The privacy promise
Your readers did not agree to be measured. They agreed to receive a letter. Letter Kit is built so that the second thing does not quietly require the first.
No open-tracking pixel
Almost every newsletter you receive contains an invisible image, one pixel across, with a URL unique to you. Loading it tells the sender that you opened the message, roughly when, and from what network.
We do not put one in. Not off by default — absent.
There is a practical argument as well as a principled one. Since Apple Mail began pre-fetching images on its readers' behalf, a large share of recorded "opens" are a data centre loading a picture that no person ever saw. The number that results is not a small approximation of engagement; it is a measurement of somebody else's caching policy. Reporting it as a percentage with a decimal point would be the dishonest part.
No click rewriting
The other standard practice is replacing every link in your issue with one pointing at the sending platform, which records the click and forwards the reader on. It is why newsletter links so often look like nonsense when you hover over them.
Your links go out as you wrote them. A reader can see where a link goes before following it, the link keeps working if we ever stop existing, and your issue does not train people to click through a domain that is not yours.
What we do measure
The mail server tells us what became of each message, and that is what you see:
| Sent | The message was handed to the mail service |
|---|---|
| Delivered | The receiving server accepted it |
| Bounced | It was rejected, permanently or temporarily |
| Complained | The reader marked it as spam |
| Unsubscribed | The reader used the unsubscribe link |
These are outcomes of delivery, not observations of a person reading. We need them: unhandled bounces and complaints are how a sending domain loses its reputation, and acting on them is the price of your issues arriving at all. They are also the honest limit of what a sender can know without watching.
Your list is yours
- We do not sell, rent, share or analyse your subscriber list.
- We do not email your subscribers on our own behalf, ever.
- We do not build a profile of a reader across the newsletters they receive here.
- You can export your subscribers, in full, whenever you want.
- If you leave, your list is deleted rather than retained in case you return.
Consent, on the record
Every subscriber confirms by email before they are active, and we keep the record of when they subscribed, from where, and when they confirmed. That exists to answer a question about consent if one is ever asked — of you, or of us — not to profile anyone.
The archive is public, and only that
Issue pages on the archive are ordinary web pages. No analytics script, no third-party embeds, no cookies for a reader who is only reading. If a page were to need a cookie one day, it would be because you asked for something that required one, and it would be said plainly here first.
Archive links we put in your emails carry no identifier for the reader who received them. That is the rule that keeps the promise above honest. A link that quietly named its recipient would let anyone holding the server logs reconstruct who read which issue — which is click tracking wearing a different hat, whether or not anything is called tracking.
One place we do count, and say so
The marketing pages you are reading now — not the archive, and not anything sent to a subscriber — count page views through Cloudflare Web Analytics. It sets no cookie, stores nothing on your device, and builds no fingerprint from your address or browser, so it cannot follow anyone between visits.
We mention it because a privacy page that quietly omitted it would be exactly the kind of thing this page exists to argue against. Measuring how many people read our own sales copy is a different act from measuring what a subscriber does with their mail, and the second one is the one we refuse.
Where this sits with the legal documents
This page is the promise in plain language. The privacy policy is the formal version, and the terms govern the service. If this page and those ever disagree, that is a mistake in our writing — tell us and we will fix it.