Privacy
What this site collects
Server logs, and Google Analytics. The detail is below, at the level I would want it if I were auditing someone else's site, including the part that does not flatter me.
What gets logged
Every request to this site lands in a CloudFront access log. Each line records the time, the path you asked for, any query string, the response status, the referring page, your browser's user-agent string, the country the CDN edge resolved, the bytes served, and your IP address.
That is a server log. Every web server produces one. Nothing here is layered on top of it.
What runs in your browser
Google Analytics 4, loaded from Google's servers on every page since 19 August 2026. It records that a page was viewed, which page, the referring page, the rough time, and the language and screen size your browser reports. Google derives an approximate country from your IP address.
It sets two cookies on this domain, _ga and one named after
the property ID. They hold a random number with no name, email or account
attached, and their job is to recognise the same browser across pages and
across visits so a returning reader is not counted as a new one every
time. They last up to two years unless you clear them.
Between 30 July and 19 August 2026 there was no script here at all, and an hourly job replayed server logs into the same Analytics property instead. That job sent Google your real IP address. It has been switched off, so the site now hands Google less about you than it did last week, not more.
Why there is no consent banner
Because I have not built one yet. That is the whole reason, and I would rather write it down than dress it up.
Cookies used for analytics normally call for consent before they are set, and this site sets them without asking. Until that changes, the honest description is that this page is the disclosure and there is no consent step in front of it. If you would rather not be measured, a tracker blocker or Google's own opt-out add-on stops it, and neither costs you anything on this site: nothing here is gated, personalised, or degraded if the tag never loads.
What still does not happen
Fonts are served from this domain, not from a font CDN. No embeds, no social widgets, no ad network, no session recording, no A/B tooling, no advertising features or remarketing audiences in the Analytics property. No forms either, so there is nothing to submit. The contact page is a mailto link.
Nothing here follows you to other sites. The cookies are first-party and only this domain can read them.
What the logs are used for
Counting. Which pages get read, which links get shared, what returns a 404. The queries run inside my own AWS account in Ireland, against a private, encrypted bucket. No crawler, no enrichment vendor, no data broker anywhere in the path. Country comes from the CDN edge itself, so no IP is handed to a geolocation service.
What goes to Google
The page path and title, the referring page, your language and screen size, the timestamp, and the random ID from the cookie described above. Your IP address reaches Google as it does any server you request a file from, and Google documents that it uses it to derive an approximate location and does not retain it in the property. That is their account of their own system, not something I can verify from mine, so what I can tell you for certain is what I send and what I ask for.
I do not send your IP address deliberately any more. Until 19 August 2026 an hourly job did exactly that, overriding the sender IP so the geography in the reports would be real. That job is off.
Google is the only third party in this path. Everything else stays in my AWS account.
How long it is kept
-
Raw access logs (S3)
90 days, then deleted by a bucket lifecycle rule
-
Query results
14 days
-
Google Analytics
14 months
-
Analytics cookies
up to 2 years, or until you clear them
There is no traffic history before 29 July 2026. Logging was switched off until then.
Legal basis
For the server logs: legitimate interest, GDPR Article 6(1)(f). Knowing whether anything published here gets read, and being able to see what broke when something breaks. Weighed against what the logs do not do. Nothing follows you off this domain, no profile is built, nothing is sold or shared beyond what is described above.
For the analytics cookies: the same interest, without the consent step that storing something on your device would ordinarily require. I am not going to argue that around into a technicality. It is a gap, it is named in full above, and the section on what you can ask for applies to it.
What you can ask for
Access, correction, deletion, or an objection to the whole arrangement. Email me and I will do it. One practical limit worth stating plainly: the only identifier in the log is your IP address, so a request has to name it along with the rough dates, or there is nothing for me to find. You can also complain to a data protection authority in your country.
If you would rather not be in the log at all, a VPN or Tor is more effective than any setting I could offer you.
If you email me
The address below is a Gmail address, so whatever you send sits in Google's mail infrastructure along with the rest of that mailbox. I keep client correspondence for as long as the engagement and its paperwork need it, and I do not add anyone to a mailing list. There isn't one.
Who runs this site
Olha Shevchenko. Questions about anything on this page: olha.n.sh@gmail.com.
Last updated 19 August 2026. This page describes infrastructure that actually runs. If the collection changes, this page changes with it.