Privacy

What this site collects, which is almost nothing: no cookies, cookieless analytics, and email you choose to send me. Written for the GDPR.

Published 6 min read

Short version: this site sets no cookies, shows no consent banner because there is nothing to consent to, runs analytics that do not identify you, and holds no data about you unless you email me.

The long version follows, because a privacy page that only says “we value your privacy” is worth nothing.

Who the controller is

Mo RezaAli, a private individual, in Messina, Sicily, Italy. Email: [email protected]

This is a personal, non-commercial site. It is not operated by Yakkyo S.p.A. or by any other company, and there is no registered business behind it. See the imprint for publisher details. There is no Data Protection Officer, because Art. 37 GDPR does not require one here.

My full postal address is available on request to anyone exercising a data-subject right or a supervisory authority. I do not publish it, because publishing a private home address to defeat scrapers is a bad trade.

Cookies

This site sets none. No analytics cookie, no preference cookie, no session cookie, no advertising cookie. There is no login, no cart, and no personalisation.

That is also why there is no cookie banner. A banner would be theatre.

Cloudflare, which serves this site, may set security cookies at the network level as part of protecting the origin. Those are described in Cloudflare’s privacy policy and I do not read, receive, or have access to them.

Analytics

The site runs Cloudflare Web Analytics. Cloudflare’s own documentation for the product describes it as privacy-first and states that it does not collect or use visitors’ personal data.

Two properties matter here, both stated by Cloudflare rather than by me:

  • It is cookieless. Cloudflare’s announcement of the product says: “We don’t use any client-side state (like cookies or localStorage) for analytics purposes.”
  • It does not fingerprint. Cloudflare states in the same post that it does not track users over time via IP address, User Agent string, or other immutable attributes for analytics purposes, and describes fingerprinting as more intrusive than cookies because users cannot opt out of it.

What I see as a result is aggregate: page paths, counts of page views and visits, referrer domains, country, and broad browser and device categories. There is no per-visitor profile, no user ID, no cross-site tracking, and nothing I could use to work out that a particular person read a particular page.

Legal basis: legitimate interests, Art. 6(1)(f) GDPR. The interest is knowing which pages are read at all, using the least intrusive method I could find. If you disagree that this balance is correct, tell me and I will hear it out.

Google Analytics, and what happened to it

The version of this site that this build replaces loaded Google Analytics 4, property G-XMEW7KSTQD, on every page. I took it out when I rebuilt the site in August 2026. There is no GA4 property, no gtag call and no tag manager anywhere in this build’s templates or configuration, and none is coming back. The change is recorded in the changelog. If you met a cookie notice or a Google tag on this domain before then, that is what it was.

Server logs and hosting

The site is hosted on Cloudflare Pages. As with any web host, Cloudflare processes the technical data needed to deliver a page to you: your IP address, the request URL, the time, and your User Agent string. Cloudflare acts as my processor for this, under its published terms, and its handling is described in Cloudflare’s privacy policy. Cloudflare is a US company operating a global network, so this processing can take place outside the EEA under the safeguards Cloudflare publishes. I have not negotiated bespoke terms with them; I use their standard ones.

I do not have a raw-log pipeline of my own and I do not store, export, or analyse server logs.

Legal basis: legitimate interests, Art. 6(1)(f) GDPR. The interest is serving and securing the site.

Third-party requests

Fonts are served from this domain, not from a font CDN. There are no embedded videos, no social widgets, no comment system, no chat widget, no advertising network, and no tag manager. The Cloudflare Web Analytics beacon is the only third-party request the site makes.

Email

If you email [email protected], I receive whatever you send: your address, your name if you sign it, and the content of the message. I use it to reply to you and for nothing else.

  • I do not add anyone to a mailing list. There is no mailing list.
  • I do not pass your address to anyone.
  • I do not use your message to train anything.
  • If you send me a correction, I may publish the substance of the error on the corrections page. I will not publish your name or your address unless you ask me to be credited.

Legal basis: legitimate interests, Art. 6(1)(f) GDPR. The interest is answering correspondence you started.

Retention: correspondence stays in my mailbox while it is useful and I delete what I no longer need. I do not run an automated retention schedule and I am not going to pretend I do. Ask me to delete a thread and I will delete it.

No profiling, no automated decisions

There is no profiling and no automated decision-making of any kind on this site, so Art. 22 GDPR does not bite. Nothing here scores you, segments you, or changes what it shows you based on who you are. Every visitor gets the same static files.

Your rights

Under the GDPR you have these rights over personal data I hold. Given the above, in practice that means email correspondence.

Table 1
RightArticle
Access (a copy of what I hold about you)Art. 15
Rectification (correct what is wrong)Art. 16
Erasure (delete it)Art. 17
Restriction of processingArt. 18
Notification of rectification or erasureArt. 19
Portability (get it in a machine-readable form)Art. 20
Objection (including to processing based on legitimate interests)Art. 21
Not to be subject to automated decision-makingArt. 22

To use any of them, email me. There is no form and no identity-verification hoop. If you are writing from the address you corresponded with, that is enough. I will answer within one month, which is the deadline Art. 12(3) GDPR sets.

Complaints

If I get this wrong, you can complain to the Italian supervisory authority, the Garante per la protezione dei dati personali, or to the authority in your own EU country. That right is Art. 77 GDPR and you do not need my permission or my cooperation to use it.

I would rather you emailed me first, but that is a preference, not a condition.

Changes to this page

Material changes are dated in the changelog. I do not rewrite this page silently.

Last reviewed 5 August 2026.

Sources

Every source below was opened and checked on the date shown. Links open in this tab.

  1. Regulation (EU) 2016/679 (General Data Protection Regulation) EUR-Lex, Publications Office of the European Union eur-lex.europa.eu Accessed 5 August 2026
  2. Art. 6 GDPR – Lawfulness of processing gdpr-info.eu gdpr-info.eu Accessed 5 August 2026
  3. Art. 15 GDPR – Right of access by the data subject gdpr-info.eu gdpr-info.eu Accessed 5 August 2026
  4. Art. 77 GDPR – Right to lodge a complaint with a supervisory authority gdpr-info.eu gdpr-info.eu Accessed 5 August 2026
  5. Cloudflare's privacy-first Web Analytics is now available for everyone The Cloudflare Blog blog.cloudflare.com Accessed 5 August 2026
  6. Cloudflare Web Analytics: About Cloudflare Docs developers.cloudflare.com Accessed 5 August 2026
  7. Cloudflare's Privacy Policy Cloudflare, Inc. www.cloudflare.com Accessed 5 August 2026
  8. Garante per la protezione dei dati personali Garante per la protezione dei dati personali www.garanteprivacy.it Accessed 5 August 2026