SANDER KRISTIANSEN
ProjectsBlogProfile

© … SANDER KRISTIANSEN · Terms · Privacy

GITHUB

Privacy Policy

Last updated: 12 June 2026

This policy explains what personal data Sander Kristiansen processes when you use kristiansen.icu, why it is needed, and what choices you have.

Key terms

Plain-English definitions for words used in this document.

Personal data

Information that relates to an identifiable person, such as an IP address in server logs.

Data controller

The person who decides why and how personal data is processed. For this site, that is Sander Kristiansen.

Processing

Any operation performed on personal data, including storing, displaying, or deleting it.

Legal basis

The reason under GDPR that allows personal data to be processed, such as consent or legitimate interest.

Consent

A freely given choice you make, for example when accepting or declining optional cookies.

Legitimate interest

A lawful reason to process data when it is necessary and balanced against your privacy rights, such as keeping the site secure.

Subprocessor

A third-party service that processes data on our behalf, such as a hosting provider.

Retention

How long data is kept before it is deleted or anonymized.

GDPR

The EU General Data Protection Regulation. It gives individuals rights over their personal data where it applies.

TermMeaning
Personal dataInformation that relates to an identifiable person, such as an IP address in server logs.
Data controllerThe person who decides why and how personal data is processed. For this site, that is Sander Kristiansen.
ProcessingAny operation performed on personal data, including storing, displaying, or deleting it.
Legal basisThe reason under GDPR that allows personal data to be processed, such as consent or legitimate interest.
ConsentA freely given choice you make, for example when accepting or declining optional cookies.
Legitimate interestA lawful reason to process data when it is necessary and balanced against your privacy rights, such as keeping the site secure.
SubprocessorA third-party service that processes data on our behalf, such as a hosting provider.
RetentionHow long data is kept before it is deleted or anonymized.
GDPRThe EU General Data Protection Regulation. It gives individuals rights over their personal data where it applies.

1. Data controller

The data controller for personal data related to this site is Sander Kristiansen. Contact: [email protected].

kristiansen.icu is a personal site with optional community accounts — not a large-scale commercial data broker or ad network.

2. What we do not do

We do not sell personal data, run newsletters, process payments, or use ad/tracking platforms such as Google Analytics or Meta Pixel.

The Contact link opens your own email client. We do not receive your message until you send it yourself.

3. What we store and process

When you use the site, the following data may be processed:

  • Loading screen — `sessionStorage` is used once per browser session to avoid repeating the loading animation
  • Server logs — the hosting provider may log IP address, timestamp, requested URL, and browser information (User-Agent) for security and operations
  • Blog content — published posts (title, text, tags, author, date, reading time, optional featured image, linked author account) are stored in PostgreSQL and are publicly visible
  • Uploaded images — blog and avatar images are stored on the server as WebP files, tracked in the database, and served via `/api/images/`
  • GitHub data — public profile and repository information is fetched from GitHub's API as needed and may be temporarily cached; we do not permanently store GitHub profile data in our own database
  • Cookie consent — if you accept optional analytics cookies, your choice is stored with a visitor id and timestamp; declining clears that visitor cookie and does not keep a tracking record
  • Accounts — username, display name, email (encrypted at rest when enabled), email verification status, password hash, optional bio, avatar references, privacy settings, signup IP, last login IP, ban/suspension records, and badge grants
  • Sessions — httpOnly `account_session` cookie plus hashed session tokens with expiry and IP in the database
  • Comments — text you post on blog posts, linked to your account and shown publicly with your username and display name
  • Notifications — in-site messages (for example staff warnings, badge awards, or verification notices) stored per account
  • API keys — optional hashed keys you create for programmatic access to the public API; only a prefix is shown after creation
  • Staff actions — when moderators or administrators act on an account, we may store who performed the action and related metadata (for example ban reason or badge grant)
  • Captcha — Cloudflare Turnstile is used on sign-up; Turnstile may process technical signals under Cloudflare's privacy policy

4. Visitor accounts and sessions

Accounts are optional and used for comments, profiles, notifications, and (when authorised) authoring posts. On sign-up or login, an httpOnly session cookie (`account_session`) is set. Session tokens are stored hashed in the database with expiry and IP address.

Email addresses are used for verification and account recovery flows. Verified status may be required for some features.

Public profile pages show your display name, username, optional avatar, badges you choose to display, and join date according to your privacy settings. Passwords and API key secrets are never shown.

5. Staff panel access

A password-protected staff area at `/admin` is used to publish content and moderate the community. On login, an httpOnly session cookie (`admin_session`) signed with HMAC is set.

Founder, Administrators, Developers, and Moderators may access parts of this panel according to their role. Moderators can manage community members but cannot open site settings or view other staff in the user list.

Staff with CMS access may view account data needed for moderation, publishing, and media review. The `admin_session` cookie identifies staff login state; it does not contain visitor passwords.

6. Purpose and legal basis

We process data for the following purposes:

  • Displaying the site and blog content (legitimate interest)
  • Storing cookie consent choices (consent)
  • Operating, troubleshooting, and protecting the site against abuse (legitimate interest)
  • Managing and publishing content (processing by the site owner)
  • Operating visitor accounts, comments, notifications, and API keys (contract / legitimate interest)
  • Community moderation and abuse prevention (legitimate interest)
  • Preventing sign-up abuse via captcha and email verification (legitimate interest)

7. Sharing with third parties

We do not sell personal data.

Data may be processed by technical subprocessors such as hosting (server/database), Cloudflare Turnstile (sign-up captcha), and GitHub (when the profile page is shown), only as needed to deliver the site.

8. Retention

Cookie consent records are kept for up to 12 months from when you gave consent (`decidedAt`). After that, consent data is automatically removed and you will be asked to choose again.

Server logs are kept according to the hosting provider's routines, usually for a limited time.

Blog content and uploaded images are kept until deleted by the administrator or until the server is rebuilt.

Admin sessions expire after inactivity, when you log out, or when the server is purged.

Account session tokens expire after 30 days or when you sign out. Account data is kept until you request deletion or the account is removed by staff.

Notifications are kept while relevant or until cleared according to site routines.

Revoked API keys remain in the database in revoked form for audit purposes.

Comments remain visible until deleted by you (when available) or by staff.

9. Your rights

Under the GDPR you may have rights to access, rectification, erasure, restriction, objection, and data portability where data about you is concerned and where applicable law requires it.

Because we normally do not collect identifiable data about visitors beyond limited technical records, many requests may relate to logs held by the hosting provider.

Contact [email protected] for requests. You may also lodge a complaint with your supervisory authority.

10. Security

Reasonable technical and organizational measures are used to protect data, including password-protected admin access, signed session cookies with secure flags (httpOnly, secure in production, SameSite), and idle timeout.

No website or system is completely secure, but we work to keep the site maintained and protected.

11. Changes

This policy may be updated from time to time. The latest version is always published on this page with an updated date.

12. Contact

Questions about this policy may be sent to [email protected].

For general site use rules, see the Terms of Service.

Read the terms of service

SANDER KRISTIANSEN
ProjectsBlogProfile

© … SANDER KRISTIANSEN · Terms · Privacy

GITHUB

Privacy Policy

Last updated: 12 June 2026

This policy explains what personal data Sander Kristiansen processes when you use kristiansen.icu, why it is needed, and what choices you have.

Key terms

Plain-English definitions for words used in this document.

Personal data

Information that relates to an identifiable person, such as an IP address in server logs.

Data controller

The person who decides why and how personal data is processed. For this site, that is Sander Kristiansen.

Processing

Any operation performed on personal data, including storing, displaying, or deleting it.

Legal basis

The reason under GDPR that allows personal data to be processed, such as consent or legitimate interest.

Consent

A freely given choice you make, for example when accepting or declining optional cookies.

Legitimate interest

A lawful reason to process data when it is necessary and balanced against your privacy rights, such as keeping the site secure.

Subprocessor

A third-party service that processes data on our behalf, such as a hosting provider.

Retention

How long data is kept before it is deleted or anonymized.

GDPR

The EU General Data Protection Regulation. It gives individuals rights over their personal data where it applies.

TermMeaning
Personal dataInformation that relates to an identifiable person, such as an IP address in server logs.
Data controllerThe person who decides why and how personal data is processed. For this site, that is Sander Kristiansen.
ProcessingAny operation performed on personal data, including storing, displaying, or deleting it.
Legal basisThe reason under GDPR that allows personal data to be processed, such as consent or legitimate interest.
ConsentA freely given choice you make, for example when accepting or declining optional cookies.
Legitimate interestA lawful reason to process data when it is necessary and balanced against your privacy rights, such as keeping the site secure.
SubprocessorA third-party service that processes data on our behalf, such as a hosting provider.
RetentionHow long data is kept before it is deleted or anonymized.
GDPRThe EU General Data Protection Regulation. It gives individuals rights over their personal data where it applies.

1. Data controller

The data controller for personal data related to this site is Sander Kristiansen. Contact: [email protected].

kristiansen.icu is a personal site with optional community accounts — not a large-scale commercial data broker or ad network.

2. What we do not do

We do not sell personal data, run newsletters, process payments, or use ad/tracking platforms such as Google Analytics or Meta Pixel.

The Contact link opens your own email client. We do not receive your message until you send it yourself.

3. What we store and process

When you use the site, the following data may be processed:

  • Loading screen — `sessionStorage` is used once per browser session to avoid repeating the loading animation
  • Server logs — the hosting provider may log IP address, timestamp, requested URL, and browser information (User-Agent) for security and operations
  • Blog content — published posts (title, text, tags, author, date, reading time, optional featured image, linked author account) are stored in PostgreSQL and are publicly visible
  • Uploaded images — blog and avatar images are stored on the server as WebP files, tracked in the database, and served via `/api/images/`
  • GitHub data — public profile and repository information is fetched from GitHub's API as needed and may be temporarily cached; we do not permanently store GitHub profile data in our own database
  • Cookie consent — if you accept optional analytics cookies, your choice is stored with a visitor id and timestamp; declining clears that visitor cookie and does not keep a tracking record
  • Accounts — username, display name, email (encrypted at rest when enabled), email verification status, password hash, optional bio, avatar references, privacy settings, signup IP, last login IP, ban/suspension records, and badge grants
  • Sessions — httpOnly `account_session` cookie plus hashed session tokens with expiry and IP in the database
  • Comments — text you post on blog posts, linked to your account and shown publicly with your username and display name
  • Notifications — in-site messages (for example staff warnings, badge awards, or verification notices) stored per account
  • API keys — optional hashed keys you create for programmatic access to the public API; only a prefix is shown after creation
  • Staff actions — when moderators or administrators act on an account, we may store who performed the action and related metadata (for example ban reason or badge grant)
  • Captcha — Cloudflare Turnstile is used on sign-up; Turnstile may process technical signals under Cloudflare's privacy policy

4. Visitor accounts and sessions

Accounts are optional and used for comments, profiles, notifications, and (when authorised) authoring posts. On sign-up or login, an httpOnly session cookie (`account_session`) is set. Session tokens are stored hashed in the database with expiry and IP address.

Email addresses are used for verification and account recovery flows. Verified status may be required for some features.

Public profile pages show your display name, username, optional avatar, badges you choose to display, and join date according to your privacy settings. Passwords and API key secrets are never shown.

5. Staff panel access

A password-protected staff area at `/admin` is used to publish content and moderate the community. On login, an httpOnly session cookie (`admin_session`) signed with HMAC is set.

Founder, Administrators, Developers, and Moderators may access parts of this panel according to their role. Moderators can manage community members but cannot open site settings or view other staff in the user list.

Staff with CMS access may view account data needed for moderation, publishing, and media review. The `admin_session` cookie identifies staff login state; it does not contain visitor passwords.

6. Purpose and legal basis

We process data for the following purposes:

  • Displaying the site and blog content (legitimate interest)
  • Storing cookie consent choices (consent)
  • Operating, troubleshooting, and protecting the site against abuse (legitimate interest)
  • Managing and publishing content (processing by the site owner)
  • Operating visitor accounts, comments, notifications, and API keys (contract / legitimate interest)
  • Community moderation and abuse prevention (legitimate interest)
  • Preventing sign-up abuse via captcha and email verification (legitimate interest)

7. Sharing with third parties

We do not sell personal data.

Data may be processed by technical subprocessors such as hosting (server/database), Cloudflare Turnstile (sign-up captcha), and GitHub (when the profile page is shown), only as needed to deliver the site.

8. Retention

Cookie consent records are kept for up to 12 months from when you gave consent (`decidedAt`). After that, consent data is automatically removed and you will be asked to choose again.

Server logs are kept according to the hosting provider's routines, usually for a limited time.

Blog content and uploaded images are kept until deleted by the administrator or until the server is rebuilt.

Admin sessions expire after inactivity, when you log out, or when the server is purged.

Account session tokens expire after 30 days or when you sign out. Account data is kept until you request deletion or the account is removed by staff.

Notifications are kept while relevant or until cleared according to site routines.

Revoked API keys remain in the database in revoked form for audit purposes.

Comments remain visible until deleted by you (when available) or by staff.

9. Your rights

Under the GDPR you may have rights to access, rectification, erasure, restriction, objection, and data portability where data about you is concerned and where applicable law requires it.

Because we normally do not collect identifiable data about visitors beyond limited technical records, many requests may relate to logs held by the hosting provider.

Contact [email protected] for requests. You may also lodge a complaint with your supervisory authority.

10. Security

Reasonable technical and organizational measures are used to protect data, including password-protected admin access, signed session cookies with secure flags (httpOnly, secure in production, SameSite), and idle timeout.

No website or system is completely secure, but we work to keep the site maintained and protected.

11. Changes

This policy may be updated from time to time. The latest version is always published on this page with an updated date.

12. Contact

Questions about this policy may be sent to [email protected].

For general site use rules, see the Terms of Service.

Read the terms of service