privacy
plain language. no dark patterns. last updated 21 June 2026.
the short version
this site is a personal blog. the only personal data i collect is the email address you give me when you subscribe to new posts — and only after you confirm it. i don't sell it, i don't share it, and you can leave in one click.
the newsletter — what i collect
- your email address.
- the date you subscribed and confirmed, the consent text you agreed to, and the ip address of the request — kept only as proof of consent (gdpr requires this).
i use double opt-in: after you subscribe you get one email asking you to confirm. if you don't confirm, your address is never used and is eventually removed.
why, and on what basis
i process your email solely to send you new blog posts. the legal basis is your consent (gdpr art. 6(1)(a)), which you give by ticking the box and confirming. that's the only thing i'll ever email you for.
who else touches it
- Resend — my email provider, acting as a data processor under a signed data-processing agreement. it sends the emails on my behalf.
- Neon — the database that stores the subscriber list.
- Vercel — hosts the site and runs the daily job that sends new posts.
no advertising networks, no data brokers, no profiling.
how long i keep it
until you unsubscribe. when you unsubscribe i stop emailing you immediately; i may retain a minimal record of the unsubscribe to honour your choice and as proof of consent history. unconfirmed subscriptions are pruned over time.
your rights
you can unsubscribe from any email in one click — every email carries a one-click unsubscribe link and header. you can also ask me to access, correct, or delete your data, or withdraw consent entirely. just email me and i'll sort it.
analytics
i use privacy-friendly, aggregate analytics to see which posts land. it doesn't identify you and isn't tied to your email.
contact
questions about any of this? email hi@ondrejsvec.com.