Privacy
Last updated 27 August 2026
What THOUSAND NIGHTS collects, why, how long it’s kept, and how to delete all of it yourself.
THOUSAND NIGHTS is a record of what you read before bed. Keeping that record is the only reason we hold anything about you at all, and the short version of this page is: we collect your email address and the things you log, we don’t sell any of it, and you can delete the lot yourself without asking us.
What we collect
Your email address. Signing in works by sending a six-digit code to your email, so we need the address to send it to. It’s stored with your account and it’s the only thing here that identifies you as a person.
What you log. For each night: the title of the poem, the story and the essay, the author where you name one, and the language you read in. It’s free text — you type it, we keep it as you typed it. Plus your time zone, so that “tonight” means your night and not a server’s.
Analytics. Which pages get visited and roughly how people move through the site. We use PostHog for this, and Vercel Web Analytics alongside it. While you’re signed in, analytics events are tagged with your account id so we can tell — for example — whether people who log a first night come back to log a second.
We don’t collect anything else. No advertising trackers, no data brokers, no third-party profiles bought in to fill out what we know about you.
Cookies, and why there’s no banner
You haven’t been asked to accept cookies because there is nothing to accept. Analytics here is configured to store nothing at all on your device — no cookies, no local storage — so the count of people on a page is genuinely approximate and we’re fine with that. Vercel Web Analytics is cookieless by design too.
The one thing we do store on your device is the session cookie that keeps you signed in after you enter your code. It’s strictly necessary for the site to work, which is why it doesn’t need consent, and it goes when you sign out.
Why we hold it, and who else sees it
Your email is there so you can sign in and so we can reach you about your account. The rest is there because it is the product — a record of a thousand nights is not much use if it forgets. We look at analytics to work out which parts of the site are worth building on.
Your nights are private. There is no public feed, no shared library, and no page anywhere on this site that shows one reader’s record to another. Nothing is sold, and nothing is shared with anyone except the services that run the site: Supabase (database and sign-in), Vercel (hosting), Resend (sending your sign-in codes) and PostHog (analytics). Each of them holds the data to do that job and nothing more.
How long we keep it
Your account and your record are kept until you delete them. We don’t expire accounts for inactivity, and we don’t reset anything if you stop for a while — a night you miss simply isn’t counted, and nothing else happens. A record you come back to after five years should still be there.
Analytics events are retained by PostHog on its own schedule, and because analytics stores nothing on your device, events collected while you were signed out aren’t linked to you at all.
Deleting everything
Deletion is total: your account, every night you’ve logged, your preferences and your stored email address go together, immediately. Nothing is soft-deleted, held in a recycle bin, or kept in reserve — which also means we can’t undo it for you.
The self-serve button lands with the rest of your preferences shortly. Until it does — and afterwards, if you’d rather we did it — write to hello@thousandnights.app and we’ll delete your account on request. The same address handles a copy of your data or a correction. You also have the right to complain to your data protection regulator — in the UK that’s the Information Commissioner’s Office.
Changes, and getting in touch
If this page changes in a way that matters, the date at the top changes with it. Questions, corrections, or anything that looks wrong anywhere on the site: hello@thousandnights.app.
THOUSAND NIGHTS is made by Noble Fluency LLC, which is the data controller for everything described here.