ply.wtf

Privacy

Short version: no tracking cookies, no advertising profile, no analytics that follow you around. The tools on this site never send your data anywhere, and the comment system runs on my own server.

The tools

The case converter, text diff, hash generator and epoch converter run entirely in your browser. Whatever you paste into them stays on your machine — it is never transmitted, logged or stored. You can verify this by disconnecting from the network: they keep working.

The one exception is the MD5 reverse lookup, which has to ask the server. In that case only the 32-character hash is sent — never the text you typed. The request is not logged with your IP address.

Analytics

I use a self-hosted, cookieless analytics tool that records aggregate page views, referrers and rough country. It sets no cookies, assigns no persistent identifier, and cannot follow you to other sites. No consent banner is required for it, which is precisely why I chose it.

Advertising

Some pages carry ads from EthicalAds. They are contextual: the ad is chosen from the content of the page you are reading, not from anything about you. No cookies, no tracking pixels, no profile, no data sold to anyone.

I turned down the obvious alternative — the large ad network everyone uses — because it would have meant profiling cookies and a consent banner. Given what I say about privacy elsewhere on this site, that felt like a contradiction I'd rather not sell for a few euros a month.

Comments

Comments are handled by Remark42, which runs on my own server. No third-party comment service is involved, nothing is sent to an external company, and there are no tracking scripts inside the widget.

The comment widget does not load unless you click "Load comments". If you read an article and never click, no request to the comment system is made at all.

What is stored when you post a comment:

  • The text of your comment, which is public.
  • The name you chose to display. You can comment anonymously — no account is required.
  • A timestamp, and which page you commented on.
  • A hashed form of your IP address, used to let you edit or delete your own comment shortly after posting, and to limit spam. It is not stored in plain text.

This data sits in a local database on the same server as the site. It is never sold, shared or used to build a profile. If you want a comment removed, delete it yourself orask me and I will.

Bear in mind that a comment is public and search engines will index it. Don't put anything in one you wouldn't put on a postcard.

The contact form

What you type is emailed to me and nothing else: no database, no CRM, no mailing list. Your address is used to reply to you and for nothing further.

The form is protected by Cloudflare Turnstile, a captcha that verifies you are human without the behavioural tracking of the alternatives, and by a rate limit that temporarily stores your IP address in memory to count requests. That counter is not written to disk and disappears when the server restarts.

Server logs

The web server keeps standard access logs (IP address, timestamp, page, user agent) for security and debugging. They rotate automatically and are not used for analytics or shared with anyone.

Your rights

Under the GDPR you can ask what data I hold about you, request a copy, or ask for it to be deleted. Since the only thing I could realistically hold is an email you sent me, this is usually a very short conversation — just ask.

Changes

If this policy changes in a way that matters, the change goes here. It is not going to quietly grow a section about advertising partners.