Privacy

This page explains what happens to your data when you visit this site, use the Rooms, or contact me. I run the site and I am responsible for that processing.

This site sets no cookies

Not for analytics, not for sessions, not for anything. The fonts are served from this domain, not from Google. The animation library is bundled into the site’s own JavaScript, not loaded from a CDN. Apart from Vercel, which hosts the site, no third party is contacted when you load a page.

What your browser keeps

The site stores three things in your browser’s local storage: your conversation in each Room, your question count and whether you have reached the daily limit, and your analytics choice. These stay until you clear them.

When you send a question, up to twelve recent messages from that Room’s saved conversation go with it, so the answer has context. Nothing else in local storage is sent anywhere.

What happens when you ask a question

Your question, with that recent history, goes to the site’s server. If the answer needs the model, the same content goes to OpenAI.

Three kinds of record are then written to a database I run on Supabase, in Frankfurt, Germany.

Your question. Stored to see what people ask and where the site’s answers fall short. The record is the question text, the Room, which answer path handled it, and the time. It holds no name, no IP address, no session identifier, and no link to your other questions. The one way it becomes identifying is if you include identifying details yourself, so don’t put sensitive personal information in a question. My replies are not stored.

Request metrics. Room, answer path, model, token counts, cost, response time, and whether the request failed. No text. These monitor performance and keep the site inside a fixed monthly budget.

A rate-limit record. Your IP address is run through HMAC-SHA256 with a secret key and the result is stored against the day, to enforce a limit of 30 questions per day. The raw address is never written; no table has a column for it.

Who receives data

Vercel hosts the site and runs its server functions. Like any host, it processes your IP address and connection details to serve pages. Its analytics, if you allow them, are described below. The server functions run in Vercel’s Frankfurt region, but Vercel is a US company; transfers to it rely on its certification under the EU–US Data Privacy Framework.

OpenAI generates the answers. It receives your question and up to twelve prior turns — no IP, no headers, no identifiers. My agreement is with OpenAI Ireland Limited, and requests are processed in the United States; transfers within the OpenAI group rely on the European Commission’s standard contractual clauses or an adequacy decision. OpenAI states that API data is not used to train its models, and that it keeps API inputs and outputs for up to 30 days for abuse monitoring — longer only where the law requires it or where it is necessary to protect the service.

Supabase stores the database, on infrastructure in Frankfurt, Germany. Supabase Pte. Ltd is a Singapore company, and its affiliates — including Supabase, Inc. in the United States — may access the data remotely to provide support and keep the service running. Those transfers rely on the standard contractual clauses in Supabase’s data processing agreement. Its own sub-processors are listed here.

That is the full list. No advertising networks, no data brokers. Email me if you want copies of the transfer safeguards named above.

Analytics, only with your consent

Vercel Web Analytics and Speed Insights measure page views and loading performance. They set no cookies and build no profile. They stay off unless you choose Allow on the banner, and declining changes nothing about how the site works.

You can change your choice here at any time. It takes effect immediately and does not affect processing that already happened.

Why I process this

The Rooms, the rate limit, the cost metrics, and the question log rest on legitimate interest (GDPR Article 6(1)(f)): running a site I can afford, keeping it from being abused, and improving what it says. I weighed that against your interests — the question log carries no identifier, it is deleted after 90 days, and this page tells you before you type.

Analytics rest on your consent (Article 6(1)(a)).

How long I keep it

Questions are scheduled for deletion 90 days after they are written, by a nightly job.

Request metrics contain no personal data and are kept.

Rate-limit records are deleted after two days, by a second nightly job. The limit runs per day, so once a day is over its record cannot affect anything.

What is in your browser stays until you clear it. Vercel and OpenAI keep their own logs under their own retention terms.

Your rights

You can ask for access to your data, correction, deletion, or restriction, and you can object to processing based on legitimate interest. Portability under Article 20 applies only to data processed on the basis of consent or contract, which here means it does not reach the question log.

Email me at the address below. I will answer within one month, extendable where the law permits.

One limit: question records carry no identifier, so I usually cannot tell which are yours (Article 11). If you can give me enough to locate a record — the Room and roughly when — I will act on it.

You have the right to lodge a complaint with a data protection authority, including the Dutch Autoriteit Persoonsgegevens.

About the Rooms

You are talking to a language model working from material I wrote about my own career. It answers in my voice, it can be wrong, and it is not a way to message me. Nothing you write in a Room reaches me directly.

The Rooms make no decision about you with legal or similarly significant effect.

Contact

Arakou Khader — arakou.khader@getcqi.com