{"id":12333,"date":"2026-08-19T18:31:24","date_gmt":"2026-08-19T16:31:24","guid":{"rendered":"https:\/\/www.lukaswojcik.com\/blog\/privacy-policy\/"},"modified":"2026-09-28T17:11:48","modified_gmt":"2026-09-28T15:11:48","slug":"privacy-policy","status":"publish","type":"page","link":"https:\/\/www.lukaswojcik.com\/blog\/en\/privacy-policy\/","title":{"rendered":"Privacy Policy"},"content":{"rendered":"<div class=\"lw-legal\">\n<p class=\"lw-legal-stand\">Version 3.6 &middot; in force since 28 September 2026<\/p>\n<p class=\"lw-legal-intro\">This policy describes which personal data are processed when the website <code>www.lukaswojcik.com<\/code> is used, on what legal basis this happens, how long the data are kept and which rights the persons concerned have. It follows Regulation (EU) 2016\/679 (GDPR) and the Polish Act on the Protection of Personal Data of 10 May 2018.<\/p>\n<h2>1. Controller<\/h2>\n<p>The controller within the meaning of Art. 4(7) GDPR is:<\/p>\n<p class=\"lw-legal-adresse\">LW IT Solutions Company Lukas W&oacute;jcik<br \/>\nal. Tadeusza Ko&#347;ciuszki 80\/82, lok. 301<br \/>\n90-437 &#321;&oacute;d&#378;, Poland<br \/>\nNIP: PL7252266190 &middot; REGON: 369859995<br \/>\nE-mail: <a href=\"mailto:contact@lukaswojcik.com\">contact@lukaswojcik.com<\/a><\/p>\n<p>A data protection officer has not been appointed, because none of the conditions of Art. 37(1) GDPR applies to an operation of this size. All matters concerning data protection are handled directly at the address above.<\/p>\n<h2>2. What shapes this website<\/h2>\n<p>Three decisions determine how little data this site actually needs, and they are worth stating before the individual processing operations are listed.<\/p>\n<ul>\n<li><strong>The infrastructure is self-operated.<\/strong> The web server runs on hardware belonging to the controller, connected through a local access provider in &#321;&oacute;d&#378;, Poland. There is no external hosting provider, no content delivery network and no reverse proxy in front of it. Requests reach the controller&#8217;s own machine directly, which means no third party sees the traffic before it is answered.<\/li>\n<li><strong>Nothing is loaded from third parties without need.<\/strong> Fonts, stylesheets and images are delivered from the site&#8217;s own domain, and the comments do without pictures from an external avatar service. Without consent, the only thing loaded from an external server is the spam protection reCAPTCHA described in section 8.1. A Content Security Policy restricts, at browser level, which external origins may be contacted at all.<\/li>\n<li><strong>Everything that is not strictly necessary is blocked until consent exists.<\/strong> Analytics scripts are held back by the consent management platform and are only released after an explicit decision. Refusing has no effect on the usability of the site.<\/li>\n<\/ul>\n<h2>3. Server log files<\/h2>\n<p>Every retrieval of a file from this website is recorded by the web server in a log file. This happens automatically and cannot be switched off, because without it a server cannot be operated securely. The following data are recorded:<\/p>\n<ul>\n<li>the IP address of the requesting device<\/li>\n<li>date and time of the request<\/li>\n<li>the path and name of the retrieved file<\/li>\n<li>the HTTP status code and the volume of data transferred<\/li>\n<li>the referring page, if the browser transmits one<\/li>\n<li>the browser identification string (user agent)<\/li>\n<\/ul>\n<p><strong>Purpose and legal basis:<\/strong> the logs serve to deliver the site, to detect and trace attacks, and to diagnose technical faults. The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in the secure and stable operation of the server.<\/p>\n<p><strong>Storage period:<\/strong> log files are rotated daily and deleted automatically after 14 days. They are not merged with other data sources and are not used to build profiles.<\/p>\n<h2>4. Cookies and local storage<\/h2>\n<p>This site works without advertising cookies and without cross-site tracking. What this website stores locally is limited to the following; in addition there are the cookies which reCAPTCHA sets under the domain google.com (section 8.1):<\/p>\n<table>\n<thead>\n<tr>\n<th>Name<\/th>\n<th>Type<\/th>\n<th>Purpose<\/th>\n<th>Duration<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>pll_language<\/code><\/td>\n<td>Cookie<\/td>\n<td>Retains the chosen blog language (English, German, Polish)<\/td>\n<td>1 year<\/td>\n<\/tr>\n<tr>\n<td><code>lw-theme<\/code><\/td>\n<td>Local storage<\/td>\n<td>Retains the choice between light view, dark view and system default<\/td>\n<td>Until deleted in the browser<\/td>\n<\/tr>\n<tr>\n<td>Consent record of the consent management platform<\/td>\n<td>Cookie \/ local storage<\/td>\n<td>Retains which categories were accepted or refused, so that the banner is not shown again on every page<\/td>\n<td>Up to 12 months<\/td>\n<\/tr>\n<tr>\n<td><code>comment_author_*<\/code><\/td>\n<td>Cookie<\/td>\n<td>Set only if the box for saving them is ticked when a comment is submitted; on the next visit the name, e-mail address and website are then pre-filled, and the visitor&#8217;s own comment that is still awaiting approval is visible<\/td>\n<td>1 year<\/td>\n<\/tr>\n<tr>\n<td><code>wordpress_test_cookie<\/code><\/td>\n<td>Cookie<\/td>\n<td>Set only when the blog&#8217;s login page is opened, to check whether the browser accepts cookies; reading and commenting do not create it<\/td>\n<td>Session<\/td>\n<\/tr>\n<tr>\n<td><code>_grecaptcha<\/code><\/td>\n<td>Local Storage<\/td>\n<td>Token of the spam protection reCAPTCHA, see section 8.1 &ndash; created on pages with a form when the page loads, on tool pages only when a check is started<\/td>\n<td>Until deleted in the browser<\/td>\n<\/tr>\n<tr>\n<td><code>_ga<\/code>, <code>_ga_*<\/code><\/td>\n<td>Cookie<\/td>\n<td>Google Analytics 4 &ndash; only set after consent, see section 6<\/td>\n<td>Up to 2 years<\/td>\n<\/tr>\n<tr>\n<td><code>rc_conv<\/code>, <code>rc_seen<\/code>, <code>rc_tab<\/code>, <code>rc_theme<\/code>, <code>rc_locale_wahl<\/code>, <code>rc_dnd<\/code>, <code>rc_dnt<\/code> and further entries beginning with <code>rc_<\/code><\/td>\n<td>Local storage \/ session storage<\/td>\n<td>Chat, see section 6.2: the current conversation, messages already received, the view and language of the window, the wish not to be addressed again &ndash; without consent none of this is created<\/td>\n<td>Conversation 24 hours, settings up to 1 year<\/td>\n<\/tr>\n<tr>\n<td><code>mp_visitor_id<\/code><\/td>\n<td>Local storage<\/td>\n<td>MousePlayer: random identifier making repeat visits from the same browser distinguishable &ndash; only after consent, see section 7<\/td>\n<td>Until withdrawal or until browser data are cleared<\/td>\n<\/tr>\n<tr>\n<td><code>mp_session_data<\/code><\/td>\n<td>Local storage<\/td>\n<td>MousePlayer: identifier of the current visit together with its origin, so that paths across several pages are held together<\/td>\n<td>30 minutes without activity<\/td>\n<\/tr>\n<tr>\n<td><code>mp_pv_count_*<\/code><\/td>\n<td>Local storage<\/td>\n<td>MousePlayer: counter of page views within a visit<\/td>\n<td>As the session<\/td>\n<\/tr>\n<tr>\n<td><code>mp_tab_id<\/code><\/td>\n<td>Session storage<\/td>\n<td>MousePlayer: tells apart several open tabs of the same session<\/td>\n<td>Until the tab is closed<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>Legal basis:<\/strong> for the language cookie, the display preference and the comment cookies, Art. 6(1)(f) GDPR together with the Polish Electronic Communications Law (<em>Prawo komunikacji elektronicznej<\/em>) &ndash; these entries are technically necessary for a function that was actively requested. For all analytics cookies, Art. 6(1)(a) GDPR, that is consent.<\/p>\n<p>Stored cookies can be deleted at any time in the browser settings, and their storage can be prevented there in general. Blocking all cookies may cause the language selection and the display preference to be forgotten between visits.<\/p>\n<h2>5. Consent management<\/h2>\n<p>Consent for non-essential scripts is obtained and documented through the consent management platform <strong>Consented<\/strong> (consented.eu). That platform is another product of the controller named in section 1 and runs on the same self-operated infrastructure in Poland; loading it means the browser contacts the domain consented.eu, which is under the same operator and is not a third party. Its script runs before all other scripts and blocks the services listed in sections 6 and 7 until a decision has been made.<\/p>\n<p>When the banner is used, the decision is recorded on the controller&#8217;s own server so that the consent can be demonstrated later, as required by Art. 7(1) GDPR. The record contains:<\/p>\n<ul>\n<li>the decision itself, in the form <code>accepted<\/code> or <code>rejected<\/code><\/li>\n<li>the IP address at the moment of the decision<\/li>\n<li>the browser identification string, shortened to 255 characters<\/li>\n<li>the timestamp of the decision<\/li>\n<\/ul>\n<p><strong>Legal basis:<\/strong> Art. 6(1)(c) GDPR, since Art. 7(1) GDPR obliges the controller to be able to demonstrate consent. <strong>Storage period:<\/strong> for the duration of the consent and for a further three years afterwards, which corresponds to the general limitation period under Polish civil law.<\/p>\n<p>A decision once made can be changed at any time through the cookie symbol at the lower edge of the page. Withdrawal takes effect for the future and does not affect the lawfulness of the processing carried out until then.<\/p>\n<h2>6. Services that load only after consent<\/h2>\n<p>Three services stay held back until the consent management platform described in section 5 releases them: audience measurement with Google Analytics 4, the chat, and the Stats4U visitor counter. The session recording in section 7 follows the same rule.<\/p>\n<h3>6.1 Web analytics with Google Tag Manager and Google Analytics 4<\/h3>\n<p>This website uses Google Tag Manager (container <code>GTM-NKNSMSZ2<\/code>) and, through it, Google Analytics 4. Both are services of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager itself sets no cookies and collects no personal data on its own; it is a delivery mechanism for the tags configured within it.<\/p>\n<p>Google Analytics 4 uses cookies to distinguish visits and to record how the site is used. The following are processed in particular: shortened IP address, pages viewed, time of access, duration of visit, approximate location derived from the IP address, device type, browser and operating system, and the source that led to the site.<\/p>\n<p><strong>IP anonymisation:<\/strong> Google Analytics 4 shortens IP addresses within the European Union before any further processing and does not store the full address.<\/p>\n<p><strong>Legal basis:<\/strong> Art. 6(1)(a) GDPR. Neither the container nor the analytics tag is loaded before consent has been given. Without consent nothing is transmitted to Google.<\/p>\n<p><strong>Transfer to third countries:<\/strong> data may be transferred to Google LLC in the United States. Google LLC is certified under the EU&ndash;US Data Privacy Framework, so that an adequacy decision of the European Commission pursuant to Art. 45 GDPR applies. In addition, standard contractual clauses pursuant to Art. 46(2)(c) GDPR have been concluded with Google.<\/p>\n<p><strong>Storage period:<\/strong> Google Analytics 4 keeps two separate periods. Event data are retained for 2 months, user-level data for 14 months; both are deleted automatically once the period has run.<\/p>\n<p>Further information is available in Google&#8217;s privacy policy at <a href=\"https:\/\/policies.google.com\/privacy\" rel=\"noopener nofollow\" target=\"_blank\">policies.google.com\/privacy<\/a>. Independently of the consent banner, a browser add-on offered by Google at <a href=\"https:\/\/tools.google.com\/dlpage\/gaoptout\" rel=\"noopener nofollow\" target=\"_blank\">tools.google.com\/dlpage\/gaoptout<\/a> prevents transmission to Google Analytics.<\/p>\n<h3>6.2 Chat<\/h3>\n<p>A chat window is available on every page. Behind it stands <strong>Reactive Chat<\/strong>, another product of the controller named in section 1; it runs on the same self-operated infrastructure, and no external provider is involved. The window is loaded from the domain cdn.reactive.chat, and the exchange runs over a WebSocket connection to reactive.chat; both domains are under the same operator.<\/p>\n<p><strong>Already when the page loads:<\/strong> where consent exists, the window opens the connection immediately, not only when it is opened. What is transmitted then: the address and title of the page, the referring page, the browser language, the time zone, window and screen dimensions, whether the device is a mobile one, and campaign identifiers from the address such as <code>utm_source<\/code> or <code>gclid<\/code>. The server sees the IP address of the connection and the browser identification string; the IP address is not stored.<\/p>\n<p><strong>A conversation:<\/strong> what is stored are the messages with their time and direction, a session and a visitor identifier, the browser identification string, and the page on which the conversation began. Name and e-mail address are not asked for. Recognised e-mail addresses, phone numbers and card, tax and bank account numbers are replaced before storage &ndash; in the browser, and once more on the server.<\/p>\n<p><strong>The text of the page:<\/strong> when the window is opened, it reports the visible text of the page to the server, so that a question about that page can be answered; there it is stored. Form fields are left out entirely, and the result containers of the tools described in section 10 are marked as private &ndash; their content does not go along.<\/p>\n<p><strong>Answers from a language model:<\/strong> part of the answers is produced by a language model. It runs on the controller&#8217;s own machines in the local network; nothing goes to a provider of AI services or to a third country. The model receives the cleaned question, the conversation so far, extracts from a knowledge base of the site&#8217;s own pages, and the title and path of the page.<\/p>\n<p><strong>In the browser<\/strong> the chat stores entries under names beginning with <code>rc_<\/code>; they are listed in section 4. Without consent, none of them is created.<\/p>\n<p><strong>Legal basis:<\/strong> Art. 6(1)(a) GDPR and, for the storage on the device, the Polish Electronic Communications Law in addition. Without consent the window is not loaded; withdrawal through the cookie icon takes effect for the future.<\/p>\n<p><strong>Storage period:<\/strong> no fixed period has been set for conversations so far; they remain stored until deletion is requested. The chat window has a button of its own for that, which removes conversation, messages and session immediately and completely; an informal message to the address in section 1 is equally sufficient. As soon as a period is set, it will be stated here.<\/p>\n<h3>6.3 Visitor counter (Stats4U)<\/h3>\n<p>This website uses the Stats4U visitor counter (stats4u.net, LW IT Solutions Company, &#x141;&oacute;d&#x17a;, Poland). When a page is opened, your browser loads a counter image from stats4u.net and, as a technical necessity, transmits its IP address, the browser identification and the address of the page being viewed.<\/p>\n<p>The IP address is used to determine country and city approximately and to build a daily hash, which counts a visitor only once per day. It is not stored in the statistics. The daily hash is built with a secret salt that changes every day and is deleted after 2 days; after that it cannot be traced to anyone. The web server&#8217;s access log holds the IP address for up to 14 days.<\/p>\n<p>The counter sets no cookies and reads nothing from your device. What is stored are daily totals: hits, visitors, country, browser, operating system, language, the pages of this website that were opened and the transitions between them, the domain of the referring page, events defined for this website, time on page, scroll depth, load time, and the entry and last page of a visit. They are kept for 400 days. Processing takes place in Poland; no data is transferred to third countries. For the duration of a visit there is additionally one row in the live list &ldquo;who is on the site now&rdquo;: country, city, the page currently open, browser, operating system, device type and language. It is deleted at the next nightly clean-up. While the page stays open the counter checks in about once a minute so that this row does not age prematurely; all it sends is the counter number, and nothing additional is stored.<\/p>\n<p>The legal basis is our legitimate interest in audience measurement (Art. 6(1)(f) GDPR).<\/p>\n<p>The statistics for this website are not publicly visible.<\/p>\n<p>Stats4U privacy policy: <a href=\"https:\/\/www.stats4u.net\/privacy\">https:\/\/www.stats4u.net\/privacy<\/a><\/p>\n<h2>7. Session recording and heatmaps (MousePlayer)<\/h2>\n<p>This website uses MousePlayer, a tool for recording and analysing sessions, under the channel identifier <code>955a45df5ee842cb<\/code>. It captures how visitors use the website and then presents the sequence as a replay and as a heatmap. This is reviewed in order to identify usability barriers, drop-offs and technical errors. A session may also be followed live while it is happening; no separate notice is given at the moment someone is watching.<\/p>\n<p>Of everything described in this policy, this is the most far-reaching processing. It therefore gets the most detail.<\/p>\n<h3>7.1 Who operates it<\/h3>\n<p>MousePlayer is not a third-party service here. It is developed and operated by the controller named in section 1, on that controller&#8217;s own infrastructure. Provider and controller are the same legal person, which is why no processing agreement pursuant to Art. 28 GDPR exists for it and no recordings are handed to an external analytics provider. The one external element is the encrypted backup described in section 7.8.<\/p>\n<h3>7.2 Data processed<\/h3>\n<ul>\n<li>Device and environment data: browser and version, operating system, device class, screen resolution and window size<\/li>\n<li>Behavioural data: mouse movement and pointer paths, clicks, scroll depth, timestamps of interactions<\/li>\n<li>Navigation and origin: pages and addresses opened, landing page, referring domain, campaign identifiers<\/li>\n<li>The structure of the pages displayed, used solely to replay the session<\/li>\n<li>A random identifier assigned in the browser to tell visits apart<\/li>\n<li>The country derived from the IP address<\/li>\n<\/ul>\n<h3>7.3 IP address<\/h3>\n<p>The full IP address exists only in memory, for as long as establishing the connection, determining the country and preventing abuse require it. It is truncated before anything is written to the database. A visitor&#8217;s full IP address is neither stored nor displayed in the analysis.<\/p>\n<h3>7.4 Form input<\/h3>\n<p>Every character of every form input is replaced in the browser before it is transmitted. A replay shows that someone typed and how long they took &ndash; not what. Fields identified as password or payment fields always stay fully obscured. This full masking is the setting in force for this website.<\/p>\n<p>One limit deserves to be stated plainly: what the website itself displays &ndash; a confirmation page repeating an address that was entered, for instance &ndash; is part of the page and therefore part of the replay.<\/p>\n<h3>7.5 Legal basis<\/h3>\n<p>Consent pursuant to Art. 6(1)(a) GDPR; for storing information on the terminal device and accessing it, additionally the Polish Electronic Communications Law (<em>Prawo komunikacji elektronicznej<\/em>). Without consent the script assigns no identifier, stores nothing, opens no connection and records nothing. A Global Privacy Control signal sent by the browser is honoured and takes precedence over an approval.<\/p>\n<h3>7.6 Withdrawal<\/h3>\n<p>Consent can be withdrawn at any time with effect for the future, through the cookie symbol at the lower edge of the page. Withdrawal takes effect immediately: recording stops, the connection is closed, data not yet transmitted is discarded rather than sent, and the identifiers stored in the browser are deleted.<\/p>\n<h3>7.7 Retention<\/h3>\n<p>Recordings are deleted automatically after no more than <strong>365 days<\/strong>. Records of the consent decision itself are kept longer; they contain no behavioural data, only the fact, time and source of the decision.<\/p>\n<h3>7.8 Place of processing and recipients<\/h3>\n<p>Processing takes place on the controller&#8217;s own servers in &#321;&oacute;d&#378;, Poland. The recording script transmits to that infrastructure only. For backup purposes, an encrypted copy of the database is stored daily with Google Drive (storage location USA\/worldwide); encryption happens before the transfer and the keys do not leave the controller. Google therefore holds a container it cannot open.<\/p>\n<h3>7.9 Seeing and deleting what is stored<\/h3>\n<p>The browser identifier described above is the key to the recordings. MousePlayer keeps a self-service page on which that key can be used to see how many sessions are stored under it, what period they date from and on which websites they were created &ndash; and to request their deletion. The page deliberately does not display the recordings themselves: the identifier is a key without a password.<\/p>\n<p class=\"lw-legal-hinweis\"><a id=\"mp-daten\" href=\"https:\/\/www.mouseplayer.com\/my-data\">My stored data<\/a> &ndash; the link carries the identifier of this browser with it, so nothing has to be typed in on arrival. Where no consent was given, no identifier exists and nothing was recorded; the link then simply leads to the general page.<\/p>\n<p><script>\n(function () {\n    \/\/ Der Aufruf haengt am Klick, nicht am Laden: mp.js wird asynchron und\n    \/\/ erst hinter dem Einwilligungs-Riegel geladen, ist beim Ausfuehren\n    \/\/ dieses Skripts also in aller Regel noch nicht da. Der feste Verweis\n    \/\/ im href traegt jeden Fall, in dem nichts geladen wurde.\n    var a = document.getElementById('mp-daten');\n    if (!a) { return; }\n    a.addEventListener('click', function () {\n        var u = window.MousePlayer && MousePlayer.privacyUrl && MousePlayer.privacyUrl();\n        if (u) { this.href = u; }\n    });\n})();\n<\/script><\/p>\n<p>Independently of this, requests concerning recordings are answered at the address given in section 1, which is also the operator of MousePlayer. All rights set out in section 12 apply to them without restriction.<\/p>\n<h2>8. Contact form<\/h2>\n<p>The contact form on the start page and beneath the articles transmits the name entered, the e-mail address, the message text and the address of the page from which the form was sent. This last item makes it possible to see which article prompted the enquiry.<\/p>\n<p><strong>Purpose and legal basis:<\/strong> the data are processed solely in order to answer the enquiry. Where the enquiry concerns the initiation or performance of a separately concluded contract, the legal basis is Art. 6(1)(b) GDPR; in all other cases Art. 6(1)(f) GDPR, with the legitimate interest lying in answering the enquiries addressed to the controller.<\/p>\n<p><strong>Storage:<\/strong> submitted messages are stored in a database on the controller&#8217;s own server and are not passed on to anyone.<\/p>\n<p>So that a new enquiry is noticed promptly, a short push notification is sent through the messaging service Telegram. This notification deliberately carries no personal data. It contains the record number of the entry and the page from which the form was sent &ndash; and nothing else: neither the name, nor the e-mail address, nor a single word of the message. Reading an enquiry requires access to the database on the controller&#8217;s own server, so the content never leaves that machine.<\/p>\n<p><strong>Storage period:<\/strong> enquiries are deleted once the matter has been dealt with conclusively and no statutory retention obligation stands against deletion. Where an enquiry becomes part of business correspondence, the retention periods under Polish tax and accounting law apply, which normally amount to five years.<\/p>\n<h3>8.1 Protection against misuse with reCAPTCHA<\/h3>\n<p>The contact form, the comment form below the articles (section 9) and the Toolbox tools with a server component (section 10.2) are protected against automated use by reCAPTCHA v3, a service of Google Ireland Limited. The only exception is the Connection Mirror, which evaluates nothing but the incoming connection itself. reCAPTCHA analyses behaviour in the browser and returns a score between 0 and 1 which expresses how probable it is that a human is acting. Submissions and requests below a score of 0.5 are rejected. For the comment form, the server additionally checks that the token was issued for this form and for a page under lukaswojcik.com.<\/p>\n<p>For this purpose reCAPTCHA processes the IP address, the duration of the stay on the page, mouse and keyboard movements, browser and device information, and it reads and sets cookies of the domain google.com. The check runs invisibly; no images have to be selected. On tool pages, reCAPTCHA is loaded only at the moment a check is started; merely opening a tool page does not include the service. On pages carrying a form &ndash; the start page and every article page &ndash; the service loads together with the page, so that the score is ready when the form is submitted. In doing so it creates the entry <code>_grecaptcha<\/code> in the browser&#8217;s local storage, which is listed in section 4. The server of this website has the score confirmed by Google and transmits only the token generated in the browser, not the IP address. The blog&#8217;s login page, which serves the controller alone, is protected by a reCAPTCHA checkbox from the same service; it loads only there, and here too the server sends Google nothing but the token.<\/p>\n<p><strong>Legal basis:<\/strong> Art. 6(1)(f) GDPR. The legitimate interest lies in protecting the forms and the tools from misuse: without such a check the contact route and the comments would become unusable within a short time, and the tools could be turned against third-party servers in automated fashion. Anyone who does not wish reCAPTCHA to run can reach the controller by e-mail without using a form, and can submit a comment the same way; the tools that run entirely in the browser work without reCAPTCHA.<\/p>\n<h2>9. Comments on blog articles<\/h2>\n<p>Articles in the blog can be commented on. When a comment is submitted, WordPress stores the name entered, the e-mail address entered, the comment text, the time of submission, the IP address and the browser identification string. The IP address and the e-mail address are not published; they serve to combat spam and to allow enquiries in case of legal objections to a comment.<\/p>\n<p><strong>Legal basis:<\/strong> Art. 6(1)(a) GDPR for publication of the comment together with the chosen name, and Art. 6(1)(f) GDPR for storing the IP address and for the spam checks, the legitimate interest lying in defence against abusive entries.<\/p>\n<p><strong>Storage period:<\/strong> comments and the associated data remain stored until the comment is deleted. Entries in the spam folder are moved to the trash after 30 days, and WordPress deletes them permanently from there after a further 30 days. Deletion can be requested informally at any time.<\/p>\n<p><strong>Spam protection:<\/strong> Before it is stored, a comment goes through three checks. A field invisible to humans catches form bots, reCAPTCHA checks as described in section 8.1, and a keyword list on the site&#8217;s own server puts entries with typical spam content in the spam folder instead of the approval queue. Google receives only what reCAPTCHA records in the browser, and from the server only the token; the server passes the name, e-mail address, website, IP address and comment text to no one. A rejected entry is not stored. Every stored comment is held back and published only after review.<\/p>\n<p>So that a new comment is noticed promptly, a short notification goes out via the messaging service Telegram as soon as it is awaiting approval. It contains only the number of the comment and the address of the article, no personal data: neither the name nor the e-mail address nor the comment text.<\/p>\n<h2>10. The Toolbox<\/h2>\n<p>The Toolbox contains a collection of technical tools &ndash; calculators, generators, validators and analysers. Most of them run entirely in the browser (section 10.1). Some check things that cannot be checked in the browser and for that purpose send the input to the server of this website (section 10.2). These tools state on their page what the server does with the input.<\/p>\n<p>The session recording described in section 7 captures the displayed page and would otherwise make readable a result that is meant only for the person in front of the screen. The containers in which the tools display their results are therefore marked in the markup as areas to be masked &ndash; regardless of whether the result was produced in the browser or on the server. Before anything is transmitted, the recording replaces their content character by character. The same marking applies to the chat in section 6.2: its reading of the page text skips these containers. A replay shows that a result appeared and how much room it took &ndash; not what it said. Characters typed into a field are masked in any case.<\/p>\n<p>The search function of the site follows the principle of section 10.1. It loads a prepared index file and searches it locally in the browser. Search terms are not transmitted to the server and are not logged.<\/p>\n<h3>10.1 Tools that run in the browser<\/h3>\n<p>With these tools, values entered are processed in the browser and transmitted to no server. Anyone wishing to verify this can disconnect the network connection after the page has loaded, and these tools continue to work.<\/p>\n<h3>10.2 Tools with a server component<\/h3>\n<p>Some checks need a server: DNS queries, TLS handshakes, fetching a third-party page together with its headers, looking up a code in a music database. Tools of this kind (31 at the time of this version) send the input to the server of this website only after a click; the server runs the check and returns the result. What is processed is the input &ndash; depending on the tool, a domain, an address, an IP address, a DKIM selector, an ISRC, ISWC or barcode, or a Measurement Protocol payload &ndash; and the IP address of the requesting device.<\/p>\n<p><strong>Storage:<\/strong> the input is not stored, and neither is the result or any response from third-party services; both exist only in the answer sent to the browser. For each request, the only thing stored is a counter entry consisting of the IP address, the tool, the time and the size of the request in bytes. That size cannot be turned back into the input; it shows whether someone is using the tools on a mass scale or with unusually large payloads. The entry limits each tool to a fixed number of requests per IP address and hour (between 4 and 30, depending on the tool), so that it cannot be used against third-party servers on a mass scale. Counter entries are deleted after seven days; the deletion job runs every hour, so no entry exists in the database for longer than seven days and one hour. On backups, see section 15. The input does not appear in the log described in section 3 either: the tools send it in the body of the request, and the log records only the path.<\/p>\n<p><strong>Requests to third parties:<\/strong> to carry out a check, the server itself sends requests, under its own identification and from its own address. Depending on the tool, the input is received by:<\/p>\n<ul>\n<li>the servers of the domain or address entered, and in the mail transport check also its mail servers<\/li>\n<li>the public DNS resolvers of Cloudflare (1.1.1.1) and Google (8.8.8.8), through which this server resolves names<\/li>\n<li>rdap.org and the responsible registry, or for registries without RDAP their whois service, for the holder data of a domain or of an IP network<\/li>\n<li>crt.sh (Sectigo Limited) for the certificate logs of a domain<\/li>\n<li>MusicBrainz (MetaBrainz Foundation) for the ISRC, ISWC and barcode lookup<\/li>\n<li>the Google Analytics validation server for the GA4 Measurement Protocol JSON Validator, unless this check is deselected; placeholders are sent instead of access credentials, but the payload itself goes out as entered &ndash; including any real identifiers such as <code>client_id<\/code> or <code>user_id<\/code><\/li>\n<\/ul>\n<p>None of these recipients receives the IP address of the requesting device &ndash; except in the case of the Connection Mirror, where that very address is what the check is about: there it goes to the DNS resolvers for the host name and, after a click on the button for the network holder, to rdap.org and the responsible registry.<\/p>\n<p><strong>Connection Mirror:<\/strong> the tool shows what a web server learns about a connection before a single line of JavaScript runs: the IP address the request comes from, its address family, the request headers and the parameters of the encrypted connection. Every web server knows this IP address anyway, because it could not otherwise reply; the Mirror merely makes it visible. The host name is looked up by reverse DNS through the DNS resolvers named above. For a private address, that is skipped as well.<\/p>\n<p>The <strong>network holder<\/strong> is recorded in the database of a Regional Internet Registry. For European addresses that is the RIPE NCC in Amsterdam, hence within the European Union; for other address ranges it is ARIN in the United States, APNIC in Australia, LACNIC in Uruguay or AFRINIC in Mauritius. Depending on where the address comes from, the query therefore reaches a country without an adequacy decision, and for that reason it <strong>does not happen by itself<\/strong>: at this point the tool shows a button and, next to it, a note saying where the address goes. Only a click on it triggers the query &ndash; through rdap.org, which forwards to the responsible registry. The click is at the same time the explicit consent under Art. 49(1)(a) GDPR, in so far as the responsible registry sits outside the European Union; with the RIPE NCC there is no third-country transfer at all. Without that click, the address leaves the server for the reverse DNS lookup only. Cookie values and authorisation data are never returned. Here too, only the counter entry is stored. The Crawler IP Verifier looks up the same details for the address someone enters there &ndash; not for that of the requesting device; what leaves the server is the address typed in.<\/p>\n<p><strong>Legal basis:<\/strong> Art. 6(1)(f) GDPR. The legitimate interest lies in carrying out the check that was actively requested and, as regards the counter entry with its size figure, in protecting the tools and third-party servers from mass automated use. Where a transfer to a country without an adequacy decision is involved, the explicit consent under Art. 49(1)(a) GDPR is added, as with the network holder in the Connection Mirror. The recipients and the basis are set out in section 11.<\/p>\n<h3>10.3 Tools with Google sign-in<\/h3>\n<p>Seven tools are an exception, because their purpose is to read data out of a Google account:<\/p>\n<ul>\n<li><strong>GTM Container History Deep Search Engine<\/strong> &ndash; scope <code>tagmanager.readonly<\/code><\/li>\n<li><strong>GA4 PII Checker<\/strong> &ndash; scope <code>analytics.readonly<\/code><\/li>\n<li><strong>GA4 Anomaly Detector<\/strong> &ndash; scope <code>analytics.readonly<\/code><\/li>\n<li><strong>GA4 Bot Detector<\/strong> &ndash; scope <code>analytics.readonly<\/code><\/li>\n<li><strong>GA4 Advisor &amp; runReport Verifier<\/strong> \u2013 scopes <code>analytics.readonly<\/code>, <code>analytics.chatbot.read<\/code><\/li>\n<li><strong>Acquisition Audit in the GA4 Channel Debugger<\/strong> \u2013 scope <code>analytics.readonly<\/code><\/li>\n<li><strong>GA4 Property Configuration &amp; Snapshot Comparator<\/strong> \u2013 scope <code>analytics.readonly<\/code><\/li>\n<\/ul>\n<p>These tools request a temporary access token through Google&#8217;s sign-in dialogue. The requested permissions are read-only in every case; none of these tools can change, create or delete anything in a Google account.<\/p>\n<p class=\"lw-legal-hinweis\"><strong>Limited Use disclosure.<\/strong> The use and transfer of information received from Google APIs by these tools adheres to the <a href=\"https:\/\/developers.google.com\/terms\/api-services-user-data-policy\" rel=\"noopener nofollow\" target=\"_blank\">Google API Services User Data Policy<\/a>, including its Limited Use requirements. In concrete terms: the access token and the retrieved data remain in the browser. They are not sent to the server of this website. The website operator does not retain them, disclose them to other recipients, use them for advertising or use them to train models. The direct processing by Google needed for API requests, including the Advisor chat described below, remains separate from this commitment. The token expires by itself and is gone at the latest when the browser tab is closed.<\/p>\n<p><strong>GA4 Advisor &amp; runReport Verifier.<\/strong> Login loads after an explicit click. The browser sends the selected property, periods, metric and dimension as a question to Google&#8217;s Analytics Advisor and retrieves comparison reports directly from Google. Follow-up questions are also sent to Google. Access tokens, session identifiers and results stay in the tab&#8217;s memory; the tool uses no backend proxy, token cookies or persistent browser storage. Disconnecting clears the local token and results but does not revoke the permission in the Google account. Tracking, session replay and reactive.chat are disabled on this tool page. Normal page-access logs remain. An own OAuth client can be entered instead of the prefilled public client; this does not eliminate processing by Google. According to <a href=\"https:\/\/developers.google.com\/analytics\/devguides\/reporting\/data\/v1\/rest\/v1alpha\/properties\/chat\" target=\"_blank\" rel=\"noopener nofollow\">Google&#8217;s documentation<\/a>, chat activity may be used to improve the product. The AI response can be inaccurate. This tool does not request the <code>cloud-platform<\/code> scope.<\/p>\n<p><strong>Legal basis:<\/strong> Art. 6(1)(f) GDPR, as for the other tools: the legitimate interest lies in providing the function that was actively requested. No contract arises in doing so, as section 2 of the Terms of Service states. The permission granted can be withdrawn at any time in the Google account settings at <a href=\"https:\/\/myaccount.google.com\/permissions\" rel=\"noopener nofollow\" target=\"_blank\">myaccount.google.com\/permissions<\/a>.<\/p>\n<p><strong>Acquisition Audit and configuration snapshots.<\/strong> These two functions also use direct browser requests to Google with read-only authorization. The acquisition audit retrieves session acquisition reports; the configuration comparator retrieves a defined set of property settings, retention settings, streams, custom definitions and key events. Neither uses an AI service. Configuration snapshots can be downloaded as JSON and later compared locally without login. API secrets are not requested. Tracking, session replay and chat are disabled on these tool pages.<\/p>\n<p><strong>Local file comparison.<\/strong> The Shop vs. GA4 Revenue Reconciliation tool reads CSV files only in the browser, without uploading their contents or requesting Google access. It compares order IDs, amounts and currencies. Snapshot and CSV inputs remain in tab memory until cleared or the page is left; explicitly downloaded files remain on the device until deleted there. Tracking, session replay and chat are disabled on the reconciliation page. Normal website access logs are unaffected.<\/p>\n<p><!-- lw-collect-privacy --><\/p>\n<p><strong>Local Collect request analysis.<\/strong> The GA4 Parameter Analyser processes pasted request URLs and query\/body strings only in the tab. Requests are not replayed or uploaded. Tracking, session replay and chat are disabled on this tool page. Inputs and results are cleared when the page is left or the clear button is used; downloads remain on the device. CSV exports contain decoded input values and are not anonymized. Normal website access logs remain unchanged.<\/p>\n<p><!-- lw-anomaly-privacy --><\/p>\n<p><strong>GA4 Anomaly Detector.<\/strong> Google login is loaded only after a click. Daily aggregate report values are retrieved directly from Google using analytics.readonly and compared in the browser. Tokens and results remain in tab memory and are cleared on disconnect, client change or leaving the page. CSV downloads remain on the device. Tracking, session replay and chat are disabled on this tool page; normal website access logs remain. No AI service or background alert delivery is used.<\/p>\n<p><!-- lw-items-privacy --><\/p>\n<p><strong>E-Commerce Item Array Validator:<\/strong> pasted product arrays are checked locally in the browser tab without a Google login or upload. The tool does not store the input or results in cookies or browser storage. Clearing the form or leaving the page clears these values; downloaded JSON reports remain on the device. Tracking, session recording and chat are disabled on this tool page. Normal server access logs still record page requests.<\/p>\n<p><!-- lw-traffic-privacy --><\/p>\n<p><strong>GA4 Bot Detector \/ traffic review:<\/strong> Google login loads only on click. Read-only reports pass directly between the browser and Google. Tokens and reports remain in tab memory; disconnecting, changing the client ID or leaving the page clears them. CSV downloads remain on the device. No bot classification is sent to Google, and no Analytics data is changed. Tracking, session recording and chat are disabled on these tool pages; normal server access logs remain.<\/p>\n<h2>11. Recipients of the data<\/h2>\n<p>Data are only passed on where this is necessary for the purposes described above. The recipients are:<\/p>\n<table>\n<thead>\n<tr>\n<th>Recipient<\/th>\n<th>Purpose<\/th>\n<th>Location<\/th>\n<th>Basis for transfer<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Google Ireland Limited \/ Google LLC<\/td>\n<td>Analytics, Tag Manager, reCAPTCHA for the contact form, the comment form and the tools, API access for seven tools, including Analytics Advisor queries<\/td>\n<td>Ireland \/ USA<\/td>\n<td>EU&ndash;US Data Privacy Framework, standard contractual clauses<\/td>\n<\/tr>\n<tr>\n<td>Google LLC (Google Drive)<\/td>\n<td>Storage of the daily encrypted database backup that includes the MousePlayer recordings; the keys do not leave the controller<\/td>\n<td>USA \/ worldwide<\/td>\n<td>EU&ndash;US Data Privacy Framework, standard contractual clauses<\/td>\n<\/tr>\n<tr>\n<td>Google LLC (Google Public DNS, Measurement Protocol validation server)<\/td>\n<td>Name resolution for the tools with a server component, including reverse DNS of IP addresses (Connection Mirror, Crawler IP Verifier); validation of a payload entered<\/td>\n<td>USA<\/td>\n<td>EU&ndash;US Data Privacy Framework<\/td>\n<\/tr>\n<tr>\n<td>Cloudflare, Inc.<\/td>\n<td>Name resolution for the tools with a server component, including reverse DNS of IP addresses (Connection Mirror, Crawler IP Verifier); Cloudflare also sits in front of rdap.org<\/td>\n<td>USA<\/td>\n<td>EU&ndash;US Data Privacy Framework<\/td>\n<\/tr>\n<tr>\n<td>rdap.org<\/td>\n<td>Forwarding of an RDAP query to the responsible registry (Domain RDAP &amp; CT Lookup, Crawler IP Verifier; Connection Mirror only after a click on the button for the network holder)<\/td>\n<td>United Kingdom<\/td>\n<td>Adequacy decision of the European Commission; for one&#8217;s own address in the Connection Mirror, the consent in addition<\/td>\n<\/tr>\n<tr>\n<td>Registry of the domain or IP address looked up<\/td>\n<td>Holder data of a domain (Domain RDAP &amp; CT Lookup) or of an IP network (Crawler IP Verifier; Connection Mirror only after a click); what is transmitted is the entry looked up and nothing else<\/td>\n<td>Depending on the domain ending or address range; for European IP addresses the RIPE NCC in the Netherlands, otherwise ARIN (USA), APNIC (Australia), LACNIC (Uruguay) or AFRINIC (Mauritius)<\/td>\n<td>For a domain or address entered, no data of the requesting device leaves the server. In the Connection Mirror: within the EU (RIPE NCC) no third-country transfer, otherwise the explicit consent under Art. 49(1)(a) GDPR given by the click<\/td>\n<\/tr>\n<tr>\n<td>Sectigo Limited (crt.sh)<\/td>\n<td>Certificate logs of a domain entered<\/td>\n<td>United Kingdom<\/td>\n<td>Adequacy decision of the European Commission<\/td>\n<\/tr>\n<tr>\n<td>MetaBrainz Foundation (MusicBrainz)<\/td>\n<td>Lookup of an ISRC, ISWC or barcode entered<\/td>\n<td>USA<\/td>\n<td>No personal data: only the code is transmitted<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Beyond this, data are only disclosed where a legal obligation to do so exists. Personal data are never sold, and they are never made available to advertising networks or data brokers.<\/p>\n<h2>12. Rights of the persons concerned<\/h2>\n<p>Every person whose personal data are processed has the following rights under the GDPR:<\/p>\n<ul>\n<li><strong>Access<\/strong> (Art. 15 GDPR) &ndash; confirmation of whether data are being processed, and a copy of them<\/li>\n<li><strong>Rectification<\/strong> (Art. 16 GDPR) &ndash; correction of inaccurate data and completion of incomplete data<\/li>\n<li><strong>Erasure<\/strong> (Art. 17 GDPR) &ndash; deletion, provided no retention obligation stands against it<\/li>\n<li><strong>Restriction of processing<\/strong> (Art. 18 GDPR) &ndash; a stop on processing while a matter is being clarified<\/li>\n<li><strong>Data portability<\/strong> (Art. 20 GDPR) &ndash; receipt of the data in a structured, machine-readable format<\/li>\n<li><strong>Objection<\/strong> (Art. 21 GDPR) &ndash; objection to processing based on Art. 6(1)(f) GDPR, on grounds arising from the particular situation of the person concerned<\/li>\n<li><strong>Withdrawal of consent<\/strong> (Art. 7(3) GDPR) &ndash; withdrawal at any time, with effect for the future<\/li>\n<\/ul>\n<p>These rights can be exercised informally by e-mail to <a href=\"mailto:contact@lukaswojcik.com\">contact@lukaswojcik.com<\/a>. A reply follows within one month; where a request is complex, this period may be extended by two further months, in which case notification is given.<\/p>\n<h2>13. Right to lodge a complaint<\/h2>\n<p>Independently of any other remedy, a complaint may be lodged with a supervisory authority. The authority responsible for the controller is:<\/p>\n<p class=\"lw-legal-adresse\">Prezes Urz&#281;du Ochrony Danych Osobowych (UODO)<br \/>\nul. Stawki 2<br \/>\n00-193 Warszawa, Poland<br \/>\n<a href=\"https:\/\/uodo.gov.pl\/\" rel=\"noopener nofollow\" target=\"_blank\">uodo.gov.pl<\/a><\/p>\n<p>A complaint may equally be lodged with the supervisory authority of the place of residence or of the place where the alleged infringement occurred. For persons in Germany this is the data protection authority of the respective federal state, for persons in Austria the Datenschutzbeh&ouml;rde in Vienna.<\/p>\n<h2>14. Obligation to provide data, automated decision-making<\/h2>\n<p>There is no legal or contractual obligation to provide personal data. The entries in the contact form and in the comment function are voluntary; without them, however, an enquiry cannot be answered and a comment cannot be published.<\/p>\n<p>Automated decision-making within the meaning of Art. 22 GDPR does not take place. The reCAPTCHA score described in section 8.1 decides only whether a form submission or a tool request is accepted, not about any matter of legal effect; a rejected submission can be sent by e-mail at any time instead.<\/p>\n<h2>15. Data security and backups<\/h2>\n<p><strong>Backups:<\/strong> an encrypted copy of the database is created daily and stored with Google Drive; encryption happens before the transfer, and the keys never leave the controller (section 7.8). A copy covers every table, including those named in this policy. A deleted record can therefore persist there for a while: daily copies are deleted after 7 days, weekly copies after one year. A backup is restored only after a loss of data.<\/p>\n<p>The entire site is delivered exclusively over TLS-encrypted connections; unencrypted requests are redirected. A Content Security Policy limits which origins the browser may contact, which considerably reduces the effect of injected scripts. Access data for the database and for external services are held outside the web directory and appear in no source file that is delivered. The administration area is protected by additional access checks.<\/p>\n<h2>16. Changes to this policy<\/h2>\n<p>This policy is amended whenever a change in the services used or in the legal position requires it. The version currently in force is always the one retrievable here. A substantial change raises the main version number. The start page may point it out for a limited period. The current version number and the date on which it took effect appear at the top of this page.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Version 3.6 &middot; in force since 28 September 2026 This policy describes which personal data are processed when the website www.lukaswojcik.com is used, on what legal basis this happens, how long the data are kept and which rights the persons concerned have. It follows Regulation (EU) 2016\/679 (GDPR) and the Polish Act on the Protection [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"tags":[],"class_list":["post-12333","page","type-page","status-publish","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Privacy Policy | Lukas Wojcik<\/title>\n<meta name=\"description\" content=\"How data are handled on lukaswojcik.com: self-hosted server, logs deleted after 14 days, analytics only after consent, tools that compute in the browser.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.lukaswojcik.com\/blog\/en\/privacy-policy\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Privacy Policy | Lukas Wojcik\" \/>\n<meta property=\"og:description\" content=\"How data are handled on lukaswojcik.com: self-hosted server, logs deleted after 14 days, analytics only after consent, tools that compute in the browser.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.lukaswojcik.com\/blog\/en\/privacy-policy\/\" \/>\n<meta property=\"og:site_name\" content=\"Lukas Wojcik - Blog\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-28T15:11:48+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/08\/og-default.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"34 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/privacy-policy\\\/\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/privacy-policy\\\/\",\"name\":\"Privacy Policy | Lukas Wojcik\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#website\"},\"datePublished\":\"2026-08-19T16:31:24+00:00\",\"dateModified\":\"2026-09-28T15:11:48+00:00\",\"description\":\"How data are handled on lukaswojcik.com: self-hosted server, logs deleted after 14 days, analytics only after consent, tools that compute in the browser.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/privacy-policy\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/privacy-policy\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/privacy-policy\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Privacy Policy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/\",\"name\":\"Lukas Wojcik - Blog\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\",\"name\":\"Lukas Wojcik\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"contentUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"width\":424,\"height\":636,\"caption\":\"Lukas Wojcik\"},\"logo\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\"},\"sameAs\":[\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Privacy Policy | Lukas Wojcik","description":"How data are handled on lukaswojcik.com: self-hosted server, logs deleted after 14 days, analytics only after consent, tools that compute in the browser.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.lukaswojcik.com\/blog\/en\/privacy-policy\/","og_locale":"en_US","og_type":"article","og_title":"Privacy Policy | Lukas Wojcik","og_description":"How data are handled on lukaswojcik.com: self-hosted server, logs deleted after 14 days, analytics only after consent, tools that compute in the browser.","og_url":"https:\/\/www.lukaswojcik.com\/blog\/en\/privacy-policy\/","og_site_name":"Lukas Wojcik - Blog","article_modified_time":"2026-09-28T15:11:48+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/08\/og-default.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"34 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/privacy-policy\/","url":"https:\/\/www.lukaswojcik.com\/blog\/en\/privacy-policy\/","name":"Privacy Policy | Lukas Wojcik","isPartOf":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/#website"},"datePublished":"2026-08-19T16:31:24+00:00","dateModified":"2026-09-28T15:11:48+00:00","description":"How data are handled on lukaswojcik.com: self-hosted server, logs deleted after 14 days, analytics only after consent, tools that compute in the browser.","breadcrumb":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/privacy-policy\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.lukaswojcik.com\/blog\/en\/privacy-policy\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/privacy-policy\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.lukaswojcik.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Privacy Policy"}]},{"@type":"WebSite","@id":"https:\/\/www.lukaswojcik.com\/blog\/#website","url":"https:\/\/www.lukaswojcik.com\/blog\/","name":"Lukas Wojcik - Blog","description":"","publisher":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.lukaswojcik.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9","name":"Lukas Wojcik","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","url":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","contentUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","width":424,"height":636,"caption":"Lukas Wojcik"},"logo":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg"},"sameAs":["https:\/\/www.lukaswojcik.com\/blog"]}]}},"_links":{"self":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/pages\/12333","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/comments?post=12333"}],"version-history":[{"count":17,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/pages\/12333\/revisions"}],"predecessor-version":[{"id":20823,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/pages\/12333\/revisions\/20823"}],"wp:attachment":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/media?parent=12333"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/tags?post=12333"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}