Privacy
How we handle your data.
A short, honest note about what we collect when you visit this site — and what we don't.
Last updated · 29 May 2026
What we collect
Each time you load a page we record one row: the path you visited (e.g. /work), the root domain that referred you (e.g. google.com — never the full URL, and never an internal link from this site), your browser's reported language, a coarse device class (mobile / tablet / desktop), your browser and operating-system family, any utm_source / utm_medium / utm_campaign in the address, and your country as a two-letter code. We also store a short fingerprint computed from your IP address and browser, hashed with a daily-rotating secret salt, which lets us count unique visitors within a day and group a visit's pages together, but cannot link visits across days or back to a specific person. Your IP address itself is not stored at this level — it is used to derive the country code and the daily fingerprint, then discarded.
With your consent
If you accept on the banner, we additionally store your IP address and your exact screen dimensions on each row. These do identify you, which is why they are never recorded unless you say yes — the server discards them otherwise, whatever your browser sends. You can decline with one click, declining is as easy as accepting, and if your browser sends a Do Not Track header nothing is sent at all and you are never asked. The lawful basis for this tier is your consent (GDPR Article 6(1)(a)); everything in the section above rests on legitimate interest instead.
What we don't
We set no cookies. The only thing we keep in your browser is a single localStorage entry recording whether you accepted or declined analytics, so we do not ask again on every page — nothing else, and no identifier. We embed no third-party scripts, no social-share widgets, no advertising, no profiling. We do not record what you type into form fields beyond what you submit. We do not track you across other sites. If your browser sends a Do Not Track header, the tracker doesn't fire at all.
Why
To know roughly how many people find the site, which pages they read, and where they come from. That's the only purpose — there is no advertising or monetisation tied to this data. The lawful basis is our legitimate interest in understanding usage of our own site (GDPR Article 6(1)(f)); the daily salt rotation and lack of cross-day correlation keep the impact on you minimal.
How long we keep it
The identifying data you consented to — your IP address and screen dimensions — is erased seven days after the visit. What remains identifies nobody, and the whole row is deleted 400 days after the visit. Both run automatically, several times a day. Contact-form submissions are kept for as long as the conversation they started is active, then archived for our records.
Who sees it
Only us. The data lives in a Postgres database on our own server, never sent to a third party for analytics. The server logs (nginx, application) are accessible to the technical team for operating the platform — same legal basis, same retention plan.
Your rights
You can ask for a copy of the data we hold about you, or for its deletion. Email haloceteki@hotmail.com. Realistically: unless you consented to IP logging within the last seven days, the fingerprint rotates daily and isn't reversibly linked to you, so we may not be able to identify which rows belong to your visits — but we'll do our best with whatever identifier you can provide (the IP you used, the approximate time of your visit, etc.).
Contact form
When you submit the contact form, we collect your name, email, optional company, and message. We use this to reply to you, and only to reply to you. The email lands in our inbox via our own mail relay — no third-party transactional-mail provider has the content. We don't sign you up for anything.
Bot protection
The contact form is protected by Cloudflare Turnstile, which runs a brief invisible challenge to filter out automated submissions. Turnstile sets a short-lived storage token in your browser for that purpose, which Cloudflare classes as strictly-necessary anti-abuse technology and not subject to consent. Cloudflare publishes its own privacy notice at cloudflare.com/privacypolicy.
Invite requests
If you use the self-service form at auth.haloceteki.eu/Request to ask for an invite, we collect your email, your name (if you provided one), the app you requested access to, and your message. We also store your IP and user-agent briefly — both are cleared as soon as the request is decided. The confirmation link we send you contains a token stored only as a SHA-256 hash; the live token is sent in the email and never written to disk. Declined requests are kept for 30 days as anti-abuse history, approved requests link to the resulting invite code, and spam-marked requests are deleted after 90 days.
Changes to this notice
If we change how we handle data, we'll update this page and note the change in the date at the top. There's no separate notification — checking back here from time to time is on you.