Follow

Privacy

last updated

This is a blog. It has no accounts, no comments, no newsletter and no analytics, so there is very little to write a privacy policy about. Here is the whole of it anyway, because “we value your privacy” on a page that then loads six trackers is not worth reading.

the short version

  • No account to create and no form to fill in, so you never hand me anything.
  • No analytics, no advertising, no tracking pixels, no third-party embeds.
  • The site sets no cookies of its own. Your theme choice stays in your browser.
  • Cloudflare serves the pages and sees the usual request data, the way any web server does.

Who is responsible

Marcin runs this site as a private individual, and is the data controller for anything described here. Contact: marcin.adroit.dev@gmail.com.

What the site collects from you

Nothing you type, because there is nowhere to type it. No sign-up, no login, no comment box, no contact form, no newsletter. The only way to reach me is the email address above, and then I have whatever you chose to put in the message.

There is no analytics package on any page. No Google Analytics, no self-hosted alternative, no tracking pixels, no advertising, no A/B testing, no session recording, no heatmaps. Nothing about your visit is profiled, and nothing is sold or shared for marketing.

Fonts are bundled with the site rather than pulled from a font CDN, so loading a page does not announce your IP address to a third party you did not choose.

What the server sees

The site is hosted on Cloudflare Workers. Like every web server, Cloudflare's edge sees the data a browser sends in order to be answered: your IP address, the page requested, the user agent, a timestamp, and similar request metadata. This is used to deliver the site and to keep it standing up under abuse, which is a legitimate interest under Article 6(1)(f) GDPR.

I keep no server logs of my own and run no database of visitors. Cloudflare processes that request data as my hosting provider, under its own data processing terms, and retains its edge logs for a limited period set by its policy rather than by me. Cloudflare is based in the United States, and covers transfers under the standard contractual clauses in its data processing addendum.

Cookies and browser storage

The site sets no cookies of its own. Your light or dark theme preference is kept in your browser's local storage, which is not a cookie and is never sent anywhere. Clearing site data forgets it.

Cloudflare may set a strictly necessary security cookie to tell browsers apart from bots. There is no consent banner because there is nothing optional to consent to, and a banner offering a choice that does not exist is theatre. The cookie policy has the detail.

Links out, and the feed

Articles link to documentation, repositories and other people's writing. Once you follow a link you are on their site under their policy, not this one. Code samples are plain text and embeds are avoided, so a page does not quietly load a video player or a widget that watches you read.

The RSS feed is a static file with no per-subscriber URLs and no tracking pixels. I cannot tell who subscribes to it, which is how a feed should work.

Your rights

Under the GDPR you can ask for access to your personal data, its correction or erasure, a restriction on how it is used, a copy in a portable form, and you can object to processing based on legitimate interest. In practice I hold nothing that identifies you unless you have emailed me, in which case those rights apply to the email.

You can also complain to the data protection authority in the EU or UK country where you live or work. I would rather you wrote to me first, but that is your call, not a precondition.

There is no automated decision-making or profiling here. The site is not aimed at children, and collects nothing that would tell me a reader's age.

not live yet

Accounts and payments

None of this is running today. It is written down so the change is visible when it happens rather than appearing quietly in a diff.

Paid articles and courses are planned. When accounts arrive, creating one will mean storing an email address and a hashed password, and a session cookie will be set to keep you logged in. That cookie is strictly necessary: without it you cannot stay signed in.

Payments will be handled by Paddle, which acts as the seller and takes care of card details and tax. Card numbers will never reach this site, and I will see that a purchase happened, not what you paid with. If a Patreon connection is added later, linking your account will share only whether your membership is active at the required tier.

This page gets updated before any of that goes live, not after.

Changes

If this policy changes, the date at the top changes with it. Something that affects what is collected gets a note saying what moved, because a silently edited privacy policy is not much of a promise.

Questions about any of this go to marcin.adroit.dev@gmail.com. A person reads it, not a ticketing system.