$ cat privacy.md
Privacy Policy
This is a personal homepage. There is no account to create, nothing to buy, and one form, which only runs when you open it. What follows is all of it.
what is kept on your device
Two settings, and both of them are yours. Your theme choice is kept in local storage under tg-theme, and the background pause switch in session storage under tg-pause.
Neither is sent anywhere. Clearing site data removes both, and the page goes back to following your operating system.
There is no cookie on this site, for measurement or for anything else.
The measurement library described below is told to keep its working state in page memory, so it writes nothing here either.
what is measured
Arriving on a page is counted, and so is leaving it. Beyond that, four interactions are counted: following a link off this page, finding a hidden command, opening either in-page game, and sending the contact form.
The four interaction events are built by hand and stay small. Each carries the page path, a random identifier, and the time, and that path never includes the query string or the fragment.
The identifier is made in page memory and is gone when the tab closes. Finding a hidden command also sends which one it was, and a sent message sends which of the four topics it was filed under.
Nothing else rides on these four: no referrer, no device profile, nothing you typed at the prompt, and no word of a message you sent.
Page views and page leaves come from PostHog's own library instead. Those two carry what that library ships: the full page address including any query string, the referring page, and browser and screen details.
The same library may record a session replay: a reconstruction of what the page showed while you were on it. In every replay the prompt is blanked and all terminal text is starred out, so what you typed stays out of it.
Clicks and scrolling are also collected in aggregate, as a heat map of where a page gets used. And when a script here crashes, the error is reported so it can be fixed.
how the measurement is configured
No cookie is set and nothing is written to your browser. The measurement library keeps its working state in page memory only.
Because of that, the identifier it uses is made fresh on every page load and is gone when the tab closes. A reload looks like a new visitor, and so does the next page you open here.
IP addresses are discarded on arrival rather than stored, and every event is flagged so that no person profile is built from it.
Surveys are switched off, and the library never captures the text of the elements you click.
The project is hosted in the United States. Anonymisation rather than geography is what makes that proportionate for a visitor in the EU.
There is no advertising, no cross-site tracking, and nothing collected here is sold or shared for marketing.
do not track and global privacy control
If your browser signals Do Not Track or Global Privacy Control, no measurement code is installed at all.
That is not a filter applied afterwards. For those visitors nothing is ever wired up, and the measurement library is never even downloaded.
That refusal covers all of it: the counted events, the page views, the replays, the heat maps and the error reports.
security reports
The site ships a content security policy. When your browser blocks something that policy forbids, it reports the violation to the same analytics host.
The report names the page, the rule that fired, the blocked address, and the referring page if there is one.
Your browser sends every one of them. Roughly nine in ten are discarded on arrival rather than stored, but that happens at the far end and not on your device.
These reports are written by the browser, not by this page. Their addresses are the full ones, including any query string.
hosting
The pages are static files served by Vercel. Like any web server it records the requests it answers, under its own policy rather than this one.
writing to me
The contact form on the home page posts what you wrote to this site, and this site does three things with it.
It emails the whole message to me, with your address set as the reply-to, so answering you is one keystroke.
It appends one row to a private spreadsheet only I can open. That row holds the time, the topic, your name and address, the company and link if you gave them, the message, and the file names.
It records that a message arrived. That record carries the topic and whether the delivery worked, and no part of what you wrote.
Attachments ride along with the email and are not stored anywhere else. Nothing you type is kept in your browser, and closing the form without sending leaves nothing behind.
The mail goes through Resend and the spreadsheet is Google Sheets. Both are processors here, and both hold what is listed above and nothing more.
Ask me to delete a message and I will delete the mail and the row. There is no other copy.
who is responsible, and what you can ask
This site is run by Tomasz GORKA as a personal homepage. There is no company behind it, and no data protection officer, because there is no organisation to appoint one.
Events are held for up to a year by the analytics plan this site runs on, and then they go.
There is no account here, no mailing list, and no identifier that survives your visit. Beyond a message you chose to send, there is no file of yours to show you, to correct, or to delete.
If you think anything here is wrong, or you want to know more, the contact form reaches me. The profiles linked from the home page reach me too.
changes
This page is the current version. Any change is published here, and the date under the heading moves with it.