Privacy

Last updated

The calendar you keep here is a private thing. Below is exactly what gets stored about you, why I need it, and what will never be done with it. No legal fog — if something is unclear, write to me.

Who runs this

Jozef Môstka, Tvrdošín, Slovakia

E-mail: jozef@mostka.sk

This is not a company with a support desk. It is one person and one server — write to that address and I am the one who answers.

The short version

  • Your calendar, your notes and your moods are yours alone. Nobody else sees them — until you create a public link yourself.
  • Nothing is sold and nothing is handed on. No ad network, no third-party tool, no profiling.
  • Deleting your account really deletes it. Calendars and days go with it, in one click.
  • The analytics run without cookies and know nothing about what you write in your calendar.

What is stored

Your account

Data What for
E-mail address signing in, password recovery, the mail you switch on
Password never in readable form — only a one-way hash (Argon2/bcrypt). I cannot read it or send it to you, only let you set a new one
Whether the address is verified so nobody can open an account on somebody else's e-mail
Language, colour palette, light/dark, timezone so the app looks and speaks the way you said
When the account was created operation and security

Calendars

The calendar's name, icon and colour, its rhythm (daily / a few times a week) and weekly quota, the unit, the start date, whether it is archived — and the letter to your future self, if you wrote one. That letter is as private as a note on a day.

Days

The date, your note, how the day felt, and a number if you entered one.

This is the most sensitive part of the whole database and it is treated that way: notes and moods are never written to the logs, never sent to the analytics and never part of a public link.

Milestones

Which badges you earned, and when.

Why I am allowed to process it

  • Performance of a contract (Art. 6(1)(b) GDPR) — without an address and without stored days a calendar would not be a calendar. This covers the account and everything you write into it.
  • Consent (Art. 6(1)(a) GDPR) — for the milestone mail, the one message that is not needed for the account to work. Write to me and I will turn it off.
  • Legitimate interest (Art. 6(1)(f) GDPR) — keeping the sign-in and sign-up forms from being abused: attempt limits, the picture puzzle on registration, and the server's technical logs.

Signing in with Google

Google is an option, not a requirement — an e-mail and a password are enough.

When you press that button the site sends you to Google, and after you agree Google returns two things: your account identifier and your e-mail address, along with whether Google has verified it. The app asks for the openid and email scopes only — not your name, not your profile picture, not your contacts, not your Google Calendar.

An unverified address is refused. If it were accepted, anybody could put somebody else's address on their Google profile and sign in to that person's calendar.

Google learns from this that you visited budem.sk — that happens on their side and is governed by Google's privacy policy. Google LLC is based in the USA; the transfer is covered by the European Commission's adequacy decision (EU–US Data Privacy Framework). If you would rather not, sign in with an e-mail and a password — the app is exactly the same afterwards.

Nothing about your days ever leaves for Google. Signing in is the only moment those two sites say anything to each other.

The public link

A calendar is private until you say otherwise. When you decide to share one, a long random link is generated.

  • The link shows: the calendar's name, the number of days and the grid.
  • The link never shows: your name, your e-mail, your notes, your moods, or any other calendar of yours.

Turning sharing off is as easy as turning it on, and the link stops working the moment you do.

Cookies

There is no consent bar here, because there is nothing to consent to — every cookie you get is technical, and the thing it belongs to would not work without it.

Cookie What for How long
PHPSESSID holds your sign-in and protects forms against forgery (CSRF) until you close the browser
REMEMBERME only if you tick "remember me" 30 days

No advertising cookie, no tracking cookie, nothing from anybody else. Not one.

Analytics

Visits are counted with Matomo — an open-source tool running on my own server (matomo.mostka.sk). Not Google Analytics, not a Facebook pixel, nothing that would hand data to a third party.

It runs without cookies and with an anonymised IP address (the last two octets are replaced with zeros). It records which page, when, from what kind of device and browser, in what language, and where you came from. None of that can be tied to a particular person, and none of it touches what is in your calendar.

Two things worth spelling out:

  • If your browser says Do Not Track (or Global Privacy Control), the measuring script is not loaded for you at all — that is a decision made in the app itself, not a setting in Matomo that I could overlook. No request is made to matomo.mostka.sk, so not even your IP address reaches it.
  • The address-verification and password-reset links carry a one-time token in the URL. That token is not sent to the analytics — it is replaced with the word redacted in the browser first. Otherwise anybody with access to the statistics would be holding a working link into somebody's account.

Matomo keeps the raw data for 12 months and then deletes it.

The picture puzzle on registration

The sign-up form is protected by IconCaptcha — you pick the icon that appears the fewest times. It runs entirely on this server: this site draws the images, and nothing is sent to Google, Cloudflare or anybody else. While you are solving it the server keeps, on its own side, which icons you were given, which one is right, and your IP address — so the puzzle cannot be tried forever. Once solved, or after a few minutes of inactivity, that is deleted.

Mail

Only what the app actually needs, and all of it leaves from my own mail server — not through Mailchimp, Sendgrid or any other outside tool.

  • Address verification on sign-up — the account does not work without it.
  • Password recovery — only when you ask for it.
  • Milestone — when you earn a badge. If you would rather not have them, write to me and I will turn them off.

No newsletter, no "we miss you", no advertising. And none of those mails carries a tracking pixel: I do not know whether you opened one, or when — and that is as it should be.

How long it is kept

For as long as you have an account. The whole point of this calendar is that days add up over years; deleting them after twelve months would defeat it.

  • The server's technical logs (IP address, time, page address, error messages) are rotated daily and anything older than 14 days is thrown away. They exist so a bug can be found. Notes, moods and e-mail addresses are never written into them — that is not an accident, it is the rule the app is written to.
  • Database backups are taken before any change to its structure and are discarded after a while. A deleted account disappears from them when that backup is discarded.
  • Analytics keeps its raw data for 12 months.

Deleting your account

There is a button in the settings that deletes the account and with it every calendar, every day, every note, mood and badge. Not a "deleted" flag, not an archive kept somewhere just in case. Gone.

This is not a detail. Somebody who spent a year writing down the bad days too has to know they can make them go away — all of them, at once, without having to ask.

If you cannot find the button or it fails, write to me and I will delete the account by hand.

Where it physically is

On a server in the Czech Republic (vpsFree.z.s.p.o., Prague), so inside the European Union. The database, the files and Matomo are all on the same machine. Nothing is sent outside the EU — the single exception is Google, and only if you choose to sign in that way.

Your rights

You have the right to:

  • know what I hold about you (access),
  • have it corrected (rectification),
  • have it deleted (erasure — for most of it, the button in the settings is enough),
  • limit what I do with it (restriction of processing),
  • get your data in a machine-readable form (portability),
  • object to processing based on legitimate interest,
  • withdraw consent at any time where the processing rests on it; withdrawing does not affect what was lawful before.

Writing to jozef@mostka.sk is enough.

If you think your data is being handled wrongly, you can complain to the Slovak Data Protection Authority (dataprotection.gov.sk), or to the supervisory authority where you live.

There is no automated decision-making and no profiling. Milestones are counted from a number of days and nothing else follows from them.

Children

You may open an account if you are at least 16. Younger than that, only with a parent's consent.

If something goes wrong

If there were a data breach that put you at risk, you would hear about it by e-mail, and the Data Protection Authority within 72 hours. It would not be quietly buried.

Changes

When this text changes, so does the date at the top. For a change that actually affects you I will write — I will not rely on you coming back to read a new version by yourself.

See also: Terms of use.