Journal
Notes from the desk, filed when they are true.
These pieces are written for product and data pairs already in the work. They are not recaps of vendor blogs. Dates reflect when the desk stood behind the argument.
Why hashed device IDs still leak identity in Thai fintech apps
Hashing is not anonymisation when the input space is a phone shop IMEI list. A Bangkok case from last rainy season, and what we now refuse in critique.
Designing an event taxonomy that survives a consent reset
What to version, what to freeze, and which properties should never return after a user says no. Written after three studios made the same mistake.
What “privacy-first” actually changes in your weekly product review
Four panes, one deletion log, and why counsel started staying until the end. A working format, not a manifesto.
Cohort windows vs. cookie windows: a measurement mismatch
Web cookie life still sneaks into app retention charts. Here is where the join usually hides and how first-party timestamps replace it.
How Bangkok product teams handle ATT-style prompts on Android
Thailand is not a copy of Cupertino. Permission copy, timing, and what the warehouse is allowed to remember after a decline.