This is a personal technical blog. It collects as little as it can while still working, and nothing here is sold or shared with advertisers. Last updated 31 August 2026.
What is collected, and when
Reading the site
Nothing is stored about you until you interact with something. A session cookie is set so forms can carry a security token — it is strictly necessary, holds no personal data, and expires when your browser closes or after two hours.
Article view counts are recorded per article per day, de-duplicated using a one-way hash of your IP address and browser user agent. The hash cannot be reversed to an address, is used only to avoid counting the same reader twice in a day, and is discarded within 24 hours.
Analytics
No analytics provider is currently enabled. If one is added it will be a cookieless one, or it will be placed behind the consent banner.
If you create an account
An account stores the name, username, and email address you supply, a one-way hash of your password — never the password itself — and anything you choose to add to your profile. Profiles are public unless you mark yours private in your settings.
If you comment
Comments store the text, the account that wrote it, and a salted one-way hash of your IP address used only for abuse handling. The address itself is not kept. Comments are public.
If you use the contact form or subscribe
The contact form stores what you type and the address you give, so a reply can be sent. Newsletter subscription is double opt-in: the address is recorded immediately but nothing is sent to it until you confirm through the link, and every message carries a one-click unsubscribe.
The browser tools
Most of the utilities run entirely in your browser — whatever you paste into them is never transmitted. The handful that need network access are labelled Runs on the server on their own page, and for those the value you submit is sent to this server to perform the lookup. Nothing submitted to a browser-only tool is stored.
The server-side tools are different, and deliberately so. Because they make this server connect to a host you choose, anything done with them appears to the other end as coming from here. Each run is therefore logged with the host and address looked up, the port, your IP address, your account if you are signed in, and the time. That record exists so that a report of misuse can be answered accurately, and so that misuse can be noticed — it is not used for analytics, profiling, or anything else, and it is deleted after 90 days. These tools also carry a Cloudflare Turnstile check for the same reason.
Who else sees it
These are the only third parties involved:
- SMTP2GO — delivers outbound email. Sees the recipient address and message.
- Cloudflare — DNS, and the Turnstile anti-spam widget on forms where it is enabled.
The site runs on hardware operated by Everett Kildare rather than a third-party host, so no additional hosting provider has access to the database.
How long things are kept
- Session cookies — two hours, or until the browser closes.
- View-count de-duplication hashes — 24 hours.
- Server-side tool logs, including the requesting IP address — 90 days.
- Accounts, comments, and subscriptions — until you ask for them to be removed.
- Contact messages — kept while they are useful, then deleted.
Your rights
You can ask for a copy of what is held about you, ask for it to be corrected, or ask for it to be deleted, and it will be actioned rather than argued with. Account holders can edit or delete most of it directly from account settings. For anything else, use the contact form or email blog@everettkildare.com.
Unsubscribing from the newsletter needs no account and no explanation — the link is in the footer of every message.
Changes
If this page changes in a way that affects what is collected, the date at the top changes with it. There is no mailing list for policy updates and you will not be asked to re-accept anything unnecessarily.