Privacy · updated August 2026

What this site knows about you.

Short version: no cookies, no third-party trackers, no advertising pixels, and your IP address is never stored. The site keeps a modest first-party visit log — which pages were read, from which network — because I'm curious who finds this useful. Here is exactly what that means.

What is recorded

When you load a page, the site records: the page address, the referring site (if your browser sends one), a timestamp, your approximate location (country and city, derived from your IP address), and the name of the network your connection belongs to — for an office connection that is typically an employer's name; for a home or mobile connection it is an internet provider such as Telia or Vodafone.

Your IP address is used transiently, server-side, to derive the network name and location — and is then discarded. It is not written to any database. To count repeat visits within a single day without identifying anyone, the server keeps a pseudonymous code (a salted cryptographic hash) that changes every day and cannot be traced back to you or linked across days.

What is deliberately absent

No cookies. Nothing stored on your device. No fingerprinting. No third-party analytics or advertising scripts — nothing on this site talks to Google, Meta, or any data broker. That is also why there is no cookie banner: there is nothing to consent to under the ePrivacy rules, because the site neither stores nor reads anything on your machine.

If your browser sends a Do Not Track or Global Privacy Control signal, the site honours it: the visit is counted anonymously — page and date only, with no location or network lookup at all.

Retention

The detailed visit log is deleted automatically after 90 days. What survives longer is an aggregate that contains no personal data: organisation name, date, and pages read — enough to notice that, say, a given firm has come back three times, and nothing more. Consumer internet providers and automated traffic are excluded from that aggregate.

Legal basis and your rights

Processing rests on legitimate interest (GDPR Art. 6(1)(f)): understanding, at organisation level, who reads a professional site — the same basis used by standard B2B analytics tools, with considerably less data than most of them collect. Data is stored with Supabase in Stockholm (EU) and the site is served by Vercel.

You have the usual GDPR rights — access, rectification, erasure, objection. In practice the site holds nothing that identifies you as a person, so there is usually nothing to look up; but if you have any question or objection, write to me and I'll sort it out directly. Controller: Oscar Wallner, Stockholm, Sweden.