> privacy policy

Last updated: October 2026

What this site is

martindimoski.dev is a personal blog and portfolio. It is not a product, does not sell anything, and does not run advertising.

Data collected

This site collects the minimum amount of data necessary to function.

  • -Email address - only if you choose to sign in. Used solely for authentication via magic link. Not shared with third parties.
  • -Session data - a secure cookie is stored in your browser to maintain your session after signing in. It expires automatically.
  • -Server logs - standard web server logs (IP address, browser type, pages visited) may be retained briefly by the hosting provider for operational purposes.

What is not collected

  • -No cross-site tracking and no analytics cookies. Page views are counted without cookies; see visitor counts
  • -No advertising or ad network tracking
  • -No behavioural profiling: nothing links your visits from one day to the next
  • -No data is sold or shared with third parties for marketing

Visitor counts

This site counts its own page views so I can see what gets read. Each view records the page, the website that sent you (its domain only), your country (from the hosting provider) and whether you are on a phone, tablet or computer. No cookies are set and nothing is stored on your device. Your IP address is never stored: it is combined with your browser's user agent and a secret that changes every day into a short scrambled code, so a visitor counts once a day and cannot be followed from one day to the next. Records are deleted after 90 days. If your browser sends Do Not Track or Global Privacy Control, no view is recorded at all.

The site also uses Vercel's Web Analytics and Speed Insights, which are cookie-free too and report aggregate page views and loading performance to the hosting provider. See Vercel's analytics privacy policy.

Third-party content

The Feeds section fetches RSS content from third-party publishers (OpenAI, Google DeepMind, The Verge, etc.). Visiting those feeds is done server-side - your browser does not connect to those publishers directly. Their own privacy policies apply to their content. Comic images in the Humour topic load from the publisher's own site, with no referrer sent.

Feed digests — if you are signed in and choose a topic's daily or weekly email, this site stores which topics you picked, how often, and when the last one went out. Every topic starts off. Each digest has a link to stop that topic or all of them, and you can change them on your account page. Feeds you follow in the directory are kept in your browser only.

YouTube music player

This site includes an optional music player that embeds YouTube videos. The following applies when you use it:

  • -Consent required — the YouTube player does not load until you explicitly click "Accept & play". No YouTube IFrame or Google cookies are set before that action.
  • -Privacy-enhanced embed — videos are embedded via youtube-nocookie.com, which reduces the data Google collects compared to the standard embed domain.
  • -Google cookies — once you consent and the player loads, Google may set cookies on your device as described in Google's privacy policy.
  • -Search API — YouTube search queries are routed through a server-side endpoint. Your browser does not contact the YouTube Data API directly, and the API key is never exposed client-side.
  • -Legal basis — processing is based on your explicit consent. You can withdraw consent at any time by clearing your browser's localStorage for this site (key: music-player-consent-v1).

Tube

Tube is a members-only video player at /apps/tube. It uses the same privacy-enhanced YouTube embed as the music player, with these differences:

  • -Your library stays in your browser — watch history, resume points, playlists, likes, subscriptions and recent searches are stored in localStorage under a key tied to your account. They are not sent to this site's database. You can export, import, pause or clear them from inside Tube.
  • -Searches — a new search is sent through this site's server to the YouTube Data API and recorded against your account to enforce the daily limit it shares with the music player. You can see them on your account page. Repeat searches are answered from a shared cache.
  • -Everything else — trending lists, video details, channels and comments are fetched server-side and cached. Your browser contacts YouTube only to play the video and load thumbnails.

Overtime online co-op

The game at /apps/overtime can be played by two people on different devices. This is how that works:

  • -A direct connection — the two browsers connect to each other with WebRTC, so each player's device can see the other's IP address, as on any video call. The game itself travels directly between you, not through this site.
  • -The handshake — to set the connection up, each browser sends this site a short technical description of how to reach it (a WebRTC offer or answer, which contains network addresses). It is stored with a six-character room code, the host's first name and account id, and is deleted after at most 15 minutes, or sooner when a new room is opened.
  • -Public STUN servers — to find a route between you, your browser asks Google's and Cloudflare's public STUN servers for its public address. No game data goes to them.
  • -Who can join — Overtime is for members, so hosting and joining both need an account. Any signed-in member with a room's code can join it while it is open, and only one person can.

Your rights

If you have signed in and want your email removed from the database, contact me and it will be deleted promptly.

Contact

Questions about this policy can be sent to martin@martindimoski.dev.