Legal
Privacy Policy
What this site collects, why, where it goes, and how to exercise your choices. The company responsible for your information is Aurora Group Platforms LLC.
Who this covers
This policy applies to yourbodyinsight.com (the "Site") and to The Atlas Letter, our email newsletter. The Site is published by Aurora Group Platforms LLC, 30 N Gould Street, Sheridan, WY 82801, United States, which decides how and why the information described here is used. We are a small publisher: there are no user accounts, no checkout, no comments section and no contact form, so the amount of information we can collect is limited, and this page describes all of it.
The short version
- If you subscribe to the newsletter, we store your email address, the time you signed up and your IP address in a file on our own server. Nothing else.
- Your cookie choice is saved in your browser under the name
ybi_consent. It never leaves your device. - A Microsoft Advertising measurement script is present on every page, but advertising storage is set to "denied" until you click Accept. If you decline, or your browser sends a Global Privacy Control signal, it stays denied.
- Our web server and Cloudflare keep ordinary access logs.
- We do not sell personal information, we run no other trackers, and we never see what you buy on Amazon.
What we collect, and when
| Information | When | Why | Where it lives |
|---|---|---|---|
| Email address, sign-up time (UTC) and IP address | When you submit the newsletter form | To send you The Atlas Letter and to detect duplicate or automated sign-ups | A private file on our own server |
| Your cookie choice ("granted" or "denied") | When you click Accept or Decline, or when your browser sends a Global Privacy Control signal | So the banner does not ask again on this device | Your browser only (local-storage item ybi_consent) |
| Microsoft Advertising UET page-view events and, after Accept, Microsoft's advertising identifiers | Every page load sends an event; identifiers are stored or read only after you click Accept | To measure whether visits to the Site followed one of our ads | Microsoft, as an independent company |
| Standard access-log data: IP address, browser and device type, page requested, time, referring page | Every request | Keeping the Site running and secure, diagnosing errors, stopping abuse | Our web server and Cloudflare's network |
The newsletter, step by step
The sign-up form on the homepage sends your email address to a small script on our own server. Here is exactly what that script does, in order:
- It checks a hidden anti-spam field. Real visitors never see or fill that field; if it contains anything, the script assumes an automated submission and stores nothing.
- It checks that the address is a valid email address. If not, it rejects the request and stores nothing.
- It looks for your address in the existing list, ignoring upper and lower case. If you are already subscribed, it stores nothing new.
- Otherwise it adds one line to a private subscriber file: your email address, the date and time in UTC, and your IP address. Because the Site sits behind Cloudflare, the address recorded is the visitor address Cloudflare passes to us (the
CF-Connecting-IPheader) rather than Cloudflare's own.
There is no confirmation email and no double opt-in step: submitting the form is the subscription. We use the address only to send The Atlas Letter, which goes out when we add an entry or a field note, not on a daily schedule. We do not sell, rent or trade the list. If we use an email-delivery service to send issues, your address is passed to that service for the sole purpose of delivering the email. To unsubscribe, email [email protected] from the subscribed address with the word "unsubscribe"; we delete your line from the file, including the timestamp and IP address, and you receive nothing further.
Cookie consent and Microsoft Advertising, exactly as built
We advertise the Site on Microsoft's search network, and we use Microsoft Advertising's Universal Event Tracking (UET) tag to see whether those ads lead to visits. We want to be precise about how it behaves, because "we only load the tag after you accept" would not be true:
- The UET script (
bat.bing.net/bat.js) is included in the head of every page and loads on every visit. Immediately after it, the page sets Microsoft's consent default toad_storage: denied. This is what Microsoft calls its advanced consent mode. - On your first visit, a banner offers Accept and Decline. Accept stores "granted" in your browser under
ybi_consentand sends Microsoft a consent update of "granted"; on later visits the stored value is read and the same update is sent again. Decline stores "denied", and the default stands. - If your browser or an extension sends the Global Privacy Control signal and you have not yet made a choice, the Site records "denied" for you and does not show the banner at all. We treat GPC as a Decline.
- The "Cookie settings" button in the footer erases the stored choice and reloads the page, so the banner appears again and you can choose differently. Clearing your browser's site data does the same.
According to Microsoft's consent-mode documentation, when ad_storage is denied, first-party cookies are neither read nor written for UET, third-party cookies are not written, and any third-party cookie that is read is used only for fraud and spam detection. A page-load event still reaches Microsoft in that state; Microsoft describes the data collected under a denied signal as anonymized and aggregated. Only after you click Accept may Microsoft set and read the identifiers listed in our Cookie Policy. Microsoft states that it retains UET data for 390 days and does not resell it or share it with other advertisers. Microsoft processes this data as an independent company under its own privacy statement, not as our service provider; we receive aggregate reports, never a list of individual visitors.
UET is the only measurement or advertising tag on the Site. There is no Google Analytics, no social-media pixel, no session-replay tool and no third-party font service (our fonts are served from our own domain).
When you click through to Amazon
Every product link on the Site goes to a product page on amazon.com and carries our Amazon Associates tag, which is how Amazon knows a visit came from us (see our Affiliate Disclosure). Once you are on Amazon, Amazon's own Privacy Notice and its Interest-Based Ads page govern what Amazon collects, including the cookies it sets on its own domain. Amazon reports to us how many qualifying purchases were made through our links and which items were ordered, in aggregate; it does not tell us who you are, and we cannot see your account, your orders or your address.
What we do not collect or do
- No accounts, passwords or profiles.
- No payment information, ever. We do not sell anything.
- No health information. We do not ask about your conditions, medications or symptoms, and we ask you not to send them to us by email.
- No sale of personal information, and no combining of your data with data from other sites.
- No tracking of the newsletter beyond what a delivery service needs in order to send the email.
Who else handles your information
- Cloudflare sits in front of the Site as a proxy, content-delivery and security layer. Every request passes through its network, so it processes connection data (IP address, request details) as our service provider.
- Our hosting provider runs the server where the Site and the newsletter file live.
- Microsoft Advertising, as described above: the recipient of consent-denied page-load events before you choose, and of advertising identifiers only after you click Accept.
- An email-delivery service, if we use one to send the newsletter, receives subscriber addresses for delivery only.
- Authorities and courts, if we are legally required to disclose information, or to protect the rights and safety of the Site, its readers or the public.
Where your information is processed
Aurora Group Platforms LLC is a United States company and our server is located in the United States. Cloudflare operates a global network, so your request may pass through a Cloudflare data center near you before reaching our server. If you visit from the European Economic Area, the United Kingdom or Switzerland, your information is transferred to and processed in the United States, whose data-protection rules differ from those at home. We are a small US publisher and have not entered into standard contractual clauses or joined a certification framework for such transfers. The only personal information we hold about you as a visitor from outside the US is what you choose to give us by subscribing, and you can have it deleted at any time by email.
How long we keep it
- Newsletter record (email, sign-up time, IP address): for as long as you remain subscribed. Deleted when you unsubscribe or ask us to delete it.
- Cookie choice (
ybi_consent): in your browser until you clear site data or press "Cookie settings". - Access logs: kept only as long as needed for security and troubleshooting, then overwritten by routine log rotation. Cloudflare keeps its own connection logs for its standard operational window.
- Microsoft Advertising data: retained by Microsoft for 390 days according to its documentation; the identifiers in your browser last for the periods described in the Cookie Policy, or until you clear them.
Security
The Site is served over HTTPS, sits behind Cloudflare, and keeps the subscriber file in a private directory that is not linked from any page. Access to the server is restricted to the people who run the Site. No method of storage or transmission is perfectly secure, and we cannot promise that information will never be exposed by events outside our control, but we hold very little and we keep it simple.
Children
The Site is written for adults and is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has subscribed to the newsletter, email us and we will delete the record.
Your rights and choices
Everyone
You can change your cookie choice at any time with the "Cookie settings" button in the footer, unsubscribe from the newsletter by email, and ask us what we hold about you. For almost everyone, the honest answer is "nothing" or "one newsletter line."
California residents (CCPA/CPRA)
If you live in California, you have the right to know what personal information we collect, use and disclose; to request a copy of it; to request its deletion; to request correction of inaccurate information; to opt out of the sale or sharing of personal information; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights. We do not sell personal information and we do not collect sensitive personal information. The only activity on the Site that could count as "sharing" for cross-context behavioral advertising under California law is the Microsoft Advertising tag after you click Accept. To opt out, click Decline, use the "Cookie settings" button in the footer, or turn on Global Privacy Control in your browser, which we honor automatically as an opt-out request. We respond to a verifiable request within 45 days and will tell you if we need up to 45 more. To verify a request we may ask you to write from the email address you subscribed with. An authorized agent may submit a request on your behalf with your written permission. We apply the same rights to residents of other US states with comparable privacy laws.
Visitors in the EEA, the UK and Switzerland
Where the GDPR or UK GDPR applies, our legal bases are your consent (newsletter, advertising storage), our legitimate interest in running a secure website (access logs, anti-spam checks), and compliance with legal obligations. You have the right to access, correct and erase your personal data, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent at any time without affecting what was done before you withdrew it. We answer within one month. You may also complain to your local data-protection authority, though we would appreciate the chance to resolve the matter first.
How to make a request
Email us. Say which right you are exercising and, for newsletter matters, write from the subscribed address. We do not operate a phone line for privacy requests.
- Publisher
- Aurora Group Platforms LLC
- Address
- 30 N Gould Street
Sheridan, WY 82801, United States - [email protected]
Governing law
This policy and any dispute about it are governed by the laws of the State of Wyoming, United States, and by our Terms of Use, which name the state and federal courts sitting in Sheridan County, Wyoming as the venue, without taking away any rights you have under the privacy laws where you live.
Changes to this policy
We will update this page when our tools, our practices or the law change, and we will move the "Last updated" date at the top when we do. If a change would let us collect something new, the change appears here before the collection starts. We do not send notices of changes, so check back occasionally.
Sources
- Microsoft Advertising, "Setting up UET for consent mode": the meaning of ad_storage granted and denied, and how advanced consent mode loads the tag. learn.microsoft.com/en-us/advertising/msa-help/hlp_ba_conc_uet_consent
- Microsoft Advertising, "FAQ: Universal event tracking": what UET collects, the 390-day retention period, and the statement that Microsoft does not resell the data. learn.microsoft.com/en-us/advertising/msa-help/hlp_ba_conc_uet_faq_2
- Global Privacy Control: what the signal is and how California law treats it. globalprivacycontrol.org
- Cloudflare, "Cloudflare cookies": the technical cookies Cloudflare's network may set. developers.cloudflare.com/fundamentals/reference/policies-compliances/cloudflare-cookies