elliodelics

The hard questions, answered.

When the hard questions about your data arrive, the answers should already be written down. These are ours, for this studio and this site, on the record.

Yours would cover more ground, your systems, your regulations, a real surface area. This one is just the receipt.

What data do you collect from visitors?
None. No cookies, no trackers, no analytics, no forms. The privacy notice covers the two exceptions, which are email you choose to send and the host’s own server logs.
Where does business data live?
Correspondence lives in Proton Mail, on servers in Switzerland. Code lives in GitHub. Client data lives in the client’s own systems, which is where it belongs.
Who has access?
Mike. Collaborators get access scoped to their specific project, and it ends when the work does.
Is data encrypted?
Yes. Everything between your browser and this site travels encrypted, mail sits encrypted on Proton’s servers where even Proton can’t read it, and public records limit who is allowed to issue this domain’s security certificates at all.
Who are your subprocessors?
Two. GitHub serves this site and Proton carries the mail. Both are named in the privacy notice, and nothing else touches the data.
What is your incident response plan?
A small surface gets a small plan. security.txt says where to report, reports go straight to Mike, and fixes ship in public like everything else here.
How would we verify any of this?
View source. The colophon explains how the site is built, the accessibility statement shows the audit trail, the DNS records are public, and the deploy pipeline is pinned to exact commits anyone can read.

last reviewed · july 2026

back to the full page →