Learn how we collect, use, and protect your personal data when you visit our website.
Last updated: 18 August 2026
This Privacy Policy explains how Cristian Di Carlo ("I", "me") processes limited information when you visit this website or access its private content management system.
For questions regarding privacy or the processing of your data, contact:
Cristian Di Carlo
okazakee@proton.me
This website is hosted on Vercel.
As part of normal website delivery, security and infrastructure operation, Vercel may process technical request information such as IP addresses, browser and device information, request URLs, timestamps and other HTTP metadata.
This data is processed according to Vercel's own infrastructure, privacy and data-processing policies.
Vercel Speed Insights is used to monitor website performance and Core Web Vitals.
Performance monitoring may include technical metrics related to page loading, browser, device and network conditions. It is used only to understand and improve the technical performance of the website.
This website uses a self-hosted instance of Umami for privacy-focused analytics.
Umami does not use tracking cookies or cross-site tracking. It records information such as page views, referrer URLs, browser, operating system, device type and approximate geographic information.
The visitor's IP address may be used transiently to derive anonymous session or location information, but the IP address itself is not stored as an analytics record.
The analytics instance is self-hosted and the collected analytics data remains under my control.
Access to the CMS is restricted to explicitly authorized users. Public self-registration is disabled.
Depending on the authentication method, the following information may be processed:
Passwords are handled by Supabase authentication and are not stored by this website in plain text.
When GitHub OAuth is used, the CMS may receive:
GitHub processes the OAuth authentication request according to its own privacy policy.
The CMS maintains an internal allowlist used exclusively for access control.
An allowlist record may contain:
The allowlist is not publicly accessible and is used only by trusted server-side authorization logic.
To protect the CMS login system from automated abuse, rate limiting is applied independently to the requesting IP address and login email.
Before persistence, both values are transformed into SHA-256 hashes. The raw IP address and raw email address are not stored in the rate-limiter database table.
The rate-limiter stores only the hashed identifier, attempt counters, timing information and temporary lockout state.
Successful authentication clears the corresponding rate-limit buckets. Stale rate-limit records are also subject to automated scheduled cleanup.
This information is used exclusively for authentication security and abuse prevention.
Two functional cookies are used to remember the selected appearance:
| Cookie | Purpose | Expiry |
|---|---|---|
themeMode | Stores the selected theme mode (light, dark or automatic) | 365 days |
resolvedTheme | Stores the resolved theme used during server-side rendering | 365 days |
These cookies are used only to remember a preference explicitly selected by the user.
When an authorized user logs into the CMS, Supabase authentication uses session cookies to maintain the authenticated session.
These cookies are used exclusively for authentication and session management and are not used for advertising or cross-site tracking.
Data is processed only where necessary for the following purposes:
| Processing | Purpose | Legal basis |
|---|---|---|
| Website infrastructure | Delivering, operating and securing the website | Legitimate interests, Art. 6(1)(f) GDPR |
| Performance monitoring | Diagnosing and improving website performance | Legitimate interests, Art. 6(1)(f) GDPR |
| Privacy-focused analytics | Understanding aggregate website usage | Legitimate interests, Art. 6(1)(f) GDPR |
| CMS authentication and access control | Operating and securing the private CMS | Legitimate interests, Art. 6(1)(f) GDPR |
| Login rate limiting | Preventing abuse and unauthorized access attempts | Legitimate interests, Art. 6(1)(f) GDPR |
Supabase provides database, storage and authentication infrastructure.
The Supabase project used by this website is deployed in the Central Europe (Zurich) region.
Switzerland is recognized by the European Commission as providing an adequate level of protection for personal data under Article 45 GDPR.
Supabase may also use subprocessors according to its own privacy policy and data-processing terms.
Vercel provides website hosting and performance infrastructure.
Vercel is based in the United States and may process information outside the EU/EEA. Where required, Vercel provides international data-transfer mechanisms including Standard Contractual Clauses.
GitHub processes authentication information when an authorized CMS user chooses GitHub OAuth.
GitHub's processing is governed by its own privacy policy and OAuth terms.
Website analytics are processed by a self-hosted Umami instance rather than a third-party analytics service.
Authorized CMS users may request or initiate removal of their CMS access.
The current account-removal flow removes the user's CMS allowlist entry and website profile and terminates the active session.
For requests concerning any remaining authentication or stored data, contact:
Under the GDPR, where applicable, you may have the right to:
To exercise any applicable right, contact:
This Privacy Policy may be updated when the website, CMS, infrastructure or data-processing practices change.
The latest version will always be published on this page.