I run this blog myself. There's no analytics company watching you, no ad network, and nobody buying data off me. A few parts of the site do collect things, though, and you should be able to read what they are without a law degree.
Here's all of it, surface by surface.
Last updated 13 September 2026.
Booking a call
When you book a call I ask for your name, your email, and optionally a note about what it's for. I also record the time zone your browser reports, the IP address you connect from, and, if you came from the advisor page's "Book a call" button, the fact that you did.
Your name and note go into a Google Calendar event on my calendar, because that's the invite you'll receive. Google sends you that invite and creates the Meet link. Your email is how the confirmation reaches you, and it's the address on the invite.
The link that lets you move or cancel is stored as a one-way hash. The real link exists only in your email, which means I can't look yours up, and a copy of my database doesn't contain a working link to anybody's booking.
The IP address is there to stop one person booking fifty calls.
Comments
Comments store the name you give, your email, what you wrote, your IP address, and your browser's user agent string.
Your email is never shown. It's used to recognize you across comments and to keep banned addresses out. I don't send you anything with it.
The newsletter
Your email address. Nothing gets sent until you click the confirmation link, and every email after that has an unsubscribe link that works immediately.
One thing worth saying because most newsletters don't: I can see whether you opened a given email and whether you clicked a link in it. Resend reports that back and I store it against your address. It's how I tell whether an issue landed at all. I don't act on it per person.
The contact form
Your email address and your message, which land in my inbox. I reply from my real address.
Gated pages
Two pages sit behind an email address: the talk deck at /experimentos-con-foco and the advisor page at /advisor. They're the most tracked things here, and I'd rather say so than bury it.
To open either one you give an email address, and I send you a link. An address whose link is never clicked is deleted after 30 days. Clicking it sets a cookie on your browser that lasts a year, so you don't have to ask for a new link every time. It's one cookie for both pages: an email verified for the deck opens the advisor page too, without asking again. That cookie is what ties a later visit back to the email you gave.
While you read, each page records your IP, your user agent, where you came from, and how long you spend. The deck records which slides you looked at. The advisor page records which sections you reached, how far down the page you scrolled, and whether you clicked "Book a call". I get an email the first time you open each page, and again if you sign in to it from a new browser or device.
That's there because both are things I hand to specific people, a room at a talk or a founder I've already spoken to, and I want to know whether they were useful. It isn't used for anything else.
Analytics
Page views and where you came from, through Umami, which I host on my own server rather than sending to an analytics company. Alongside the page, it records your browser, operating system, device type, screen size, language, and a country worked out from your IP address. It sets no cookies and stores no IP address.
A handful of actions send a one-word event too, so I can tell whether anything on a page gets used: subscribing, posting a comment, taking control of the robot arm on the homepage, and seeing the email form on a gated page. A comment event carries which post it was on, and the gated form's event carries which of the two pages it was. None of them carries anything about you.
If your browser sends Do Not Track or Global Privacy Control, none of it loads at all.
Who else touches any of this
Three, and only three:
- Google, for the calendar event and the Meet link on a booked call.
- Resend, which delivers my email: confirmations, the newsletter, contact messages.
- Google Cloud, where the server lives. Everything else, analytics included, runs there rather than at some other company.
How long I keep it
Until you ask me to delete it. The one automatic clear-out is on the gated pages: an email address whose link was never clicked goes after 30 days. Everything else stays until you ask, and I'd rather tell you that than pretend there's a schedule.
Getting it deleted
Reply to any email I've sent you and say so. If you've never had one, the contact form reaches me.
Tell me what you want gone and I'll remove it: the booking, the comment, the newsletter entry, what a gated page recorded, all of it. Ask me what I hold on you and I'll tell you that too.
Two honest limits on that, because a promise I can't keep is worse than no promise.
The first is backups. The database is dumped nightly to storage I control, and those dumps roll off on a schedule: seven daily, four weekly, six monthly. So deleting your data removes it from the live site straight away, but a copy sits in those backups until the last one containing it expires, which can be up to six months. I'm not going to reach into old backups; they exist so the site survives a bad day.
The second is the record of what happened. A booking leaves an audit line, which keeps the email address and what was done, so I can answer "why did this call get cancelled" later. Delete the booking and the line stays. If you want that gone too, say so and I'll remove it. Same for a blocked address: if I've had to block someone, I keep that block, or blocking would mean nothing.
What I don't do
I don't sell anything to anyone. I don't share your details beyond the three services above, which need them to do their job. There are no third-party trackers, no advertising pixels, and nothing following you to other sites.
If something here isn't clear, or you want it in a more formal shape for your own compliance reasons, ask me and I'll write it.