Legal

Privacy

This website is a set of static files. No cookies, no third-party embeds, and nothing you type. Here is what is left.

What this website collects

Nothing you type. There is no form on this site, no account, no newsletter, no comment box, no search box that reports back.

What remains is the request itself. To hand you a page, a server has to receive that request, and the request carries your IP address, the timestamp, the URL, the referrer and your browser's user agent. That is how HTTP works. It is not a tracking decision, and none of it is stored in a form we could look up later.

Hosting and content delivery

This website is hosted and delivered by Cloudflare, Inc. Cloudflare terminates the connection, serves the files from the location closest to you, and filters abusive traffic. Cloudflare acts as a processor on our behalf under Art. 28 GDPR.

Your IP address is processed in that step, because a packet cannot be routed back without it. Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in serving this website reliably and defending it against attacks. Cloudflare's network includes servers outside the EU, so a transfer to a third country can occur; it rests on the European Commission's standard contractual clauses.

Log data is used for operation and security only. It is not profiled, not enriched, not merged with anything and not sold.

Audience measurement (cookieless)

We measure how this site is used with clicktype Pulse, an analytics tool we built and run ourselves (VIICO GmbH, on our own Cloudflare infrastructure). Pulse sets no cookies and does not access anything stored on your device, so no consent under § 25 TDDDG is required and there is still no consent banner.

When you open a page we process: the page (its path), the time, the referring site (its host only, never the full address), the country, the device class (phone, tablet, desktop), the browser family, and a pseudonymous visitor identifier. That identifier is a shortened hash of IP address, user agent, date and domain. It changes every day, which makes recognising anyone beyond a single day technically impossible.The IP address itself and the full user agent are not stored and are not combined with any other data. We separately record access by automated systems — search engine and AI crawlers — based on how they identify themselves.

Two further signals are recorded on this site: that a visitor interacted with the page at all (a scroll, a click, a keystroke — that it happened, never what), which is how a person is told apart from a bot that runs a browser; and clicks on links leaving this domain, by host only. There are no forms here, so nothing form-related is measured. Nothing you type is transmitted.

Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in cookieless audience measurement and in recognising automated access. You may object at any time with effect for the future (Art. 21 GDPR). Retention: 14 months, then automatic deletion — enough to compare against the same stretch of the previous year, and no longer.

No cookies, no cross-site tracking

  • No cookies are set, not for measurement and not for "essential" purposes. The live demo is the one exception worth naming: it is the real application, so it remembers your theme and open tabs in your own browser's local storage. That never reaches us — the demo has no server.
  • No tag manager, no pixel, no session recording, no A/B tooling, no advertising network, and nothing that follows you to another website. The measurement described above stays on our own infrastructure and is not shared.
  • Fonts are served from this domain. Nothing is fetched from Google Fonts or any other font CDN.
  • No embedded videos, maps, chat widgets or social buttons. No third party sees your request.
  • Because there is nothing to consent to, there is no consent banner.

Links to other sites

Some links leave this domain: the source repository on GitHub, the container image on ghcr.io, the protocol specification. Following one of them puts you on that operator's infrastructure, under that operator's privacy policy. We have no influence there and hand over nothing beyond the referrer your own browser sends.

Your rights

Under the GDPR you can request access to your data (Art. 15), its rectification (Art. 16), its erasure (Art. 17) or a restriction of processing (Art. 18). You can request portability (Art. 20) and you can object to processing based on legitimate interest (Art. 21). You can also lodge a complaint with a supervisory authority (Art. 77), normally the one responsible for your place of residence.

One caveat, in your favour: we keep no data set that could be matched to you, so an access request about this website will usually come back empty.

Who to contact

The controller is the provider named in the imprint. Use the contact details listed there.

The salt.md software

This policy covers the website salt.md and nothing else.

If you run salt.md yourself, the instance is yours. You are the controller for everything inside it, and this policy does not apply to it. Your data stays in your data directory: one SQLite file plus an uploads folder.

The software does not phone home. It ships no analytics and no telemetry. It opens outbound connections only for the things you switch on yourself: an ACME certificate from Let's Encrypt, a Cloudflare tunnel, Google or Microsoft sign-in, outgoing mail, or an import you start. The source is public and auditable, so this is checkable rather than a promise.