Skip to content

Privacy

How your data is handled on elvinlab.dev: analytics, contact form, hosting, local storage, and your rights.

Controller and contact

The data controller is Elvin González. You can exercise your rights and get in touch through the contact page.

Cloudflare Web Analytics

This site may use Cloudflare Web Analytics (opens in a new tab) to measure traffic in aggregate: page views, load times and Core Web Vitals. Query strings are not logged [source] (opens in a new tab). The details of the data Cloudflare collects are in its documentation (opens in a new tab). Cloudflare states that it does not track individual end users across its customers' Internet properties [source] (opens in a new tab). Processing relies on the legitimate interest of understanding site usage.

Contact form

Submitting the form sends your name, email address, message and submission time. The only purpose is to be able to reply to you. These providers are involved:

  • Resend: delivery of the notification email.
  • Cloudflare Turnstile: bot check (privacy policy (opens in a new tab)).
  • Cloudflare rate limiter, which uses the visitor IP to prevent abuse.

Messages are kept only as long as needed to answer them; no fixed retention periods are defined.

Comments (giscus)

Comments and reactions on notes are provided by giscus (opens in a new tab): when you scroll to that section, your browser connects to giscus.app to load it. They are stored as GitHub Discussions (opens in a new tab) in the public repository, so anyone can see them.

To comment or react you must authorize the giscus app through GitHub's OAuth flow. According to its privacy policy (opens in a new tab), giscus keeps a server-encrypted token in your browser's localStorage to keep you signed in, and does not collect data on its own. GitHub's handling is covered by its privacy statement (opens in a new tab).

Footprints on notes

Each note and the home page have a button to leave a footprint (an anonymous “I was here”). When you press it, your browser sends this site the note identifier (or the home page one) and how many footprints you left. That number is added to a per-note and per-page counter kept in a Cloudflare D1 database, the same provider that hosts the site. The counter does not record who added to it: your IP address and any other personal data are not stored.

To limit abuse, this site uses Cloudflare’s request rate limiter, which counts requests per IP address at the time of each request; the IP address is used only for that limit and this site does not store it.

Your browser keeps, in localStorage under the key marks:<note>, how many footprints you left on each note and on the home page; it is used to respect the per-person cap and is not sent as an identifier.

Email subscription

If you subscribe, I keep your email to send you new notes and, now and then, a heads-up about one of my projects. Nothing else: I never share or sell it.

What I keep. Your email, the language of the page where you signed up, whether you confirmed or unsubscribed, and the dates of those steps. I also keep which notes I already sent you, only so I never send you the same one twice. Until you confirm, it is stored with a fingerprint of the confirmation link, and I delete it after 7 days.

How it works. I write to you first so you can confirm: this way nobody can sign your address up without you knowing. Every email carries a one-click unsubscribe link, with no account and no questions.

Who is involved. Cloudflare stores the list and Resend delivers the emails, both only as technical support. Turnstile checks that you are a person; I do not store your IP.

If you unsubscribe, I keep your address marked as “unsubscribed” so I never email you by mistake. If you would rather have it deleted completely, ask through the contact page and I will remove it.

Hosting and logs

The site runs on Cloudflare Workers with request logging enabled for observability (latency, errors and status codes).

Local storage

This site only keeps five interface preferences in localStorage: the theme, the background effect you pick, whether the banner is expanded, the language hint dismissal, and whether you turned on reading mode. They are not used to identify you or for tracking. If you leave footprints on a note, localStorage also keeps how many you left on that note (marks:<note>), only to respect the per-person cap.

Cookies

This site's own code does not set cookies. The third-party services loaded on some pages (those in the analytics, contact form and comments sections) have their own policies, linked above, and those policies determine whether they use cookies or other storage.

Your rights

You can exercise your rights of access, rectification, erasure and objection through the contact page. Requests are answered within the timeframes required by applicable law.