Phaeacia

§ / Privacy

Last changed 2026-09-13. This applies to phaeacia.ai only; the product at app.phaeacia.ai has its own notice.

Privacy

This site has no cookies, no accounts and no tracking script, so there is nothing to consent to and no banner asking you to. Its server counts page requests without identifying anyone, and the first section says exactly what that record holds. One page reaches one other company: the signup form on the front page loads a bot check, and only if you open it. Below is the whole of it, in the order that matters.

What is collected when you read this page

A count, and nothing about you. When your browser asks for a page, our server records that a request happened: the UTC date, the path of the page, and the host name of the site the link came from, if there was one. That is the whole record. It holds no IP address, no browser signature, no cookie and no identifier of any kind, so two requests from one person look exactly like one request each from two people, and nothing can join them up later. If your browser sends the Do Not Track or Global Privacy Control signal, the request is not counted at all.

The counts live in our hosting account at Netlify, in the same place as the site itself. A report reads them each morning to tell us how many pages were opened and from where. Raw entries are deleted after 45 days; the daily totals are kept.

Nothing else. No cookie is set, first party or third. No analytics script runs in your browser. No pixel, tag, session recorder or A/B tool is present, and nothing on the page reports how far you scrolled or what you did on it.

The fonts are served from this domain. They are not fetched from Google or any other font host, which would otherwise hand a third party your address and the page you were reading. On a site whose product argument is about consent, that request would be a contradiction.

This site stores nothing in your browser

No cookie, no localStorage entry and no session storage, on any page. The site does not record your appearance settings or browsing preferences.

A key named phaeacia-theme may still be sitting in your browser, unread. A theme control on this site wrote it until 2026-08-09, and the sample passport page went on writing it, with no control on the page to set it, from 2026-08-10 until 2026-08-18. That was a copy of the app's script arriving with the sample, it recorded nothing about anybody, and it is gone. Nothing here writes or reads that key now; clearing site data for this domain removes it.

The one thing you can send

The access form takes an email address. Submit it after the script that handles this form has run, and it is used for two things: a reply about the current state of the build, and a follow-up if you answer that reply. It does not come to rest in one place, and the paragraphs below name every place it does. That script does not always run, for one of several reasons, such as JavaScript being off, the script being blocked by an extension or a network filter, or the form being submitted before it finishes loading. In any of those cases none of that happens; see below for what does instead.

  • It is not sold, rented or shared for anyone else's marketing.
  • It is not added to a newsletter or any list you did not ask for.
  • There is no queue and no waiting list to be prioritised in.
  • It is kept while there is a reason to answer you and while you want the updates, reviewed at least once a year and deleted when neither is true. Ask for deletion sooner at hello@phaeacia.ai and it goes from the list and from the mailbox it was emailed to. The one thing that outlasts it is Resend's own record of the messages it has already delivered, which it keeps under its retention rather than ours.

Submitting the form after the script that handles it has run sends your address to a small program on Netlify, which does three things and nothing else: it emails you a confirmation, it emails that address to us so we can answer you, and it adds you to a list held at Resend, which is what the occasional update is sent from.

So it ends up in three places: the list at Resend, Resend's own record of the two messages it sent, and the mailbox those messages arrive in, which is Google Workspace. If one of those steps fails, the program also writes the address into its log at Netlify, which the section on server logs describes. All three companies act on instruction only and none is permitted to use your address for anything of their own.

If that script did not run, for one of several reasons (JavaScript is off, the script was blocked by an extension or a network filter, or the form was submitted before it finished loading), the form still submits, because that is what a form does regardless. It goes instead to a different, much smaller program on Netlify. The request still carries the address as far as Netlify, since that is how a submission physically travels, but the handler never reads it: it checks only that the request is a POST and answers with a redirect to a page explaining what happened. Nothing in our code stores, logs or forwards the address in that case, because nothing in our code reads it. None of the three things above happen: no confirmation, no notification to us, no addition to any list.

The scripted signup path is rate limited by Netlify on our behalf, counted per IP address so that nobody can flood it. It refuses shortly after a burst begins rather than at an exact count, which is worth saying plainly because the number in our configuration reads like a hard cap and does not behave as one. The counting happens inside Netlify; we neither see it nor keep it. The fallback path above carries no rate limit of its own.

Every update carries an unsubscribe link. Using it stops the updates and leaves your address on a suppression list, which exists so that unsubscribing sticks; ask for deletion instead and both go, on the terms in the bullet above.

The bot check on the signup form

The signup form on the front page is the only thing on this site that can send us anything, and until 2026-09-01 anyone could post to it as fast as they liked. It now runs Cloudflare Turnstile, a check that the thing filling in the form is a person. Cloudflare is the only other company this site reaches, and that form is the only thing that reaches it. It loads from challenges.cloudflare.com, on the front page only, and only once you open the signup box. Read every page without opening it and nothing of yours reaches anyone but this domain. That is the path this section describes, and it depends on the script that handles the form having run. If it did not, the form takes a different path, with no Turnstile check and no rate limit of its own, described in the section above, which is safe for a different reason: nothing on our side reads what you typed.

What that costs you, plainly: your browser contacts Cloudflare, which means Cloudflare receives your IP address and can run its check in your browser. What we receive back and send on is one opaque token and nothing else. Our server does not pass your address, your IP or anything you typed to Cloudflare. Cloudflare's own statement about Turnstile is that it does not access, store or transmit form entries or other page inputs; that is their claim about their product rather than something this page can verify for you.

What this page is permitted to fetch from them is narrow and you do not have to take our word for it. The security policy this site sends with every page names challenges.cloudflare.com for a script and for a frame, and for nothing else. It does not open a data channel: the policy still says connect-src 'self', so this page cannot send anything to Cloudflare or to any other outside host, and your browser enforces that rather than trusting us to. You can read the policy in the response headers of this page.

And the degradation, because it is real: if the script that handles this form has run but the check does not finish, whether because your browser cannot reach challenges.cloudflare.com or because it loaded and refused, the form will tell you so and will not submit. Nothing leaves your browser in that case and no address is stored. If that script did not run at all, see the section above for what happens instead: the form submits natively and the address reaches Netlify, but nothing on our side reads it. Writing to the address at the foot of this page reaches the same person and always will.

Server logs

The site is static and is served by Netlify, which is where your browser connects and where the connection ends. Netlify keeps ordinary request logs containing an IP address, a timestamp, the path requested and a user agent, kept under their retention policy for the plan this site runs on, and they exist to run and defend the server. They are not joined to anything else, profiled, or used to work out who you are. Nothing on this site adds to them, and nothing here reads them. The page count in the first section is a separate record, kept by us rather than by Netlify's logging, and it is the one that holds no address.

Cloudflare is this domain's registrar and runs its DNS, and that is the whole of it: it answers the lookup that tells your browser where phaeacia.ai is, and your browser then connects to Netlify. It never receives your request for a page. It does keep a log of the DNS lookups it answers, which records the name asked for, the record type, the response code, a timestamp, which of its data centres answered, the transport, and the source and destination addresses. The source address there is the resolver that asked on your behalf, not yours: the busiest sources in this domain's own log are large public resolvers. A query log is also a record of what was asked rather than a list of what exists, since it records lookups for names that were never here.

One qualification, because the list above is closed and a closed list invites a conclusion it has not earned. Some resolvers, Google's public one by default, attach a shortened piece of your address to the query they pass on; the standard is called EDNS Client Subnet. Whether Cloudflare's nameservers keep that is a fact about their systems, not ours, and this page will not tell you either way rather than guess in the direction that flatters us.

One thing does write a log of its own, and it is the form on the front page. If your confirmation cannot be sent, if we cannot be notified, or you cannot be added to the list, the code behind that form records what failed and the address it was handling. That is a separate log from the request logs above, held by Netlify in the same way and for the same kind of period, and it exists so that a signup which did not arrive can be found and answered by hand rather than quietly lost. Nothing else on this site writes an address anywhere.

The product is a different address

Agent Passports run at app.phaeacia.ai, which handles real content: passport files, the pages they produce, and the links that reach them. That site has its own notice, and this one does not describe it. What holds on both sides is the product rule: a passport names credential types and never credential values, so no token, key or password reaches either service.

Who is responsible

The controller is Raffael Hueberli, St. Gallen, Switzerland, reachable at hello@phaeacia.ai.

The basis for holding your address is your consent, given when you submitted the form, and you can withdraw it at any time by asking or by using the unsubscribe link in any update. Withdrawing does not affect anything sent before you did. Four processors act on instruction: Netlify, which serves the site and runs the form's endpoints, Resend, which holds the list and sends the mail from its European region, Google, whose Workspace holds the mailbox your address is emailed to, and Cloudflare, which runs this domain's DNS and the bot check on the signup form. All four are companies with United States parents.

Your rights

Under Swiss data protection law and the GDPR you may ask what is held about you, ask for it to be corrected, ask for a copy, and ask for it to be erased. You may also complain to a supervisory authority: in Switzerland that is the Federal Data Protection and Information Commissioner, and in the EU it is the authority where you live. The honest version of that here is short. The one thing you gave us is the email address you typed in, and asking removes it from every place named above. The request logs are the other thing held about you: they carry an IP address, they belong to Netlify rather than to us, and we neither join them to anything nor read them to work out who you are. Write to hello@phaeacia.ai and it is answered without a process.

Changes

If this changes, the date in the margin changes with it. A change that widens what is collected will be described in the text rather than absorbed quietly, and nothing collected under this version is repurposed under a later one.

Two claims on this page are checkable rather than promised, and one of them now has an exception you can check too. Open the network panel and reload any page here, including the front page: every request should be to this domain. Then open the signup box on the front page, and exactly one other host should appear, challenges.cloudflare.com, and no other. What this page is allowed to fetch from it is a script and a frame: everything else stays shut, because the policy this site sends with every page still reads connect-src 'self', so the page cannot open a data channel to Cloudflare or to anybody else. A browser asked to would refuse out loud in your console rather than quietly. Open storage: there should be nothing at all, on any page. The theme key that used to be the one exception went with the theme control on 2026-08-09.