Privacy policy

Last updated: September 13th, 2026

What data do I collect?

By default

  • I do not store, share, or sell your data.
  • Service logs are disabled. All public services have their logging capabilities disabled.
  • Webserver requests are not logged to disk. To investigate active abuse or diagnose a technical problem, webserver logs may be enabled temporarily and only for the affected service. While enabled, it may capture request data such as IP address, user agent, and requested URL. Logging is disabled as soon as the incident is resolved. Any logs collected during the incident are deleted immediately afterward and are never retained beyond the duration of the incident.
  • Webserver requests are kept in RAM for a maximum of 60 seconds. Request data such as IP address, user agent and path (but not the hostname or query string) is processed locally by Crowdsec WAF and is never written to disk. Normal requests that do not match any of Crowdsec’s rules are typically discarded from RAM within seconds.
  • I do not use any analytics, tracking, or browser fingerprinting
  • Cloudflare reverse proxy is disabled
  • All services are self-hosted on Oracle Cloud Infrastructure in the Netherlands, unless mentioned otherwise below. Network/BGP infrastructure does not process or proxy user requests.

All services follow this policy. Any exceptions are listed below.

Service-specific exceptions

redlib and nitter;
Cloudflare reverse proxy is enabled to protect against increased bot activity and abuse.

statuspage;
Selfhosted on a VPS in Germany.


How your data is processed

I use the following open-source security tools to protect my infrastructure from abuse and bots. Both process data entirely on my servers.

  • Go-Away — A proof-of-work challenge that runs in your browser. It uses several rules and signals to decide whether to allow, challenge or deny a request. No data is transmitted to third parties.

  • CrowdSec — Detects malicious traffic such as exploit attempts, scans, and brute-force attacks. All processing is done locally. When traffic is suspicious but not conclusively malicious, CrowdSec may present a captcha (a selfhosted Altcha widget) to verify you are human before allowing the request. Altcha is privacy-friendly and self-hosted on my server, it does not transmit any data to third parties. In cases of confirmed abuse, the offending IP address and user agent is reported to CrowdSec Cyber Threat Intelligence and AbuseIPDB to help other operators.


Third parties

  • All services are hosted on Oracle Cloud Infrastructure. Oracle Privacy Policy
  • The status page is hosted on BreadByte.cloud. BreadByte Privacy Policy
  • Cloudflare reverse proxy provides content delivery (CDN) and web application firewall (WAF) protection on subdomains where it is enabled. When active, Cloudflare may process and temporarily retain suspicious traffic, including IP address, user agent, and requested URL. Cloudflare Privacy Policy

Changes to this policy

This policy may be updated over time. Any change is reflected in the Last updated date above. Previous versions can be viewed via the Internet Archive.

Update September 13th, 2026: Crowdsec log processing in RAM
Update July 18th, 2026: Switched to Go-Away
Update July 17th, 2026: Cloudflare Turnstile has been replaced with the Altcha.org selfhosted captcha widget