Updated 19 September 2026

Privacy

What this site records about your visit, why, and how to have it removed.

Every request to this site is logged, and this page says exactly what that means. Nothing here follows you to other sites, and nothing is sold, shared for advertising, or used to build a profile of you.

The logs exist so the site stays secure, so abuse can be spotted, and so the Activity app can show how busy the site has been.

What's recorded

Request logs8 months
ReactionsKept
Messages you sendNot stored
Page analyticsAggregated

One log entry per request, deleted automatically after 243 days. Reactions are the likes and loves on posts, and they are kept indefinitely: they hold no address, only the visitor ID below, and removing them would let the same person react to a post again and again.

What a log entry holds

Your IP address, the page you asked for and any query string, where you came from, your browser and its user agent, every request header your browser sent — credentials such as cookies and authorization are replaced with [redacted] before anything is written — an approximate location worked out from the IP, meaning country, region and city rather than a street, your network operator, and a fingerprint of your browser’s TLS handshake.

Your IP address is also turned into a visitor ID: a hash made with a secret salt that never leaves the server. It is what counts unique visitors and keeps reactions to one per person per post. It cannot be turned back into your IP address.

Why, and on what basis

Logging and analytics run on legitimate interest (Article 6(1)(f) GDPR): keeping the site secure, spotting abuse, and the public Activity app. You can object to this at any time, and I will remove your records.

A message you send with the Mail app is used to reply to you and for nothing else. Your address becomes the Reply-To of the email it turns into, so answering you is one click.

The booking calendar is the one thing that asks first, because it loads from Google and Google sets its own cookies. That runs on your consent, and you can take it back whenever you like.

Automatic classification

Each request gets a score guessing whether it came from a person, a search crawler or something suspicious, based on the user agent, the network it came from and the TLS fingerprint. It only feeds the visitor counts. It makes no decision about you, changes nothing about what you can see or do here, and has no legal effect, so it is not the kind of automated decision-making Article 22 covers.

Who else sees it

VercelHosting, analytics
CloudflareContact form
My own serverThe logs
GmailYour messages
GoogleOnly if you load the calendar
Lanyard, Discord, SpotifyThe status widget

The logs sit on hardware I run myself, not with a cloud provider. The status widget connects from your browser to Lanyard, which relays my Discord presence, so those services see your IP address the way any site you open does; they store nothing on your device. Some of these companies are outside the EU.

Stored in your browser

Your appearance settings — wallpaper, glass, reduced motion and reduced transparency — whether you have dismissed the lock screen this session, your language, and an offline copy of the pages you have opened so the site still works without a connection.

There is no cookie banner because none of this tracks you: it only remembers what you chose or keeps the site working offline, which is exactly what the rules exempt. Google’s booking calendar is the exception, and it asks before it loads.

Your choices

The booking calendar loads only if you ask it to, and you can withdraw that at any time. Taking it back is as easy as giving it.

Open Settings

Your rights

You can ask for a copy of what is held about you, have it corrected or deleted, have its use restricted, object to it being processed at all, or ask for it in a portable form.

Email me and I will deal with it within a month. Because records are keyed to a hash of your IP address rather than a name, tell me roughly when you visited and from which address, otherwise I cannot find them.

If you are unhappy with how I handle it, you can complain to your local data protection authority. For Romania, where I am based, that is ANSPDCP (dataprotection.ro).

Who runs this site

ControllerEduard Stere
Emaileduard.stal@gmail.com