DATA PROTECTION
PRIVACY POLICY
The short version
This website sets no cookies and runs no advertising, pixels, fingerprinting or profiling of any kind. There is one contact form; it sends only what you type into it, and only when you press send. There is one tool in the Lab; it takes a web address, checks that page and stores nothing. There is one self-check under /systems/; it runs entirely in your browser, and the only thing it ever sends is an anonymous tick to our own domain — someone started, someone finished, nothing else. On page load the site calls one outside service — a cookieless analytics beacon — which costs two requests: the script that measures, and the measurement it posts back. A third request exists only for failure: if a request to us never completes, your browser reports that failure to Cloudflare, which already hosts this site. A page that loads sends nothing. Everything else — fonts, scripts, images, video, audio — is served from our own domain.
Below is the long version, including the five items we store in your own browser and why.
Controller
Black Oar Studio L.L.C.
1209 Mountain Road Pl NE, Ste N
Albuquerque, NM 87110
United States of America
Email: privacy@blackoarstudio.com
Where the General Data Protection Regulation applies to us under Article 3(2) — because we offer services to people in the European Union — we process personal data in accordance with it.
Hosting and server logs
This site is hosted on Cloudflare Pages, operated by Cloudflare, Inc. Serving a page necessarily involves your IP address reaching the server, and Cloudflare records standard access data for delivery, security and abuse prevention: IP address, timestamp, the resource requested, the response status, and the browser's user-agent and referrer string.
We set Referrer-Policy: no-referrer site-wide, so no referrer is sent when you
follow a link away from this site.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is delivering the site reliably and defending it against attack.
Cloudflare acts as our processor under a data processing agreement. Cloudflare, Inc. is a US company; transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, its certification under the EU–US Data Privacy Framework.
Network error reports
Cloudflare adds two headers, NEL and Report-To, to every response
from this site. They ask your browser to report requests to us that fail at the network level
— a connection that never opens, a name that does not resolve, a timeout. The sampling rate
in the NEL header is success_fraction: 0.0, and that means exactly
what it says: a request that succeeds is never reported, so a page that loads sends nothing.
Only a failure produces a report, and it goes to a.nel.cloudflare.com —
Cloudflare, the host already described above, not a further third party. Such a report
carries the address that was requested, the kind of failure and how long it took, plus your
IP address in transit, as any HTTP request must. Both headers sit in the response headers of
every page here; your browser's network panel shows them.
Legal basis: Article 6(1)(f) GDPR, the same interest as the logs above — we cannot repair a delivery fault we never hear about. Your browser remembers the reporting instruction for as long as the header says, the way it remembers any response header: that is a note about where to send a failure, not a cookie, not site storage, and not data about you.
Analytics
We use Cloudflare Web Analytics. It is the only third-party service this site loads.
It is deliberately the least invasive option available to us:
- It sets no cookies and writes nothing to your browser storage.
- It assigns no identifier to you, and cannot follow you across websites.
- It performs no fingerprinting.
- We see aggregate figures — page views, referrers, countries, device categories — never individuals, and never a path through the site attributable to one person.
It takes two requests, both to Cloudflare: the script beacon.min.js loads from
static.cloudflareinsights.com, and the measurement it takes is posted to
cloudflareinsights.com/cdn-cgi/rum. Open your browser's network panel and you
will see those two leaving our domain; on a visit where nothing fails, there is nothing else.
The only thing that can join them is the error report described under
Hosting and server logs. Both carry your IP address in transit, as any
HTTP request must. Neither is used to build a profile of you.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is understanding, at the level of totals, whether the site works and where visitors arrive from. Because the technique stores nothing on your device and identifies no one, we take the view that it does not require consent under Article 5(3) of the ePrivacy Directive or § 25 TDDDG. If you disagree, a tracker-blocking extension or browser will stop the beacon and the site will work normally.
What we store in your browser
Five entries, all functional, all first-party, none containing personal data. None requires consent, because each exists solely to honour a choice you made yourself.
bos-motion — local storage, persistent
Written only when you press the MOTION control in the footer. Holds the single value
off when you have switched animation off, and is removed entirely when you
switch it back on. It exists so the site does not re-enable motion on you on every page.
Clear your site data to remove it.
bos-shopify-health-check-v1 — local storage, persistent
Written only when you set a status or type a note in the Shopify Health Check under /systems/. Holds your PASS / FAIL / NOT SURE / SKIP choices and your optional notes for the twenty checks, so reloading the page does not erase your progress. It contains what you entered and nothing about you, and it is never transmitted — we cannot read it. The counting signal described under the Health Check's counting signal sends two fixed words and never touches this entry. The tool's Reset button removes it entirely; clearing your site data does the same.
bos-hc-signal-start / bos-hc-signal-complete — local storage,
persistent
Written once each by the same Health Check: the first when you mark your first check, the
second when all twenty have a status. Each holds the single value 1 and exists
so the anonymous counter described under
the Health Check's counting signal counts each browser
once instead of once per visit. They survive the tool's Reset button on purpose — resetting
your answers does not make you a new visitor. Clear your site data to remove them.
bos-ambient — session storage, temporary
Written when you use the ambient audio player. Holds whether the track is playing and the playback position in seconds, so audio continues across page navigation instead of restarting. Your browser deletes it when you close the tab.
Nothing else is written. There are no cookies on this site, and no IndexedDB.
Contacting us
The contact panel offers two routes. You can copy our address and write from your own mail program — nothing reaches us until you send that message yourself. Or you can use the form, which submits your name, your email address and your message to us directly. The form sends nothing until you press send, sets no cookies, and keeps no draft outside your own browser window.
All three fields are required: the form will not send without them, and we cannot answer a message that carries no way to reply. Nothing obliges you to provide any of it — the only consequence of leaving it out is that no enquiry reaches us. The copy-and-write route needs nothing from you at all until you decide what to put in the mail yourself.
Two quiet defences sit on that form, both ours, neither a CAPTCHA. One is a field you cannot see: hidden from the page and skipped by the keyboard, so only an automated script ever fills it in. It is submitted with every message like any other field, and from a person it arrives empty — that emptiness is the whole check. The other is time — the form notes how many seconds pass between opening it and sending, because a bot posts instantly and a person does not. A submission that trips either check is discarded instead of delivered; in practice that only catches software, since two seconds is faster than anyone can write an enquiry. Neither check writes anything to your device, and neither involves a third party.
When you write to us — by either route — we receive and process what you send: your name, your email address, and the content of your message, together with anything else you choose to include. Messages sent through the form additionally carry the two-letter country code that Cloudflare derives from your IP address, so that we know which timezone we are answering into. We use all of it to answer you and, if we go on to work together, to run the engagement.
Legal basis: Article 6(1)(b) GDPR where the correspondence concerns a contract or its negotiation, otherwise Article 6(1)(f) — our legitimate interest in replying to people who write to us.
Retention: enquiries that lead nowhere are deleted within twelve months. Correspondence belonging to a project is kept for the life of the engagement and afterwards for as long as commercial and tax record-keeping obligations require.
Mail addressed to our domain reaches us in two stages. Cloudflare Email Routing accepts it first and forwards it to our mailbox. It does not keep the message, but it records delivery metadata — sender, recipient, timestamp and outcome — which we can see in a routing log. The mailbox itself is Gmail, operated by Google, and that is where the message is stored.
Messages from the form take a different path towards that mailbox: they are received by a Cloudflare Pages Function on our own domain and handed to Resend, our sending provider, which processes the contents in order to deliver them.
All three act as our processors under data processing agreements. Cloudflare, Inc., Google LLC and Resend are US companies; transfers rely on Standard Contractual Clauses and, where applicable, certification under the EU–US Data Privacy Framework.
Retention we do not set ourselves: Cloudflare's access and security logs, its analytics aggregates, the routing log for inbound mail and Resend's delivery log each run for the period that provider operates for the service. We hold no separate copy of any of them and cannot extend them. Where a provider documents a period, that period governs; where it does not, the data exists only as long as delivery, troubleshooting and abuse prevention require. The message itself, once it is in our mailbox, follows the twelve-month rule above.
The Machine Readability Check
Our Lab hosts a tool that takes the address of a web page and reports whether a machine can reach, read, identify and quote it. It asks nothing of you beyond that address: no name, no email, no account, and it sets nothing in your browser.
What happens when you press the button: the address travels to a Cloudflare Pages Function on
our own domain. That function requests the page once, plus the two files any crawler may ask
for — robots.txt and llms.txt — evaluates twelve fixed criteria and
returns the result. The request goes out from our servers, not from your browser, so the site
being checked sees us and not you. No outside service is involved, and the same two quiet
defences as on the contact form apply: an invisible field and a minimum fill time, neither of
which writes anything to your device.
We keep no record of what was checked. The finished report is held in Cloudflare's edge cache for fifteen minutes, keyed by the address, so that several people checking the same site do not make us knock on that site several times. That cached report describes a public web page, not you. The request itself appears in the ordinary server logs described under Hosting and server logs; nothing beyond that is written anywhere.
A web address is not normally personal data. It can be, if you enter one that identifies a person — a profile page, for instance — and in that case the address is processed exactly as described above and nowhere else. Legal basis: Article 6(1)(f) GDPR, our legitimate interest in providing the function you asked for.
The Health Check's counting signal
The Shopify Health Check under /systems/ runs entirely in your browser: your answers and notes stay in the local-storage entry described under Browser storage and never leave your device. The only thing the tool ever transmits is a counting signal — two events, each sent at most once per browser.
What happens, and when: the first time you give any check a status, your browser posts the
word start to a Cloudflare Pages Function on our own domain; if all twenty
checks ever hold a status, it posts the word complete once. Each message
carries that word plus the page language — nothing else. Not your answers, not your notes,
not which checks you marked, no identifier, no cookie. Loading the page sends nothing: a
crawler that fetches the page never appears in this count, because the signal fires only on
a real interaction.
What we keep: the function writes one row — timestamp, event, language, and whether the
requesting client's user-agent string announced itself as automated (the single word
browser or bot; the user-agent itself is not stored) — to a
database at Cloudflare, which already hosts this site. No IP address is written. The request
itself appears in the ordinary server logs described under
Hosting and server logs; nothing beyond that is recorded anywhere.
Why it exists: to tell us whether the tool is used at all — not by whom. The counter cannot be linked to a person, and we could not undo its anonymity if we wanted to. Legal basis: Article 6(1)(f) GDPR, our legitimate interest in learning whether a tool we publish for free is actually being used, measured without identifying anyone.
What we do not do
For the avoidance of doubt, and verifiable by reading this site's source:
- No advertising, retargeting or conversion tracking of any kind.
- No Google Analytics, Tag Manager, Meta pixel, LinkedIn Insight tag, TikTok pixel, Hotjar, Clarity, Plausible, Fathom or Matomo.
- No cookie banner, because there are no cookies to consent to.
- No fonts, scripts, stylesheets, images, video or audio loaded from a third-party CDN.
- No embedded YouTube, Vimeo, Google Maps or social widgets. No iframes at all.
- No error-reporting or session-replay SDK — the browser's own network error reporting is described under Hosting and server logs.
- No newsletter, no mailing list, no marketing automation behind the contact form.
- No automated decision-making and no profiling within the meaning of Article 22 GDPR.
- We do not sell, rent or trade personal data. We never have.
Your rights
Where the GDPR applies, you have the right to obtain confirmation of and access to your data (Art. 15), to have it corrected (Art. 16) or erased (Art. 17), to have processing restricted (Art. 18), to receive it in a portable form (Art. 20), and to object to processing based on legitimate interests (Art. 21). Where we rely on consent, you may withdraw it at any time with effect for the future.
Write to the address above and we will respond within one month.
You may also complain to a data protection supervisory authority in the EU Member State where you live, work, or where you believe an infringement occurred. Exercising these rights costs you nothing and needs no particular form.
External links
Links to our demo projects and to our profiles on X (Twitter), Instagram, Facebook, LinkedIn, Pinterest and LinkedIn (Jens Guenther) leave this site. Once you follow one, the privacy practices of that destination apply, not ours. We have no influence over them.
Changes
We will update this page when the site changes. The date at the top always reflects the current version. We do not maintain an archive of superseded versions; if you need to know what it said on a particular date, ask us.