is paid in your data.
- Cloudflare serves every page. Like any web server it records ordinary request logs — your IP address, your browser’s user-agent string, the page requested and the time — which it keeps briefly for security, abuse prevention and traffic handling under its own policies. I don’t build profiles from them, and I have no visitor-level log of my own.
- Supabase holds the database and the uploaded photos and video, in its Sydney, Australia region (ap-southeast-2). Your account, your email address and your saved trips live there.
- Resend (resend.com), in the United States, is the mail provider this site sends through. It sees the address a message goes to and the text of the message.
- Anthropic (the Claude API) sorts and drafts replies to comments left on my YouTube videos, in the backoffice, as described below. It is never given an account, an email address, a saved trip or anything else from this site.
Google is involved only where you can see it: the embedded YouTube player on an entry, and my own channel connection.
Sydney is in Australia and Resend and Anthropic are in the United States, so your data does leave Thailand. Thailand’s Personal Data Protection Act asks me to say that plainly rather than bury it: it leaves, to those companies, for those purposes, and for nothing else.
How long it is kept
- Your account and everything in it: as long as you keep it.
- An account whose address was never confirmed: 30 days, then deleted along with its consent records. An address that never confirmed is neither a lead nor a lawful record, so it isn’t kept as one.
- A sign-in link: 15 minutes live, and the used-up record is deleted 30 days later.
- A session: deleted 30 days after it expires, or after you sign out or revoke it.
- The record that you agreed to these terms: three years after you delete the account, with your email address removed from it first. What is left says that somebody agreed, to what, and when, and cannot be tied back to you by me or by anyone else.
Deleting your account
On your account page: “Delete my account”, then type your own address to confirm. The account, its sessions and its saved trips go immediately — no cooling-off period, no email asking you to reconsider, no reason needed. Everything else about you goes with them.
The one thing that survives is the consent record described above, with your address stripped out of it, for three years. If you would rather I did the whole thing by hand, write to hello@thekeptjournal.net and I will.
Embedded YouTube players
Entry pages embed the matching video from my YouTube channel. The player is Google’s: when it loads, Google can set its own cookies and receive your IP address and viewing data under Google’s privacy policy, which I have no control over and no access to.
Google user data
The backoffice of this site — a private area only I can log in to — connects to my own YouTube account only, through Google’s OAuth consent screen. It never asks for, and cannot obtain, access to anyone else’s Google account. The scopes granted are youtube.readonly, yt-analytics.readonly, youtube.force-ssl and userinfo.email.
What it reads with that access:
- Channel and video statistics — subscriber, view and video counts, and per-video performance.
- YouTube Analytics reports for my channel, broken down by country (views, estimated minutes watched, average view duration).
- Comments left on my own videos, with their author name and text as YouTube publishes them.
- The email address of the Google account I connected, so the backoffice can show which account is linked.
What it does with it:
- Shows it to me, in the private backoffice. None of it is published on this site.
- Classifies each comment — question, praise, criticism, spam — and drafts a suggested reply, so I can answer the ones that deserve an answer. That classification is performed by Anthropic’s Claude API, which means the text of a comment and the title of the video it was left on are sent to Anthropic for that purpose and for nothing else.
- Lets me update the title and description of my own videos from the backoffice. That is the only thing it ever writes back to YouTube.
What it never does:
- No replies are posted automatically. A drafted reply is a suggestion on my screen; every comment I answer, I answer by hand.
- Google user data is never sold, never shared with advertisers or data brokers, and never transferred to anyone except as described above.
- It is never used to train, fine-tune or improve any machine-learning model, mine or anyone else’s.
- It is never used for advertising, and there is no advertising on this site.
The Google refresh token is stored encrypted at rest (AES-256-GCM, with the key derived from an application secret that lives only in the server environment), in the same Supabase database described above. It is never written to a log, never shown in a page, and never leaves the server.
Limited Use. The Kept Journal’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking that access
Because the connection is to my own account, I am the one who revokes it: at myaccount.google.com/permissions, by removing The Kept Journal’s access, and by deleting the connector in the backoffice, which deletes the stored token. Doing either one stops all further reading immediately.
Comments you leave on YouTube
If you comment on one of my videos, that comment is public on YouTube. My backoffice may store a copy of it and classify it as described above — including sending its text to Anthropic’s Claude API — so that I can read and answer it. Your comment stays yours: delete it on YouTube and it is gone from the place it was published. Write to me if you would also like my stored copy removed.
Your rights, and how to use them
Wherever you live — and under Thailand’s Personal Data Protection Act, which is the law I sit under — you can ask what I hold about you, ask for a copy of it, ask for it to be corrected, ask for it to be deleted, and withdraw a consent you gave. If you have an account, four of those five are buttons rather than requests: your account page downloads everything the site holds about you as a file, switches the news email on or off, signs you out of every device, and deletes the account outright.
For anything else, write to hello@thekeptjournal.net. One person reads that mailbox; expect a human reply rather than a ticket number. If I get it wrong you can complain to the Personal Data Protection Committee of Thailand, and you don’t need my permission to do it.
Changes to this policy
This page is edited in place and the date at the top changes with it. There is no archive of earlier versions, and the date is the version: it is recorded against every consent, so a record of what you agreed to always points at a wording rather than at “the policy”. If something material changes about accounts, about email, or about the Google connection, it is described here before it ships. The matching rules for using the site are in the terms of service.