Headroom is run by Kaleidoscope LLC, a California company. If you want anything on this page acted on — a copy of your data, a correction, or deletion — there is a form further down this page and a person on the other end of it. Under data protection law that makes Kaleidoscope LLC the “controller” of the information described below.
If you apply
The application asks six questions about your DJing, and then for your name, email address and phone number. All of it goes into a private spreadsheet that only I can open. No one else gets it, it is not sold, rented, or swapped, and there is no third-party service in the middle of it.
Your phone number is there because I would rather text than email. I use it to reply to your application and to tell you about the course. I do not call out of the blue, and it does not go anywhere else.
The legal basis is your consent, given by submitting the application. You can withdraw it at any time by replying to any message from me, or through the form below, and your details are deleted. Withdrawing does not undo messages already sent. Otherwise it is kept until you ask for it to go or until Headroom stops running, whichever comes first.
While you are filling the application in, your answers to the six questions are saved in your own browser, so that closing the tab does not lose them. Saved alongside them is the tracking code from the web address, if you arrived from an ad — the same code described below, kept here so that coming back to a half-finished application does not lose it. That copy never leaves your device, is not readable by this site until you press submit, and is deleted the moment you do. Your name, email and phone number are never part of it. Clearing your browser’s site data removes it, and it expires on its own after thirty days.
If you just read the site
Visits are counted with Fathom Analytics, which is here specifically because it does not set cookies, does not build a profile of you, and cannot follow you to other sites. What it produces is a count: how many people read a page, roughly where in the world they were, and which link they arrived from. None of that identifies you, and the legal basis is a legitimate interest in knowing whether anything on this site is being read.
The site is hosted by GitHub Pages and the videos are served by Cloudflare. Like every web server, theirs record the IP address and browser of anything that connects, which is a technical necessity of delivering a page to you rather than a choice made here.
If you arrived from an ad
Headroom advertises inside ChatGPT, on Reddit, and on Facebook and Instagram, and each of those companies has a measurement pixel that runs on these pages so an application can be traced back to the ad that paid for it. They work the same way as each other, and only the one belonging to the ad you clicked ever runs. Taking OpenAI's as the example:
- It only runs if you came from one of those ads. Clicking one adds a reference code to the web address, and that code — or a cookie left by it on an earlier visit — is what switches the pixel on. Arrive from a search engine, a link, or anywhere else, and none of the rest of this happens: nothing is loaded, nothing is stored, nothing is sent.
-
When it does run, it stores two cookies on this domain: the reference
code itself, as
__oppref, for thirty days; and__obref, a random number identifying your browser to OpenAI, for a year. Neither contains your name or your email address. -
If you then sign up, the pixel tells OpenAI that a signup happened, and
sends your email address and first name scrambled —
passed through a one-way function so OpenAI receives something like
a3f9c2…and never the address itself. OpenAI compares that against the same scramble of people who saw the ad. It is a way of matching two records without either side handing over the actual details. - What comes back is a number: how many signups an ad produced. Not who.
Reddit's pixel does the same job, and one thing differently. It runs only
if you arrived from a Reddit ad, which is what puts a rdt_cid
reference code in the web address; it stores _rdt_uuid, a
random number identifying your browser to Reddit; and if you apply, it
tells Reddit that an application happened.
Meta's pixel — Facebook and Instagram are the same company —
works the same way as Reddit's. It runs only if you arrived from one of
their ads, which is what puts an fbclid reference code in the
web address; it stores that code as _fbc and a random number
identifying your browser to Meta as _fbp, both for ninety
days; and if you apply, it tells Meta that an application happened.
The difference is what they are sent. OpenAI receives your email scrambled, because this site scrambles it first, and never your phone number. Reddit and Meta receive your email address, your phone number and your first name as they are. Neither system has a way to take a scrambled one from us — it would match nobody — so sending them at all means sending them as they are, and the honest thing is to say so rather than describe them as protected when they are not.
What Reddit and Meta do with them is match your application to the ad you clicked, and build a picture of the kind of person these ads reach, which is what decides who gets shown them next. If you would rather one of them did not have your details, not clicking their ads is enough — each pixel runs only for people who arrived from that company's own ad, so clicking a Reddit ad tells Meta nothing, and applying after arriving some other way sends all of them nothing at all.
Those two companies are the only advertisers involved, and those cookies are the only ones they set. The only other thing this site stores on your machine is the half-finished application described above — its answers and that tracking code — which never leaves it. The legal basis is consent where the law requires it.
To switch it off: not arriving from an ad is enough, and
is the usual case. Otherwise, block advertising scripts in your browser
or use any ad blocker — the pixels are loaded from
bzrcdn.openai.com and
www.redditstatic.com, and blocking those stops all of the
above.
Nothing else on this site changes if you do; the application works
exactly the same. You can also delete both cookies from your browser
settings at any time.
Where your information goes
The companies above — Google, which holds the signup spreadsheet; OpenAI; Reddit; Meta; Fathom; GitHub; Cloudflare — are all based in the United States, so applying means your name, email and phone number are stored there. If you are in the UK, the EEA, or Switzerland, that is an international transfer, and it is covered by the standard contractual clauses those providers publish.
Your rights
Wherever you live, you can ask for a copy of what is held about you, ask for it to be corrected, or ask for it to be deleted, and you can object to any of it. In the UK, the EEA, and Switzerland those are legal rights under the GDPR, along with the right to receive your data in a portable form and the right to withdraw consent at any time. In California they are legal rights under the CCPA. Everywhere else, the answer is the same anyway.
The form below is how you exercise any of them. It goes to a person, not a ticketing system, and the reply comes from a real address so you can simply continue the conversation from there. Expect an answer within thirty days, and usually within a few. There is no verification hoop beyond replying to that email, which confirms the address is yours.
If you are in the UK, the EEA, or Switzerland and you think this has been handled badly, you have the right to complain to your national data protection authority. You are welcome to try the form first.
Ask for something
Your email address is the only thing needed, because it is both the thing the request is about and the way to answer it. It is used for that and nothing else — asking to be deleted does not put you on a mailing list, which would be a remarkable way to run one.
Children
This site is not aimed at children and does not knowingly collect anything from anyone under 16. If you believe a child has signed up, say so through the form and it will be deleted.
Changes
If what the site collects changes, this page changes with it, and the date below moves. There is no mailing list for privacy policy updates and there is not going to be one.
Last updated 6 September 2026.