gtmjosh

Privacy Policy

Last updated: September 29, 2026

GTM Josh is a personal publication site run by Josh Buchanan. This page explains what information the site collects and how it is used.

Information I collect

If you subscribe to the newsletter, I collect your email address and basic subscription metadata, such as the page you subscribed from. Newsletter subscriptions are handled through Buttondown.

Like most websites, hosting and infrastructure providers may collect basic technical information in server logs, such as IP address, browser type, requested URL, referrer, and timestamps. This is used for security, debugging, abuse prevention, and basic site operation.

The site may use local browser storage for preferences, such as light/dark mode and newsletter form state, and temporary session storage for traffic measurement. This browser-side state stays on your device.

Site traffic analytics

GTMJosh uses Vercel Web Analytics and a first-party traffic counter to understand how the public site is used. Traffic analytics may include the page path, timestamp, acquisition channel, referrer hostname, optional UTM campaign tags, coarse country code, and coarse device type. Admin, lab, and internal routes are excluded from the first-party traffic counter.

For the first-party counter, a random browser session identifier is kept in session storage and rotated after 30 minutes of inactivity. The server stores only a one-way keyed hash of that session identifier so pageviews from the same visit can be counted together. The traffic table does not store the raw session identifier, raw IP address, or full user-agent string. Vercel may process technical information for its analytics service according to its own terms and privacy practices.

First-party behavior measurements also record estimated time while a public page is visible, the deepest visible content position, and counts of selected actions such as copying code, clicking a download, completing a chapter, or saving a completed exercise receipt. These measurements are linked to the temporary session and pageview, not to your account or email address. They do not contain copied text, form entries, exercise answers, or session replay. No persistent cross-visit visitor identifier is added for this reporting. Detailed engagement measurements are automatically removed after 90 days.

Interactive demos

Some guides may link to or proxy interactive demos. Demo usage may be rate limited to prevent abuse and control API costs. If a demo asks for an email address after free usage is exhausted, that email may be used to continue access and subscribe you to GTM Josh updates.

Demo data is sample or mock data unless a page clearly says otherwise. Do not submit sensitive, confidential, or production customer data into a demo.

GTM Skill Lab

Skill Lab uses fictional CRM records and simulated enrichment providers. Deterministic examples run in your browser without sending a request to a model or enrichment vendor. Up to five reference traces are kept in local storage and can be removed by clearing this site's browser storage.

When you choose a live model run, your submitted request and the synthetic tool results are sent to OpenAI. The application requests that OpenAI not store the response. GTMJosh separately stores the request, explicit tool calls and results, synthetic snapshots, model usage, errors, and approval events so you can inspect and replay the run. This is an execution log, not a screen recording or the model's hidden chain-of-thought.

Live runs are associated with a keyed hash of a signed visitor cookie and are retrievable only in that browser session for seven days. Expired run records are removed in bounded batches during subsequent run admissions. A keyed IP hash is used for abuse and cost limits; the Skill Lab run table does not store raw IP addresses. The site operator can use these records for troubleshooting, safety checks, and aggregate usage reporting. Do not include confidential information or real customer records in your request.

josh.ai

josh.ai is an optional GTMJosh assistant. You can use it without an account. Anonymous conversation history is stored only in your browser for up to 30 days, limited to your 10 most recent conversations. It can be cleared from the chat panel or by clearing this site's browser storage. Individual questions submitted to josh.ai may also be stored separately as query analytics, as described below; this does not store the anonymous assistant transcript as a server-side conversation.

If you sign in, you provide an email address, confirm that you can receive mail at that address, and either already have an active newsletter subscription or choose to subscribe. The verification email is sent through Resend and newsletter access is managed through Buttondown. You can choose to add conversations saved on your device to your account when you sign in. Your completed guide chapters and last location are also synchronized with your account, while anonymous guide work remains stored only in your browser. Account conversations are retained for up to 12 months unless you delete them sooner. Deleting your chat account does not unsubscribe you from the newsletter.

Chat messages, the selected learning path, and limited page context such as the URL, page title, visible heading, and nearby text are sent to OpenAI to generate a response. The application requests that OpenAI not store the response. GTMJosh stores signed-in conversations as described above. Josh may review a conversation and follow up personally only if you select that optional consent. Do not submit confidential, regulated, customer, or production data.

Search and query analytics

When you explicitly submit a site search or a question to josh.ai, GTMJosh may store the submitted text, the part of the site where it was submitted, limited page-path context, the number of matching search results when applicable, and the time of the request. Autocomplete text that you have not submitted is not stored as a search query.

These records are used to understand what readers are trying to find, identify missing or difficult-to-find content, and improve the site and assistant. Query analytics do not store your raw account or visitor identifier; the site derives a one-way keyed hash so repeated requests can be counted without exposing that identifier in the analytics record. Because submitted text itself is stored, do not put confidential, regulated, customer, or production information into site search or josh.ai.

Internal tools and Google Ads API data

I may use private internal tools to perform SEO and keyword research for owned GTM Josh content. These tools may use services such as the Google Ads API Keyword Planning service to retrieve keyword ideas and keyword metrics. This is used for content planning only and does not involve selling, sharing, or exposing personal visitor data.

How I use information

I use collected information to operate the site, send newsletter updates, improve content, prevent abuse, debug issues, and understand which topics are useful to readers.

How information is shared

I do not sell personal information. Information may be processed by service providers that help run the site, such as hosting, analytics, newsletter, database, email, or infrastructure providers. Those providers process data according to their own terms and policies.

Information may also be disclosed if required by law, to protect the site, or to prevent abuse.

Your choices

You can unsubscribe from the newsletter using the unsubscribe link in any email. You can also block cookies or clear local and session storage in your browser, though some preferences and measurement state may reset.

Contact

Questions about this policy can be sent to josh@gtmjosh.com.