🔒 Privacy Policy
Last updated: 7 August 2026
This is a personal website. I'm not selling anything, I'm not running ads, and I'm not building a profile of you. There's no analytics script, tracking pixels, advertising cookies, or anything of the like anywhere on diaduck.xyz.
That said, a few things do involve your data, so here's the honest rundown of it all.
Why does a personal website even have one of these? The guestbook, mostly. The moment I started publishing other people's names, avatars, messages, and personal websites out to the whole internet, I stopped being someone with a hobby site and became what UK and EU law calls a data controller -- the "it's just a personal thing" exemption doesn't stretch to broadcasting someone else's details to an indefinite audience. That comes with an obligation to tell you plainly what I collect and why. Hence this page.
🧑 Who's responsible
Dia, running diaduck.xyz from Manchester, UK. You can reach me at dia@diaduck.xyz about anything on this page including asking me to delete your data.
🌐 Just browsing
The site is hosted on Cloudflare Workers. Like any web host, Cloudflare handles the technical details of your request -- your IP address and browser user-agent, as well as which page you asked for -- to actually serve the page and to protect the site from abuse. I don't store those logs myself, and I don't have a dashboard of who visited what.
I don't set any analytics or tracking cookies. If you never touch the guestbook, this site sets no cookies at all.
📖 The guestbook
The guestbook is the only part of the site where I deliberately collect and keep anything. There are two ways to sign it.
Signing with Discord
If you sign in with Discord, I ask Discord only for the identify scope. From that I store:
- Your Discord user ID (used to stop the same account signing twice)
- Your username and display name
- Your avatar image URL
- The message you wrote, and the date you wrote it
All of that except the raw ID is shown publicly on the homepage, as per the point of a guestbook. Entries live in Cloudflare KV storage, with a copy on my machine as backup.
I never see, receive, or store your Discord password, email, or access token. The OAuth token is used once, server-side, to read your public profile and is then discarded.
While you're mid-signature there's one cookie: gb_session. It holds only the profile details above, is HttpOnly and Secure, and expires after 10 minutes (or immediately once you've signed). It's strictly necessary to make the form work, it isn't used for tracking.
Signing by email form
If you use the email form instead, I collect your display name, email address, message, and optionally a website and avatar URL. These go into a pending queue that I review by hand.
- Your email address is never published. It exists so I can reply to you about your entry, to check something, or to tell you it's live. I don't add it to any mailing list, because I don't have one. (yet!)
- Your name, message, website, and avatar are published once I approve the entry.
- If you give an avatar URL, I download that image and re-host it on my own site rather than hot-linking it, so your server never sees my visitors and vice versa.
- If I reject an entry, I delete the submission -- email included.
How long it's kept
Guestbook entries are meant to stick around indefinitely, it's a scrapbook! But it's your entry: email me and I'll remove it, no questions asked and no explanation needed.
💬 Webmentions
Blog posts use webmentions via webmention.io, a third-party service. When you view a blog post, your browser fetches that post's mentions from webmention.io, so that service sees your IP address and request. Their privacy practices are their own.
If you send a webmention, or if Brid.gy forwards a like or reply you made on Bluesky or Mastodon, then your name, avatar, post content, and the URL you posted from get displayed publicly on my post. Ask and I'll remove any of it from my site, though I can't remove it from the original network or from webmention.io.
🔗 Other people's stuff
A few pages load or link to things I don't run. When your browser loads one of these, that company sees your IP address:
- timeanddate.com -- the little clock embedded on the contact page
- Discord's CDN -- avatar images on Discord-signed guestbook entries
- webmention.io -- as described above
- SubToMe -- only if you click the RSS button on the contact page, which loads their script on demand
Ordinary links out to GitHub, Twitter, Twitch, Last.fm, Bluesky and friends don't load anything until you actually click them. Once you're there, you're under their privacy policy, not mine.
⚙ Your rights
Under UK GDPR supplemented by the Data Protection Act 2018 you can ask me to show you what I hold about you, correct it, delete it, or stop using it. In practice that's a short list - a guestbook entry, or an email you sent me - and the way to exercise any of it is the same: email me. I'll sort it out, and I won't make you jump through hoops.
My lawful basis is consent when you choose to sign the guestbook or email me, and legitimate interests for keeping the site online and secure. If you're unhappy with how I've handled it, you can complain to the ICO, though I'd rather you just told me first so I can fix it.
🐣 Kids
This site isn't aimed at children under 13, and I don't knowingly keep data from them. If a child has signed the guestbook and you'd like it gone, email me and it's gone.
📝 Changes
If I add something to the site that changes any of this, I'll update this page and the date at the top. There's no explicit edit history as of writing.
Questions? dia@diaduck.xyz. 🦆