Skip to content

Privacy

This site is built privacy-first. It sets no cookies, runs cookieless analytics, and stores nothing on your device except a single functional theme preference. Because nothing here tracks or profiles you, there is no consent banner. Any data exists only so I can see which writing, talks and projects are useful — never to identify you.

This notice covers the whole site, including community features (comments, reactions, newsletter) that are rolling out under the site’s engagement plan; each section is updated as a feature goes live.

Who is responsible, and how to reach me

This is a personal site operated by Rodrigo Sicarelli (São Paulo, Brazil). For any privacy question or to exercise your data rights, email [email protected]. As a small-scale individual operator, no formal Data Protection Officer (DPO) is appointed; this email is the communication channel required by LGPD Art. 41 §1.

What’s measured (analytics)

Only aggregate, anonymous signals:

  • Page views and visitor counts per page.
  • Per-post view counts, tallied first-party in our own database. A reader is de-duplicated with a daily-rotating salted hash of IP + browser — the raw IP is never stored, there are no cookies and no client-side storage, and no number is shown on the page.
  • A few interaction events — material downloads, outbound link clicks, and talk-video plays — counted as totals, never tied to a person.
  • Approximate, coarse location (country) and referrer, derived without storing your IP address.

Storage on your device

  • A theme value in localStorage that remembers your light/dark preference. It is functional, not tracking — strictly necessary for a setting you asked for — and is read before paint to avoid a flash of the wrong theme. It is never sent anywhere.
  • Nothing else: no cookies and no other localStorage for tracking, before or after you interact.

Third parties

ServicePurposeData & privacy posture
Cloudflarehosting / CDN + Web Analyticscookieless edge measurement; no client storage, no fingerprinting
Umamiopen-source, cookieless analyticsdaily-rotating salted hash of IP + user-agent; the IP is never stored

Community features (rolling out)

These are part of the site’s engagement plan and are documented here as each one launches:

  • Comments — Giscus (GitHub Discussions). When enabled, signing in to comment is handled by GitHub; comments live in this site’s GitHub Discussions and are subject to GitHub’s privacy policy. Giscus sets no cookies on this domain — only an encrypted token in localStorage after you sign in. You can delete your own comments on GitHub at any time.
  • Anti-spam — Cloudflare Turnstile. Protects forms (e.g. newsletter) from abuse. In its default mode it sets no cookies and does no cross-site tracking; it issues a one-time token validated server-side.
  • Newsletter — Buttondown. Opt-in only, with double opt-in (your address only joins the list after you click the confirmation email). The signup form is our own — it posts your email to Buttondown through a server-side API call, so there is no third-party JavaScript or cookie on this site. Your email is stored at Buttondown solely to send the newsletter; you can unsubscribe from any email, and it is never shared or sold.
  • Reactions — anonymous, first-party. The emoji reactions on a post are anonymous and stored only as per-post totals in our own database. A reaction is de-duplicated with the same daily-rotating salted hash of IP + browser used for view counts — the raw IP is never stored, and there are no cookies and no client-side storage.

If any of these introduces device storage beyond the functional theme key, this page is updated before it ships.

  • Aggregate analytics: legitimate interest (LGPD Art. 7 IX / GDPR Art. 6(1)(f)) — measuring audience without identifying anyone.
  • Functional theme storage: strictly necessary for a service you requested.
  • Newsletter / comments: your consent (you opt in); withdrawable at any time.

Retention and data minimization

  • Analytics are stored only as aggregates; the daily analytics salt is rotated and deleted every 24 hours, so visits can’t be linked across days.
  • Raw IP addresses are not logged long-term.
  • Where an avatar is ever shown from an email, only a hashed form of the email is stored, never the raw address.

Your rights

The site is operated from Brazil, so Brazil’s LGPD always applies; if you’re in the EU/UK, the GDPR / UK GDPR gives you the same core rights. Under LGPD Art. 18 and GDPR Arts. 15–20 you can request access, correction, deletion, portability, and objection to processing of your personal data. Email [email protected] and I’ll respond within the legal window (about 15 days under the LGPD; 30 days under the GDPR). For comments stored in GitHub Discussions, you can also delete them directly via your GitHub account.

Because the analytics here are genuinely anonymous and cookieless, and the only device storage is the functional theme preference, no consent banner is required:

  • Brazil (LGPD): anonymized data falls outside the law’s definition of personal data (Art. 12). The ANPD’s Guia Orientativo sobre Cookies recognises aggregate audience measurement as a legitimate interest (Art. 7 IX), and cookieless tools sidestep the cookie question entirely.
  • EU/UK (GDPR & ePrivacy/PECR): storing no non-essential information on your device and processing no personal data means there is no cookie or consent obligation to satisfy.

If this ever changes — for example, if paid content later needs account-based analytics — this page will be updated first, and any consent mechanism added before such tracking begins.

Last updated: 2026-06.