# Privacy — Thorfyn

Canonical URL: https://thorfyn.com/en/privacy

> What we collect on this site and in the contact form, why, for how long, where it is stored, and how to have it deleted.

What this site collects, and what it does not.

By default nothing is stored on your device. A few optional features stay off until you turn them on, and the contact form keeps only what you send.

## Who is responsible

- **Controller** — Thorfyn decides why and how the data described here is used. The address at the end of this page reaches the person who handles it.

## What is collected

- **Visits, with no choice made** — Which door you clicked, which sections you scrolled to, the page language and the page you were on. There is no cookie and nothing is written to your device: the random visit id lives in the tab's memory and disappears when you close it. The analytics provider is set to discard your IP address. While a page test runs, a one-way hash of your network address and browser picks which version of the page you see; it is computed for each request, never stored and never sent, and the analytics only learn which version you saw.
- **Page speed** — How long the page took to show its main content and for the server to start answering, as two numbers rounded to a tenth of a second and added to a running total. They carry no identity, no cookie and no network address, nothing is written to your device, and one visit cannot be told apart from another.
- **The contact form** — Your email, your message and when you want it running, plus the page language, the last door you clicked, the page you landed on, the site that sent you and the campaign tags in the link, kept twice: for your first visit in the session and for the visit that sent the form. As the enquiry moves forward (qualified, call held, proposal, paid discovery, client) the owner marks each step, and the step is kept with the enquiry and counted anonymously in the analytics, without your email or message. A one-way hash of your network address is kept for one hour to limit repeated submissions; it cannot be turned back into the address.
- **If you use the speed report** — The address you ask us to measure and the numbers Google returns for it, kept for seven days so the same address is not measured twice in a day, never the content of the page; and a hash of your network address, kept for one hour to limit how many measurements one visitor can ask for. If you ask for the full version, your email is kept like a message from the contact form.
- **If you use the Supabase exposure check** — The link of the app you ask us to check and a short record of what its public scripts named — the Supabase project, a masked fragment of the published key and the table names — kept for a day so the same app is not checked twice, never the content of any table, only how many rows answer; and a hash of your network address, kept for one hour to limit how many checks one visitor can ask for. We read only what the app already serves to every visitor, and store nothing from the tables.
- **If you got a message from us with a link** — Your name, role, company, the address of your site and your public professional profile, which we looked up ourselves, plus the dates of the messages we sent and when your link was opened. Not your email, your phone or your network address. The link only opens a page of this site. Tell us to stop and we erase all of it and keep only a one-way mark so we never write to you again.
- **Only if you accept** — A random id kept in this browser's local storage, not in a cookie, so separate visits read as one; a recording of how you use the pages, with every form field masked; a count of where visitors click and how far they scroll; one optional question, shown at most once every thirty days to a visitor who read the pricing and is leaving, whose answer you type yourself and should keep free of contact details; and that id attached to a message you send. Nothing is sold or shared for advertising.

## Why, and on what basis

- **Measuring the site** — To learn which parts of the page help someone decide. Legitimate interest: the data is aggregate, carries no identity and sets nothing on your device.
- **Answering you** — To reply to your message and, if you ask for it, to send a proposal. These are steps before a contract, taken at your request. The confirmation email and the two reminders sent when there is no answer belong to the same reply, and each carries a link that stops them.
- **Recognizing you, recording the session and asking one question** — Only with your consent. You can refuse or withdraw it at any time, as easily as you gave it, and refusing changes nothing else on the site.

## How long it is kept

- **Messages** — Twelve months after you send them, then deleted automatically, together with the records of the confirmation, the reminders and any booking linked to them.
- **Address hash** — Cleared from the message record the next time the form is used after an hour has passed.
- **Contacts we wrote to first** — Twelve months after we added them, then deleted automatically, with their messages and clicks. The one-way mark kept after someone asks us to stop has no expiry, because it is what keeps us from writing again.
- **Analytics events** — Twelve months, the retention of the analytics plan in use.
- **Session recordings** — One month, and only for visitors who accepted. Only some visits are recorded, so the monthly volume stays inside the analytics plan.
- **Click maps and survey answers** — Twelve months, the retention of the analytics plan in use, and only for visitors who accepted.
- **Your choice** — Kept in this browser until you change it or clear the site's data.

## Where it is stored, and who handles it

- **Analytics** — PostHog Cloud, European region (Frankfurt, Germany).
- **Messages** — Cloudflare hosts this site and stores messages in its database, in a region Cloudflare chooses. Cloudflare Email Routing delivers the notice to our mailbox.
- **Confirmation and reminders** — Resend sends the confirmation email to the address you typed and, if there is no answer, up to two reminders, each with a link to stop them.
- **Booking a call** — If you choose to book, Cal.com handles the scheduling on its own page and tells us the time you picked and the email you used. Booking is optional and the form works without it. If you book without writing to us first, we keep that email address, the language and the time zone for up to 12 months, only to send the call mails. Whoever books, written or not, gets one reminder before the call, in Brasília business hours; whoever books without writing also gets a welcome. Each mail carries a link that stops them.
- **Transfers** — When data leaves your country it relies on the processors' data processing agreements, which include standard contractual clauses, and on the EU–US Data Privacy Framework where it applies.

## Your rights, and how to delete

- **What you can ask** — Confirmation that we hold data about you, a copy, correction, deletion, portability and the names of who received it, under the LGPD and, if you are in the European Union, the GDPR.
- **How** — Write to the address below from the email you used in the form. We answer within 15 days. Deleting removes your message and any analytics profile we can link to you.
- **Complaints** — You can complain to the ANPD in Brazil or to your data protection authority in the European Union.
- **On this device** — Withdraw your consent below or in the footer: the stored id leaves this browser immediately.

## Your choice

Measurement beyond the basics stays off until you accept.

- Responsible: 63.378.910 MATHEUS SANTOS PAVANELI · CNPJ 63.378.910/0001-22
- Questions and requests: hello@thorfyn.com
- Updated: 2026-10-11
- Back to the home page: https://thorfyn.com/en
