Privacy

Datenschutz

Contents

Last updated: July 2026

The short version first: this website is a static blog. It sets no cookies, uses no trackers and no analytics services, embeds nothing from third-party servers, and never asks you to enter personal data. The only optional exception is push notifications — and those exist only if you explicitly enable them. What is processed technically when you visit is listed below, in full and without fine print.

Controller

Responsible for the data processing on this website is the person named in the legal notice. For any privacy question, an informal email to the address given there is enough.

No cookies, no tracking

This website sets no cookies, uses no local storage for tracking purposes, and embeds no analytics, advertising, or social media services. There is therefore no cookie banner — it would simply be pointless.

Fonts and other content

All content on this website — including the fonts (Inter, Bitter, JetBrains Mono) — is served locally from the same server. Merely visiting establishes no connection to Google Fonts, content delivery networks, or other third-party servers. Your IP address is thus disclosed to no one except the host named below. (For the one opt-in exception, see the Push notifications section.)

Hosting and server logs

This website is delivered via the content delivery network bunny.net, a service of BunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, Slovenia — a European company.

When the website is accessed, the host automatically processes the data your browser transmits for technical reasons, in particular:

  • IP address of the requesting device
  • date and time of access
  • page or file requested
  • browser type and version, operating system (user agent)
  • previously visited page (referrer), if your browser sends it

This data is technically necessary to deliver the website and additionally serves the stability and security of operation (such as defending against attacks and abuse). The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the secure and reliable operation of a website). No merging with other data and no evaluation for marketing purposes takes place on my part.

Delivery runs over a globally distributed network of servers; requests from Europe are regularly answered by a server within the EU. The only processor is the EU company named above — there is no contractual relationship with a provider in a third country. Details are in the bunny.net privacy policy.

Push notifications

On the Subscribe page you can enable browser notifications about new posts. This happens only through your explicit action: a click on the button plus your browser’s permission prompt. The legal basis is your consent (Art. 6(1)(a) GDPR); it can be withdrawn at any time with effect for the future — via the same button or your browser’s notification settings.

What is stored: When you enable it, your browser generates a technical push address (endpoint URL) together with two cryptographic keys. Only this data is stored on a server I operate myself (push.flooo.pro) — no name, no email address, no account, no link to other data. It is used solely to send the notifications.

Delivery path: Web push messages are, by design, delivered through the push service of your respective browser vendor (e.g. Google for Chrome, Mozilla for Firefox, Apple for Safari) — the push address points to their server, in some cases located in the USA depending on the vendor. The notification contents are end-to-end encrypted; the browser vendor cannot read them. Which push service your browser uses is determined by the browser alone, not by this website.

Deletion: When you disable notifications, the push address is deleted from my server. Addresses that have become invalid (e.g. after a browser is uninstalled) are removed automatically on the next send. No evaluation of whether or when notifications are opened takes place.

Contacting me

If you email me, I process the data you provide (email address, content of your message) solely to handle your request (Art. 6(1)(b) or (f) GDPR). The correspondence is deleted once it is no longer needed and no statutory retention obligations stand in the way.

Your rights

Under the GDPR you have the following rights:

  • Access to the data processed about you (Art. 15)
  • Rectification of inaccurate data (Art. 16)
  • Erasure (Art. 17) and restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Withdrawal of consent given (Art. 7(3)), e.g. for push notifications
  • Objection to processing based on legitimate interests (Art. 21)

If you believe that the processing of your data infringes data protection law, you can lodge a complaint with the Austrian data protection authority: Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb.gv.at.

Changes

Should anything change in the technical setup of the website (such as a comment system or a different host), this notice will be updated accordingly. The date at the top shows the current version.