Last updated: 31 August 2026


TL;DR

No tracking cookies, no advertising or cross-site trackers, no accounts, no ads. The only data processing is privacy-friendly, cookieless analytics, plus privacy-friendly web performance metrics and the technical delivery of pages through Cloudflare.


Data controller

The data controller is bytesdust, reachable at hello [at] bytesdust [dot] com .

This is a personal, non-commercial blog. No data protection officer (DPO) has been appointed, as none is required under art. 37 GDPR given the nature, scope and purposes of the processing.


What this site does NOT do

  • No tracking or profiling cookies — neither first-party nor third-party.
  • No consent banner — it is not needed, because nothing non-essential is stored on or read from your device (see “Cookies and local storage” below for the complete, technical list).
  • No advertising, no profiling, no cross-site tracking.
  • No user accounts, no newsletters, no comment systems.
  • No social media embeds.
  • No sale of personal data, and no disclosure of personal data to third parties for their own purposes.

Analytics (Umami, self-hosted)

I collect aggregate visit statistics using Umami , an open-source, privacy-focused analytics tool that I host myself.

  • What is collected: pages viewed, referring site, approximate geographic origin (country level), browser, operating system and device type. I also record custom events — simple counters such as clicks on outbound links, theme toggles, code-copy clicks and easter-egg discoveries; they carry no directly identifying data.
  • How your IP address is handled: your IP address is processed transiently, in memory, together with your user agent and a rotating server-side salt, in order to derive a hashed visitor identifier. The IP address itself is never stored, logged or retained — neither by Umami nor in the analytics database. The resulting identifier rotates and cannot be used to recognise you across sites, nor across days.
  • Nature of the data: the resulting measurement is pseudonymous and non-identifiable in practice.
  • What is NOT collected: stored IP addresses, cookies, device fingerprints, or any identifier that persists across sessions or across sites.
  • Legal basis: legitimate interest (art. 6(1)(f) GDPR).
  • Legitimate Interest Assessment (LIA): the processing is strictly limited to aggregate statistical data. The measurement is cookieless and does not access or store information on your device. The data is not used for profiling, advertising, or automated decision-making. Your interests are not overridden because: (a) no directly identifying data is retained, (b) no cross-site or cross-session tracking occurs, (c) you suffer no adverse effect or differential treatment, and (d) the purpose — understanding which content is read — is proportionate to the minimal intrusion involved.
  • Retention: raw event data is retained for 24 months; after this period it is either deleted or irreversibly aggregated into non-identifiable statistics. Aggregate statistics may be kept indefinitely, as they contain no personal data.

Oracle Cloud

Certain website funcionalities run on Oracle Cloud Infrastructure, in an EU region.

  • Role: Oracle acts as a data processor under art. 28 GDPR, under Oracle’s Data Processing Agreement for Oracle Cloud Services.
  • Location of storage: European Union.
  • Legal basis: legitimate interest (art. 6(1)(f) GDPR) — operating the analytics service.

Web performance metrics (Cloudflare Web Analytics)

To monitor page-load performance (Core Web Vitals and similar) I use Cloudflare Web Analytics (Real User Monitoring), which loads a small beacon script from Cloudflare.

  • What is collected: page views, page-load timing and performance metrics, browser and device type, country. It is explicitly designed to be privacy-friendly: no cookies, no local storage, no fingerprinting, no cross-site or cross-session tracking (Cloudflare's documentation ).
  • Who processes it: Cloudflare, Inc. as data processor under art. 28 GDPR, under a Data Processing Addendum (DPA).
  • Legal basis: legitimate interest (art. 6(1)(f) GDPR) — keeping the site fast and reliable, without identifying you.
  • LIA: the processing is limited to technical performance metrics and no identifying data is collected.

Hosting and content delivery (Cloudflare)

The site is a static website served through Cloudflare. When your browser requests a page, Cloudflare necessarily processes your IP address and connection metadata to deliver the content and to protect the service (for example against abuse and denial-of-service attacks).

  • Role: Cloudflare acts as a data processor under art. 28 GDPR, covered by its Data Processing Addendum .
  • International transfers: Cloudflare, Inc. is a US company. Transfers rely primarily on the EU-US Data Privacy Framework adequacy decision (art. 45 GDPR), for which Cloudflare is certified. Standard Contractual Clauses, Module Two (Controller to Processor) are incorporated in Cloudflare’s DPA and apply as a fallback mechanism under art. 46 GDPR.
  • Where cookie data is processed: by default, Cloudflare may process cookie data in its data centres in the United States. Cloudflare’s regional data-localisation options are not enabled on this Site.
  • Legal basis: legitimate interest (art. 6(1)(f) GDPR) — secure and efficient delivery of the website.
  • Cloudflare Ray ID: Cloudflare assigns a unique, ephemeral Ray ID to each HTTP request for operational troubleshooting (for example diagnosing delivery issues or abuse). This identifier is technical, is not linked to your identity, and is retained by Cloudflare according to their data retention policies .

Contacting me

If you email me, I process your email address and the content of your message solely to read and reply (art. 6(1)(f) GDPR). Emails are not used for marketing and are not shared.

Correspondence is retained for up to 24 months from the last message, unless a longer period is necessary to establish, exercise or defend a legal claim. You can ask me to delete our correspondence at any time.


Cookies and local storage

First-party storage

This Site sets no first-party cookies. The only browser storage used is strictly technical and never leaves your device:

NameTypePurposeDurationTransmitted?
themelocalStorageremembers your light/dark preferenceuntil you clear site dataNever
menu-scrolllocalStorageremembers menu scroll positionuntil you clear site dataNever
session-gatesessionStoragerecords that a security challenge has already been passed, so it is not shown again during the same browsing sessionuntil the tab is closedNever

None of the above is transmitted to me or to anyone else: these values are written and read entirely by your browser.

Why no consent is required. Access to and storage of this information falls within the strictly-necessary exemption of art. 122 of the Italian Privacy Code and art. 5(3) of the ePrivacy Directive: theme stores a user-interface preference that you set yourself by an explicit action; menu-scroll preserves interface state within your navigation; session-gate is required to deliver the security functionality of the Site. None of them contains an identifier usable for profiling, and none is transmitted anywhere.

Third-party technical cookies (Cloudflare)

Cloudflare’s edge may set short-lived, non-tracking cookies required to deliver and protect the service. The following is based on Cloudflare's official cookie documentation :

NameSet byPurposeDurationCategory
__cf_bmCloudflarebot management: contains information used to calculate Cloudflare’s bot score; its contents are encrypted and readable only by Cloudflare, and a separate cookie is generated per siteexpires after 30 minutes of continuous inactivityStrictly necessary
cf_clearanceCloudflarestores the proof that a security challenge was passed, so that the challenge is not issued again; required to reach the origin serveras configured by the Challenge Passage settingStrictly necessary
cf_chl_rc_i, cf_chl_rc_ni, cf_chl_rc_mCloudflareChallenge Platform internal cookies, used by Cloudflare to identify production issues on clientssessionStrictly necessary
cf_ob_infoCloudflarerecords the HTTP status code returned by the origin, the Ray ID of the failed request and the data centre serving the traffic (Always Online)30 secondsStrictly necessary
cf_use_obCloudflaretells Cloudflare to fetch the requested resource from the Always Online cache on the designated port30 secondsStrictly necessary

cf_clearance is set with the SameSite=None; Secure; Partitioned attributes, so that challenge state is partitioned by top-level site and is not shared across embedding sites.

All of the above fall under the strictly-necessary exemption of art. 122 of the Italian Privacy Code / art. 5(3) of the ePrivacy Directive: they are required to deliver and protect the service you requested, they carry no identifier usable for profiling, and Cloudflare does not use them to track users from site to site or from session to session.

Because there are no non-essential cookies, there is no cookie banner and nothing to accept or refuse.


Automated decision-making

No automated decision-making or profiling within the meaning of art. 22 GDPR takes place on this Site. Nothing you read here produces legal effects concerning you or similarly significantly affects you.

Cloudflare’s bot-detection systems may automatically present a security challenge to requests that appear automated. This is a technical security measure applied to the request, not a decision about you as a person; if you are ever blocked in error, contact me and I will look into it.


Your rights

Under arts. 15–22 GDPR you have the right to access, rectify, erase, restrict or object to the processing of your personal data, and to data portability.

What this means in practice: this Site processes essentially no identifiable personal data, so in most cases there is very little to exercise these rights against. Nonetheless, you can contact me and I will:

  • confirm whether any data relating to you is being processed;
  • provide a copy if any processing exists;
  • delete any correspondence or identifiable data on request.

Right to object (art. 21 GDPR). Because the analytics and delivery processing described above relies on legitimate interest, you may object to it at any time by writing to hello [at] bytesdust [dot] com . Note that the analytics measurement is pseudonymous and cookieless, so there is no per-user identifier I could use to selectively exclude you; in practice an objection will be handled by confirming what is processed and, where technically possible, removing the relevant records. You can also block the analytics endpoint and the Cloudflare beacon in your browser or via a content blocker, which prevents the measurement entirely.

I will reply without undue delay and in any case within one month of receiving your request. Where a request is particularly complex, that period may be extended by two further months, in which case I will inform you within the first month (art. 12.3 GDPR).

You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali .


Information for California residents (CCPA/CPRA)

The California Consumer Privacy Act (CCPA), as amended by the CPRA, does not apply to this Site: it is a personal, non-commercial project and does not meet the definition of a “business” under Cal. Civ. Code § 1798.140, as none of the applicable revenue or volume thresholds are met.

As a courtesy, and for the avoidance of doubt:

  • This Site does not sell personal information.
  • This Site does not share personal information for cross-context behavioral advertising.
  • This Site does not process sensitive personal information beyond what is technically necessary to deliver the pages.

Changes to this policy

If the stack changes (for example, new third-party services), this page will be updated before the change goes live. The “last updated” date at the top always reflects the current version. Material changes will be announced via a notice on the Site for at least 30 days.