notaroutine

Privacy

This is a personal log that happens to be readable by anyone. It has no accounts, no analytics and no advertising, and it collects nothing about you. There is exactly one place where anything leaves your browser, and you have to press a button to make it happen.

N=1, not medical advice. This page describes how the site handles data, which is a different thing from being legal advice about your data.

Everything you log stays in your browser

Sessions, the plans you build, the weights and reps you type in, your own movements and their links, your readiness numbers — all of it is written to this browser’s local storage on this device. It is not uploaded. There is no server that holds it, which also means there is no server that can be asked for it, breached for it, or sold with it.

The flip side is honest: clearing your site data deletes it, and it does not follow you to another device or another browser. Nobody can send it back to you, including me.

Readiness data never leaves the device. At all.

Recovery, HRV, resting heart rate, sleep, sleep performance, strain, and whatever you type into the notes field — that is health data, and it is the most revealing thing on this site. It is never put in a request, never synced, never backed up anywhere. The one server this site talks to has no endpoint that would accept it: a request carrying it would be answered with a 404 before anything read the body.

The Copy the prompt and Copy brief buttons put text on your clipboard. If you then paste that into Whoop, Claude or anything else, the data goes wherever you pasted it, under that company’s terms rather than these. That is your decision each time, which is exactly why it is a copy button and not an integration.

The one request: the shared video library

The Videos page has a shared library at api.notaroutine.life. Your browser asks it for the list when that page opens, and posts to it when you press Share it or report an entry. Nothing else on the site talks to it, and every page works normally when it is unreachable — the shared list goes empty and says so.

An entry in that library is five things and nothing else:

There is no column for who submitted it, when, from where, or with what. There is no timestamp at all, and entries are ordered by movement name and then by that random id, so the list cannot be read back as a record of who was here when. Two entries from the same person cannot be linked to each other, by me or by anybody else.

No accounts, no cookies, no analytics

No email address, no username, no phone number, no password. No cookies of any kind, including the ones sites set for their own analytics. No Google Analytics, no Plausible, no pixels, no embedded players, no fonts loaded from anyone else’s server — the two typefaces are files in this repository. Nothing on any page makes a request to a third party.

What the hosts see, because it would be dishonest not to say

The site is served by GitHub Pages, and the shared library runs on Cloudflare. Any computer that serves you a file necessarily receives the request that asked for it, which includes your IP address. That is true of every website and I cannot make it untrue; what I can do is not use it. The Worker keeps no logs — request observability is turned off — and nothing about a request is written to the database.

The rate limit that stops one person flooding the library is Cloudflare’s own, counted at their edge. What it is handed is a hash of the connecting address rather than the address, and it is a counter that expires after a minute, not a record.

Reporting something in the shared library

Every shared entry has a report button, and it asks which of four things is wrong before it sends anything. No account, no explanation needed, no free-text box: there is deliberately nowhere in that flow to type something about yourself, or about anyone else.

Two of those four outcomes are different, and the button says so before you press it:

The first tier is still abusable by anyone determined — there is no login to stop them. The trade is deliberate, and it is narrowed to the one reason where being wrong in that direction is the cheaper mistake.

Anything else — a link that should come down, a question about this page — goes to hello@notaroutine.life. That address is a person, not a signup.

Deleting things

Your own data: clear this site’s data in your browser, or use the clear buttons on the builder and sessions pages. It is gone at that point, everywhere, because there was only ever the one copy.

Something you shared: report it, or email the address above. Since nothing ties an entry to you, I cannot find “everything you submitted” on request — that is the cost of not knowing who you are, and it is the right cost.

What isn’t working


Back to the videos →