Privacy Policy
Please, Mrs. Henry! · Last Updated: May 13, 2026
Notice: This Privacy Policy is provided as a general template and is not legal advice. Stinky Tofu Publishing recommends consulting a qualified attorney before relying on it.
1. Introduction
This Privacy Policy explains how Stinky Tofu Publishing(“we,” “us,” or “our”) collects, uses, and shares information when you visit www.pleasemrshenry.com(the “Site”), the official website for the novel Please, Mrs. Henry! by Brian A. Ask. By accessing or using the Site, you agree to the practices described in this Policy.
2. Information We Collect
A. Information You Provide
We collect information you voluntarily provide—such as your email address and any message contents—when you contact us or submit a form on the Site. The Site features an “Easter Egg” discovery game; if you participate, we may collect:
- Easter-egg guesses you submit (the text of the guess is sent to an AI provider for evaluation, see Section 4);
- An optional finder name you may attach to an egg you have successfully discovered;
- Easter-egg suggestions, including the description you submit and (if you choose to provide it) an email address for follow-up.
B. Information Collected Automatically
When you visit the Site, our hosting and infrastructure providers may automatically log technical information including your IP address, browser type, referring page, pages visited, and timestamps. To keep the Easter-egg game fair and to prevent abuse, we derive a salted, hashed value from your network address using a server-side secret (a “pepper”) and store only that hash to enforce per-visitor discovery and rate limits. We do not store raw IP addresses for these purposes.
3. How We Use Your Information
We use the information we collect to:
- Operate, maintain, and improve the Site;
- Run the Easter-egg discovery game, including evaluating guesses and enforcing fair-play limits;
- Respond to inquiries and communicate with you;
- Protect against fraud, spam, abuse, and security threats;
- Comply with legal obligations and enforce our Terms of Use.
4. How We Share Information
We do not sell your personal information. We may share information with:
- Hosting— Vercel (site hosting and request logging).
- Database— Supabase (stores Easter-egg discovery records, finder names you choose to attach, and the salted IP hash used for per-visitor limits).
- AI Evaluation— Google Gemini (analyzes the text of Easter-egg guesses against the publicly visible Easter-egg titles and descriptions to determine whether a guess matches a hidden reference). The secret keywords used to validate a guess are not transmitted to the AI provider; they remain on our server.
- Rate Limiting— Upstash (stores the salted, hashed identifiers described in Section 2B to enforce short-window request limits on Easter-egg actions).
- Analytics— Vercel Web Analytics (privacy-friendly, cookieless page-view counts; does not use cross-site tracking and does not store identifiers in your browser).
- Transactional Email— Resend (forwards Easter-egg suggestions to the operator).
- Legal Compliance when required by law, subpoena, court order, or to protect the rights, property, or safety of Stinky Tofu Publishing, our users, or others.
- Business Transfers in connection with a merger, acquisition, financing, or sale of all or part of our assets.
5. Cookies and Similar Technologies
The Site does not set tracking cookies for marketing, advertising, or cross-site profiling. Our analytics provider (Vercel Web Analytics) is cookieless and does not write identifiers to your browser. Our hosting and security providers may set short-lived, strictly necessary cookies (for example, to route requests or to mitigate abuse); these are not used to build a profile of you. You can configure your browser to refuse cookies, though some features of the Site may not function properly as a result.
6. Data Retention
We retain personal information only for as long as needed to fulfill the purposes described in this Policy, comply with legal obligations, resolve disputes, and enforce our agreements. We periodically delete or anonymize data that is no longer needed.
7. Security
We use reasonable administrative, technical, and physical safeguards to protect the information we hold. No method of transmission over the internet or method of electronic storage is 100% secure, however, and we cannot guarantee absolute security.
8. Your Rights and Choices
Depending on where you live, you may have the right to access, correct, delete, port, or object to the processing of your personal information, and to opt out of certain disclosures. California residents have additional rights under the California Consumer Privacy Act (CCPA). EU and UK residents have rights under the GDPR/UK GDPR. To exercise any of these rights, contact us at the email address below.
9. Children’s Privacy
The Site is not directed to children under the age of 13 (or 16 in the EU/UK), and we do not knowingly collect personal information from such children. If you believe a child has provided us with personal information, please contact us so we can delete it.
10. Third-Party Links
The Site may link to third-party websites (such as retailers, publishers, or social-media platforms). We are not responsible for the privacy practices of those sites. Please review their respective privacy policies.
11. International Users
The Site is operated from the United States. If you access the Site from outside the United States, you understand that your information may be transferred to and processed in the United States, where data-protection laws may differ from those of your country.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last Updated” date at the top of this page. Continued use of the Site after changes are posted constitutes acceptance of the updated Policy.
13. Contact Us
If you have questions about this Privacy Policy or our practices, please contact us at brian@pleasemrshenry.com.
See also our Terms of Use.