Legal
Privacy Policy
Last updated
This is a starting point, not legal advice. Review it with counsel and adapt it to your jurisdiction and the services you actually use before publishing a real site. The privacy and data guide lists every place to update.
What we collect#
- Account data. If you create an account we store your name, email address, whether the address was verified, a hashed password or the identity returned by GitHub or Google, and the session records needed to keep you signed in (creation time, expiry, IP address and browser user agent).
- Contact form messages. Messages you send through the contact form are stored together with the name and email address you provide so we can reply. Their workflow state (new, read, archived) and whether the notification to us was delivered are stored as well.
- Audit log. Administrative actions, data exports and account deletions are recorded with the acting account so we can show what happened to your data. The log never contains message text or passwords.
- Server logs. Our hosting provider records standard request logs (IP address, user agent, requested URL) for security and debugging. Logs are retained for a limited time.
What we do not collect#
The site does not use third-party advertising, tracking pixels or cross-site cookies. Fonts are self-hosted, so no requests are made to font providers. If analytics is enabled, it uses a privacy-friendly, cookie-less provider and never stores personal identifiers.
Cookies#
We set only the cookies required to operate the site: an authentication session cookie when you sign in and a preference for light or dark mode stored in your browser’s local storage.
Service providers#
Depending on how this deployment is configured, the following providers process data on our behalf: the hosting platform (Vercel, Cloudflare, Netlify or our own server), the database provider (Turso) and the email provider (Resend) for sign-in links, verification and notifications. GitHub or Google only receive data when you choose to sign in with them.
Retention#
- Accounts and their sessions are kept until you delete the account. Expired sessions are removed automatically.
- Contact messages are kept while they are open. Archived messages are deleted after one year (or the retention period configured for this deployment). Where a maximum age is configured, messages are deleted after it regardless of their state.
- Audit log entries are kept indefinitely. They reference accounts and messages by identifier only.
Your rights#
You can exercise your rights yourself from your account dashboard:
- Access and portability. Download a copy of everything stored about you as a JSON file (“Download my data”).
- Erasure. Delete your account, its sessions and connected sign-in methods. Contact messages sent from a verified email address are deleted with it.
- Rectification. Change your password from the dashboard, or contact us to correct other details.
If you do not have an account, or need help, use the contact form. Requests are handled by a site administrator and answered within 30 days.
Changes#
We may update this policy as the site evolves. The date at the top of this page reflects the latest revision.