Effective August 5, 2026
The short version: essential infrastructure keeps the site secure and running; optional analytics and advertising measure how it is used; and signups go to the tools that deliver what you requested. This page names every service in those current flows and the choices you have. We do not sell personal information.
Torta Studios, LLC. For anything privacy related, write to [email protected].
Cloudflare sits at the edge of this site for caching, traffic delivery, bot detection, and abuse protection, and DigitalOcean hosts the application and its database. Those providers process connection data such as your IP address, user-agent, requested URL, and request headers as needed to deliver and secure the site. Cloudflare may set the essential, HttpOnly __cf_bmcookie for about 30 minutes to carry encrypted bot-management signals. It is site-specific and remains active regardless of the optional analytics choice. Sentry receives application errors and performance traces for operational monitoring whether or not optional analytics is enabled. Its SDK collection disables cookies, query strings, request and response bodies, authorization, attribution, reader access codes, IP/user fields, and local variables; error and trace payloads are scrubbed again before send, and browser tunnel requests omit ambient cookies and referrers.
When you explicitly choose all (or while a valid legacy implicit cookie remains unexpired), we use PostHog and Google Analytics to understand pages viewed, buttons clicked, browser exceptions, and session recordings (all form and keyboard input is masked in PostHog recordings). Google Analytics traffic is routed through a Google Cloud measurement server we operate.
PostHog keys a signup person profile with a deterministic SHA-256 hash of the lowercased, trimmed email. For a guide signup, that consented profile also receives the submitted name and email, a random guide reader code, and guide-reader status; the event may include an email-provider category, guide, referral code, and consented ad click IDs. For a newsletter signup, the profile receives the submitted email, signup placement, and an immutablehas_newsletter_signup_accepted marker recording only that Beehiiv accepted the request. It does not prove double opt-in confirmation or current subscriber status. Beehiiv owns that lifecycle, and its confirmation, status, and deletion webhooks are not copied into PostHog.
When your consent state allows advertising, tags from Google, LinkedIn, Meta, and OpenAI may collect usage data to measure ad performance and build advertising audiences. For a field-guide conversion, OpenAI may receive your normalized email as a deterministic SHA-256 hash together with your IP address, browser user-agent, its __obref click-reference cookie when present, and the signup page URL. The deterministic email hashes used here and for PostHog are pseudonymous and matchable, not anonymous: SHA-256 does not reveal the email directly, but someone who knows or guesses it can hash it the same way and match it. It is not irreversible anonymization. We do not send OpenAI your plain email address. Choosing essential only blocks these ad conversion and audience signals.
A newsletter signup sends your email to Beehiiv so it can deliver the newsletter and manage confirmation, active status, unsubscribes, and deletion. A field-guide signup sends your name and email to our DigitalOcean-hosted database, Attio (CRM), Beehiiv, and Loops (contact and guide delivery); our D.B. Fresh service also sends those details to our internal Slack workspace. These delivery flows run even with essential-only consent because they perform the request you submitted.
When optional tracking is allowed, PostHog receives the profile data described above and Beehiiv may also receive the signup's UTM source, medium, and campaign. Guide links contain a random reader code used for access and share attribution; it identifies the link, never your identity, to other readers. Visiting our contact page loads an embedded Calendly scheduler even under an essential-only choice; Calendly receives connection data and any scheduling details you enter to provide the booking flow. Our separate PostHog and advertising events about that booking remain optional-gated.
The first-party torta_consent cookie has four stored states. An explicit all or essentialchoice lasts 180 days. With no valid choice, every visitor receives session-only pending: GTM, Google, PostHog, advertising, and campaign attribution remain off until you choose accept all. Missing and malformed values fail closed and become denied pending; timezone is never used to grant consent. A valid implicit cookie created by the older policy remains honored only until its original 90-day expiry for compatibility. We do not create or renew that state. A small essential localStorage notification containing only the consent transition and a random nonce wakes other open tabs; those tabs re-read the cookie rather than trusting the notification.
An HttpOnly first-party ts_attribution cookie keeps the first consented campaign touch for 90 days: Google, Microsoft, or Meta click IDs; UTM source, medium, campaign, term, and content; the external referring origin and path; landing path; capture time; and inferred platform. We use it to connect a later signup to the campaign that brought you. Guide signups may copy the snapshot into the lead record, and consented PostHog signup events may receive its click IDs. Later campaigns never overwrite the first touch. Choosing essential only in any tab updates every open tab and deletes this attribution cookie, exact PostHog tracking persistence, and the PostHog reader email-hash cookie while preserving consent, guide access, unrelated state, and PostHog's identifier-free opt-out marker. It stops future optional collection; it does not erase data already sent, which you can ask us to delete below.
A first-party guide reader cookie lasts up to one year so the requested guide remains accessible. PostHog uses host-only browser persistence and an app-owned consent-checking transport only when consent allows it; advertising tags follow the same optional gate. Cloudflare's essential __cf_bm cookie is the security exception described above.
Lead records are kept until you ask us to remove them. Newsletter lifecycle records remain in Beehiiv until they are unsubscribed or deleted there. Session recordings and analytics follow the retention settings of PostHog and Google Analytics. Email [email protected] to access or delete anything we hold about you; deletion requests are forwarded to the services above.
current choice: …
You can also opt out per platform through Google, LinkedIn, Meta, and OpenAI ad settings, or email us and we will handle it.
When the stack changes, this page changes in the same release. The effective date above always reflects the latest revision.