Privacy Policy
Last updated: 5 September 2026
Webtrail is a notebook, not a service. There is nothing to sign up for, so for a reader this policy is mostly a list of things that do not happen.
1. Who is responsible
Webtrail is operated by Brian Douglas in Switzerland (hc.liartbew@ofni). That person is the data controller within the meaning of the Swiss Federal Act on Data Protection (nDSG) and, where it applies, the EU General Data Protection Regulation (GDPR).
2. What is collected
- No reader accounts. Webtrail has no public sign-up, no comments, no newsletter and no forms for a reader to fill in. Reading it leaves no name, address or email address here.
- Server logs. Requests are logged with an IP address, the browser's user-agent string, the requested path and a timestamp. They are kept for up to 30 days and are used to find faults and abuse.
- Rate-limit counters. Requests are counted per IP address for a few minutes at a time so that one client cannot flood the site. The counters expire on their own and are not read for anything else.
- Administrator data. The single editorial account holds an email address and a bcrypt password hash. That is the operator's own account, not a reader's.
3. Legal basis
- Legitimate interests (Art. 6(1)(f) GDPR / Art. 31(1) nDSG) for server logs and rate limiting: keeping the site up and defending it against abuse.
- Contract performance (Art. 6(1)(b) GDPR / Art. 31(2)(a) nDSG) for the editorial account, which exists to operate the site.
4. Cookies and trackers
One cookie exists on this site: a first-party session cookie set after the operator signs in to the editorial pages. A reader who never signs in is never given it. There are no analytics, no advertising cookies, no fingerprinting and no tracking pixels.
Nothing is loaded from a third-party host either. Typefaces, styles, scripts and images are all served from this domain, so opening a page here does not announce your visit to a font CDN, an analytics vendor or a social network. Because only strictly necessary cookies are used, no consent banner is required under Swiss or EU law; this paragraph is the disclosure instead.
5. Where the site is hosted
Webtrail runs on Fly.io in Amsterdam, in the Netherlands. Its data — the SQLite database, uploaded images and logs — sits on a volume attached to that machine inside the EU/EEA. Fly.io processes it as an infrastructure provider only, with no access beyond what running the machine requires.
6. Links out, and the screenshots
Every stop on a trail points at somebody else's site. Following one takes you to a host that has its own privacy practices, and this policy stops at the link. Nothing here is an affiliate link, and no click is tracked or passed to the destination.
The screenshot next to each stop is stored and served from this domain, not embedded from the site it depicts, so a page of the catalog loads without your browser contacting any of the sites it lists.
7. How the content is written
AI tools are part of how webtrail is made, and it would be dishonest not to say so. Large language models are used to draft and edit the write-ups, to summarise pages that have been opened and read, and to help maintain the site's own code. Nothing is published on the strength of a model's output alone: every stop is a real page that a person opened, and every write-up is reviewed and edited by a person before it appears.
This matters for your privacy in one specific way, so to be explicit: no reader data goes into those tools. Server logs, IP addresses and request data are never sent to an AI provider, and there is no reader data to train on in the first place. What the tools see is the public pages being written about and the site's own source code.
AI-assisted text can still be wrong in ways review does not catch. If you find a stop that misrepresents your site, or a claim that is simply incorrect, write to hc.liartbew@ofni and it will be corrected or removed.
8. Email
Webtrail sends no newsletter and no marketing email, because it has no reader mailing list. The only message the site can send is a password reset to the operator's own editorial account.
9. Sharing
No personal data is sold, rented or shared. Apart from the hosting provider named above, nobody receives data from this site, and there are no analytics or advertising partners to receive any.
10. Retention
Server logs are kept for up to 30 days and then discarded. Rate-limit counters expire within minutes. Published content and its images are kept for as long as the page stands.
11. Security
Everything is served over HTTPS. The editorial password is stored as a bcrypt hash and is never readable in plain text. A Content Security Policy restricts what a page may load, and access to the production machine is limited to the operator.
12. Your rights
Under the nDSG, and the GDPR where it applies, you may ask for access to the personal data held about you, its correction or its erasure, and you may object to its processing. In practice there is very little to ask about unless you are the operator: a reader's trace here is a log line that expires within 30 days.
Write to hc.liartbew@ofni to exercise any of these rights. You may also complain to the Swiss Federal Data Protection and Information Commissioner (edoeb.admin.ch) or to your local EU supervisory authority.
13. Changes to this policy
If this policy changes, the revised version appears on this page with a new date at the top. There is no mailing list to notify, so the date is the notice.
14. Contact
Brian Douglas, Switzerland
hc.liartbew@ofni
The social channels linked in the footer reach the same person, and you are welcome to use them. Email is the channel to use for anything under section 12, because it is the one that does not require an account somewhere else and is not filtered by a platform.