Privacy policy
This website is a static informational site for Phantom Maze AI & Language Lab. We process the minimum amount of personal data needed for the site to work, to respond to messages you send us, and to send the newsletter you explicitly request.
1. Data controller
The data controller for this website is Phantom Maze AI & Language Lab. For any privacy-related request, contact us via the contact form.
2. What data we process
What you submit through the contact form:
- Your name
- Your email address
- The text of your message
If you join the newsletter, we process your email address, the language you chose, the page where you signed up, and the timestamps and confirmation status needed to operate the list. We do not collect IP-address logs at the application layer. The contact form is transmitted via TLS to our delegated form-handler (FormSubmit.co); the newsletter is stored on our own server. Hosting infrastructure (Cloudflare) may retain short-lived access logs for security and abuse prevention.
3. Legal basis & purpose
The legal basis for processing your contact-form submission is your explicit request to be contacted — Article 6(1)(b) GDPR (steps prior to entering into a contract or service relationship) combined with Article 6(1)(f) (legitimate interest in answering correspondence). The data is used only to reply to your message.
We do not:
- Sell, rent, or share your data with third parties for marketing.
- Use submissions to train language models or other machine-learning systems.
- Profile, score or otherwise automate decisions about you.
4. Retention
We keep contact-form submissions only as long as our conversation with you reasonably requires it, plus a short period for our own records. If you ask for deletion, we delete it.
Audience-measurement events (section 5) are kept by Cloudflare in unsampled detail for 7 days, after which only aggregated counts remain, available to us for up to 6 months. Nothing in those records identifies you, so there is nothing in them to delete on request; what we retain beyond that is a plain count of page views.
The reading and purchase-intent notices stored on our own server are kept without a fixed time limit, because they contain no personal data and their only value is as a series over time: knowing whether an essay published last year is still being read. Should that ever change — if we were to add any field that could point at a person — this policy would be rewritten before the change took effect, not after.
Newsletter addresses stay in the active list until you unsubscribe. Unconfirmed requests are deleted after 30 days. When you unsubscribe, we remove the address in clear text and retain only a one-way hash needed to honour the opt-out; it cannot be used to send you mail.
5. Third-party processors
- Cloudflare — hosting and content delivery. May process IP addresses for security purposes. Cloudflare privacy policy ↗
- Cloudflare Web Analytics — audience measurement, in aggregate and for this site only. A small script reports: the page path visited (without any query string), the address of the page that linked you here (host and path), a country derived from your IP, your device type, browser and operating system, and page-loading performance measurements (Core Web Vitals). It writes no cookie and no identifier to your device, performs no fingerprinting, and cannot recognise you on a later visit, in a later session, or on any other website. Cloudflare does not combine this data with data from other sites and does not use it for advertising. Your IP address is used transiently to derive the country and is not stored in the analytics record. We see only aggregate counts. About Web Analytics ↗
- Our own server (Argentina) — reading and purchase-intent counts. When you finish reading an essay, or click through to buy the book, your browser sends us a short notice. It contains exactly five fields and nothing else: the kind of event (finished reading, or purchase click); what it refers to (the essay's path, or which edition of the book); the language (English, Spanish or Italian); a schema version number; and the time we received it, which our server writes — your device does not send a timestamp. We do not receive or store your IP address, your browser or device, any identifier, or how long you took. To be precise about the boundary: the notice reaches our server through Cloudflare, which — as with every request to this site — handles your IP address in transit and may keep short-lived logs for security, as stated above. What arrives at our server, and what we keep, is the five fields and nothing else. Nothing links one notice to another, so we cannot tell whether two of them came from the same person, and we never try to. These notices are stored on a server we own, located in Argentina — a country the European Commission has recognised as providing adequate protection for personal data (Decision 2003/490/EC of 30 June 2003; Article 45 GDPR), so no additional safeguards are required for the transfer. No third party has access to them.
- Our own server (Argentina) — reading and purchase-intent counts, and the newsletter list. Newsletter data is stored in a private SQLite database with file permissions restricted to the service account. The server receives no application-level IP log. The newsletter list contains the email address only while it is active, plus language, sign-up page, timestamps and cryptographic confirmation/baja tokens; after a withdrawal, the address is removed in clear text as described in section 4. Argentina is recognised by the European Commission as providing adequate protection for personal data (Decision 2003/490/EC of 30 June 2003; Article 45 GDPR).
- FormSubmit.co — contact-form delivery. Processes name, email and message in transit. FormSubmit terms ↗
- Resend — transactional delivery of the newsletter confirmation email and the newsletter itself. Resend processes the recipient address and email content in transit. Resend privacy policy ↗
- Google Fonts — typography. Loaded from Google CDN; according to current EU case law, font requests may transmit the IP address to Google. If you prefer, you can block
fonts.googleapis.comin your browser; the site will fall back to system fonts and remain fully readable.
6. Your rights under GDPR
If you are in the EU, you have the right to:
- Access the data we hold about you (Article 15)
- Correct inaccurate data (Article 16)
- Request deletion of your data (Article 17)
- Restrict processing (Article 18)
- Receive your data in portable form (Article 20)
- Object to processing (Article 21)
- Lodge a complaint with your national supervisory authority
To exercise any of these rights, use the contact form and reference the email address you used. You can also leave the newsletter directly through its unsubscribe link.
7. International transfers
Some of our processors (Cloudflare, Google, Resend) are based outside the EU. They are bound by Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. Newsletter data is stored on our own server in Argentina; Resend receives only the address and content required to deliver the email.
8. Cookies
This site sets no cookies of its own. We use no tracking pixels and no advertising scripts. Our audience measurement (section 5: Cloudflare Web Analytics, and the reading counts on our own server) writes no cookie and no identifier to your device, so it cannot recognise you on a later visit, in a later session, or on another site. There is no cross-site or cross-session tracking here of any kind. Your browser may receive cookies only from third-party resources such as Google Fonts; those are not under our control.
To be exact about what the script does: it reads timing information your browser already holds about the page you are currently loading, and sends aggregate statistics to Cloudflare. Article 5(3) of the ePrivacy Directive covers access to your device, and it has no single EU-wide exemption for audience measurement; several national authorities (among them the Italian Garante and the French CNIL) accept measurement of this kind without consent when it meets strict conditions. We have configured this measurement to meet them: it is first-party and for this site alone, it produces aggregate statistics only, it writes no identifier of any kind, the provider does not combine the data with other sites or reuse it for its own purposes, and retention is as stated in section 4 — well inside the ceilings those authorities set.
The corresponding GDPR basis is our legitimate interest in knowing which of our essays are read — Article 6(1)(f) — weighed against a measurement that cannot single you out. Where we rely on legitimate interest you have the right to object (Article 21, section 6 below): write to us and we will tell you exactly what we hold, which for this measurement is an aggregate count with nothing attached to you.
If you would rather not be counted at all, blocking static.cloudflareinsights.com in your browser or extension is enough; the site behaves exactly the same. That is an additional option, not a substitute for the right above.
9. Changes to this policy
We will update this page when our practices change. The "Last updated" date at the top indicates when the policy was last revised. Material changes will be flagged on the home page for a reasonable period.