hupden/ projects
blogtools

Privacy Policy

Last updated August 9, 2026

hupden.com is a personal, self-hosted site operated by Rich Stadnick in Rhode Island, United States. This policy explains what the site collects, why, and for how long. It is written to be short because the site collects very little.

The short version

What is collected

Like most web servers, this site automatically records a log entry for each request. Each entry may include your IP address, browser user-agent string, the page or resource requested, the referring URL, the response status, and a timestamp. That is the only information collected about visitors.

What is not collected

Why it is collected

Server logs are used only to keep the site secure and working — detecting and blocking abuse and automated attacks (via fail2ban) and understanding aggregate traffic. For visitors in the EU/UK, the legal basis is legitimate interest in the security and integrity of the site.

How long it is kept

Full server logs are automatically deleted after 30 days. Records of IP addresses temporarily blocked for abuse may persist for the duration of the block.

Before that deletion, a reduced copy of each day is archived and kept indefinitely, so that long-term traffic and attack patterns can still be studied. In the archived copy your IP address is truncated to its network — the last part of an IPv4 address is replaced with zero (203.0.113.47 becomes 203.0.113.0), and IPv6 addresses are cut to their first three groups. The archive is not published.

One exception: requests that were probing the server rather than visiting it keep their full IP address in the archive. That means requests for a hostname this server does not host (including requests sent to the bare IP address), attempts to guess subdomain names, and requests for paths that only exist on software this site does not run — /.env, /wp-login.php and similar. Retaining those addresses is necessary to recognise repeat attackers over time, which is a security purpose the GDPR specifically recognises (Recital 49). The test looks only at what was requested; it never treats your browser or client identification as grounds for keeping your address. Ordinary browsing of this site is never caught by it.

Who it is shared with

Nothing is shared with third parties. The site runs on a server the operator manages directly; visitor traffic is not routed through third-party analytics or advertising services. Data may be disclosed only if required by law.

Your rights

If you are in the EU or UK, you have rights under the GDPR to access, correct, or request deletion of personal data relating to you, and to object to its processing. Because full logs are automatically purged after 30 days and are not tied to any account, they are removed without you having to ask. For ordinary visits, the longer-term archive keeps only truncated network addresses, so there is no record in it identifying you individually. Where a full address has been retained under the security exception above, it is kept on the legitimate-interest basis described there; you can object, and that objection will be weighed against the security reason for keeping it. To make a request, contact privacy@hupden.com.

Children

This site is not directed at children under 13, and does not knowingly collect information from them.

The admin area

The private /adminarea is used only by the operator and is not accessible to visitors. It stores a login token in the operator's own browser (via local storage, not a cookie) purely to keep them signed in. It sets nothing on visitors' devices.

Changes

This policy may be updated from time to time; the date at the top reflects the latest version.

Contact

Questions about this policy: privacy@hupden.com.

← hupdenPrivacyTerms