Privacy
What this site collects, what it loads from other companies, and what you can do about either. Written to be checked against the page source rather than taken on trust.
Who this is
The Application Security Podcast is published by Kerr Ventures, which decides what this website does and is the contact for anything on this page. Write to hello@appsecpodcast.com.
This covers this website only. The show is also distributed through Apple Podcasts, Spotify, YouTube and every app that reads the RSS feed, and what those platforms collect while you listen there is theirs to describe.
The site itself collects nothing
Every page here is a static file, built ahead of time and served as-is. There is no application server, no database, no accounts, no login, no comments and no advertising of any kind. Nothing you do on this site is written to anything we own, because there is nothing to write to.
Everything below is therefore about other companies: the analytics, newsletter form, audio host, video host, and the CDN the files are served from. Audio and the full YouTube player are not contacted until you press play.
Cookieless analytics
This site uses Plausible Analytics to count visits and understand which pages and outbound links are useful. That includes clicks on links to episode sponsors. Plausible does not place cookies, use local storage, or create a persistent identifier that follows a browser across days, sites, or devices. There is therefore no analytics consent choice to remember in your browser and no cookie banner.
Plausible receives:
- your IP address and user agent long enough to produce aggregate daily statistics; the raw values are not stored;
- the page you view, its referring page, and campaign parameters such as
utm_source; other query parameters are discarded by default; - your browser, operating system, device type and approximate country;
- the destination when you click an outbound link.
The resulting reports are aggregate rather than profiles of individual people. They live in Plausible's systems under its data policy. How long reports are kept is an account setting rather than anything this site's source code can prove, so no retention period is stated here.
The newsletter form
The subscribe form is beehiiv's, embedded fromsubscribe-forms.beehiiv.com on episode pages. Loading an episode page can send beehiiv your IP address and the page you are on, even if you do not submit the form.
If you type an email address into the form and submit it, that address goes to beehiiv and is stored there so we can send you the newsletter. It is the only thing anyone visiting this site is ever asked to type. Nobody buys the list, because there is no arrangement under which it could be sold. To come off it, unsubscribe from any issue or email us and we will remove you.
Audio — nothing until you press play
The player on an episode page is a plain HTML audio element pointed at the MP3 on Buzzsprout, not a Buzzsprout embed, and it is set not to preload. No request reaches Buzzsprout while you are only reading the page.
Press play and your browser fetches the file directly from Buzzsprout, which sees your IP address and browser and counts it as a download — that request is how podcast listener numbers are counted everywhere, including in the apps.
Video — the thumbnail loads, the player does not
Episodes with a video show a still image rather than an embedded player, and the two halves of that behave differently:
- The thumbnail is an image fetched from
i.ytimg.com, a Google domain, when the page renders. Google therefore learns your IP address and that a browser loaded a page on this site, without you clicking anything. - The YouTube player itself is only inserted when you click play, and it is loaded from
www.youtube-nocookie.com. Until that click there is no player, no YouTube JavaScript and no YouTube cookie. After it, you are watching on YouTube's terms in an iframe on our page.
This site sends strict-origin-when-cross-origin as its referrer policy, so a passive request like that thumbnail carries only the site's origin, not the address of the page you are reading. Plausible separately records the page path as part of its aggregate analytics.
Hosting
The site is served by Cloudflare Pages, which keeps the ordinary edge access logs any web host keeps: IP address, timestamp, requested URL, user agent. We do not run analytics on top of those logs.
Search does not leave your browser
Search is powered by Pagefind, which is a static index built at the same time as the pages and shipped alongside them. When you type a query, the browser downloads slices of that index from this same domain and does the matching locally. The query is not sent to any server — not ours, because there isn't one, and not anybody else's.
A search page can be linked to with the query already in the address, as/search/?q=…. Plausible discards that q parameter by default, and queries you type on the page never enter the address bar.
What is not here
No advertising network, no cross-site or affiliate tracking, no A/B testing, no session recording or heatmaps, no social media buttons that phone home, and no third-party fonts — the typefaces are served from this domain specifically so that loading a page does not announce it to a font host.
What you can do
- Block
plausible.iowith your browser or content blocker if you do not want your visit included in aggregate analytics. The site works the same without it. - Don't press play, and neither Buzzsprout nor YouTube hears from you.
- Ask us. Mail to hello@appsecpodcast.com gets a person, and we will delete anything we can reach — realistically, your newsletter subscription. Analytics data is not held in a form that lets us find one person in it.
What this policy does not claim
It does not claim compliance with the GDPR, the CCPA, or any other data protection regime. This page is a concrete description of what the site's code does, not legal advice or a substitute for reviewing account settings and contracts that are not present in this repository.
The point of this page is to describe accurately what happens, so that anyone who cares can verify it in the page source and act accordingly.
Changes
If what the site does changes, this page changes with it and the date below moves. There is no mailing list for policy updates and no published version history — the date is the only claim this page makes about its own age.
Last updated