Privacy notice
This page describes what php.cristianrenosto.party does with personal data. It is a subdomain of cristianrenosto.party and it runs on the same machine as the main site, but it is a separate application: separate code, separate database, separate cookies. No data from this subdomain is sent to the main site or to any third party.
Last updated: 30 September 2026
1. Who is the controller
The controller is Cristian Renosto, reachable at [email protected] and at https://cristianrenosto.party.
No Data Protection Officer has been designated (Article 37). The processing is occasional, limited to a personal toolbox with a single user, does not require large-scale processing, and does not include special-category data, so the designation is not mandatory. This is a judgement call, stated openly: if the use of this application changes, this paragraph has to be revisited.
2. What this subdomain is
It is a set of small tools (JSON, regex, hashes, QR codes, colour contrast, cron, timestamps, diffs and similar) plus a private workspace for the owner: code snippets, notes, bookmarks, a time tracker, an uptime monitor and the inbox of the contact form.
The workspace requires an access token. It is not a multi-user system: there are no accounts, no registrations and no third-party authentication.
3. Personal data processed, purposes and legal bases
Three groups of data exist on this server. Everything else is stateless.
| Data | Where it comes from | Purpose | Legal basis | Stored |
|---|---|---|---|---|
| Nothing. Text pasted into the tools (JSON, regex subject, hashes, colour values, URLs, diff inputs, QR content). | You | To produce the result you asked for | Article 6(1)(b) — steps taken at your request, prior to any contract | Not stored. The value travels in one HTTP request, is processed in memory and discarded when the page closes. |
| IP address (truncated to the network part: IPv4 /24, IPv6 /48), user agent | Automatically, from the HTTP request | Rate limiting and abuse prevention | Article 6(1)(f) — legitimate interest in keeping the service available | SQLite, cleared with the hit itself; see 5 |
| Name, email address, subject, message body | You, through the contact form | To reply to you | Article 6(1)(f) — legitimate interest in answering messages addressed to me | SQLite (messages), max 12 months |
| Snippets, notes, bookmarks, tracked hours, monitored URLs | The owner of this application | Personal productivity | Article 6(1)(f) — legitimate interest of the controller in his own working material | SQLite, until deleted (one click in Data & backup, or the whole file) |
Minimisation, in practice
- The contact form asks for four things. Not a phone number, not a company, not a profile.
-
The IP is truncated before it is written:
203.0.113.42becomes203.0.113.0/24. Enough to recognise an abusive network, not enough to identify a person behind a shared connection. - Nothing typed into a tool is written anywhere. Open the browser devtools during a JSON formatting and watch the network tab: there is one request, and then nothing.
- No fonts, scripts or styles are loaded from other people's servers. The fonts are served from this host, which is also why there is no consent banner: see cookies.
4. Cookies
Two cookies are set, both strictly necessary, neither used for profiling. No consent banner appears, because there is nothing to consent to: strictly necessary cookies used to provide a service the user explicitly requested do not require consent under the ePrivacy rules (Article 5(3) of Directive 2002/58/EC, as amended).
cr_tools— session cookie. Holds the CSRF token and the flash messages. Expires when the browser closes.cr_theme— remembers whether you chose the light or dark theme. One year.
The full list, with purposes and lifetimes, is on the cookies page.
5. Retention
| What | How long | Who deletes it |
|---|---|---|
| Tool inputs and results | Not stored at all | — |
| Rate limit records | 24 hours | Automatic, opportunistic cleanup |
| Contact messages | Up to 12 months | Automatic purge, plus a manual delete button |
| Search history | Session only | When the session cookie expires |
| Workspace content | Until deleted | The owner, from Data & backup |
| Server logs | As configured by the host, typically 7-30 days | The web server |
6. Recipients and international transfers
No data is shared with anyone. There are no processors, no sub-processors, no analytics, no advertising, no error-reporting services, no fonts or scripts from third parties, no web fonts, no map embeds, no social widgets. The only outbound connections this application can make are the ones you ask for in the HTTP inspector and in the uptime monitor, and those go to the address you type.
Consequently there are no transfers outside the European Economic Area. If the application is hosted on infrastructure outside the EEA, the hosting provider becomes a processor and an appropriate transfer mechanism would be required — that is a deployment decision, and it is yours to make knowingly.
7. Security measures (Article 32)
- HTTPS with HSTS, including subdomains.
- A Content-Security-Policy that forbids inline and evaluated scripts (
script-src 'self'). - CSRF tokens on every POST, compared in constant time.
- Strict session cookies:
HttpOnly,SameSite=Lax,Secureunder HTTPS,use_strict_modeon. - Rate limiting per IP on every write and a stricter one on the contact form.
- An SSRF guard on the two features that make outbound requests: private, loopback, link-local and reserved addresses are refused, redirects are re-validated, and the response size is capped.
- The workspace is behind a token compared with a constant-time comparison, and the session identifier is regenerated on unlock.
- All output escaped by default; the Markdown renderer escapes HTML before applying any formatting, so injected markup stays text.
- Direct access to
storage/,app/,src/andviews/is denied by the web server configuration.
What is not in place: the database file is not encrypted at rest, and there are no backups outside the server. Both are acceptable for a single-user toolbox on a private server, and neither would be acceptable for a service used by other people.
8. Your rights
You have the right of access (Article 15), rectification (16), erasure (17), restriction (18), portability (20) and objection (21), and the right not to be subject to automated decision-making (22).
How to exercise them here:
- Access and portability: everything this application holds about you is in the Data & backup page, as a single JSON file. Ask for it and you get it, or download it yourself if you know the token.
- Erasure: the same page deletes every record in one action. For contact messages there is a delete button next to each message.
- Rectification, restriction and objection: write to [email protected]. The answer comes from a person, in a few days.
- Complaint: the supervisory authority for Italy is the Garante per la protezione dei dati personali, whose contact details are published at garanteprivacy.it.
9. Automated decisions and profiling
None. No profiling, no scoring, no decisions taken by automated means, no behavioural advertising. The "password strength" tool computes an entropy estimate from the string you type, in the browser request, and never stores it.
10. Children
This site is not directed at children and collects no data knowingly from anyone under 16. If you believe data from a child has been submitted through the contact form, write to [email protected] and it will be deleted.
11. Changes to this notice
The date at the top of this page is the date of the last revision. Material changes (a new feature that stores data, a new third party, a new purpose) will be visible here and in the repository history, not buried.
12. What is deliberately not here
- No cookie banner. With no non-essential cookies there is nothing to ask about. Adding an analytics script would require one, and would require changing this notice.
- No double opt-in on the contact form. It is a mailbox for a personal site, not a newsletter; a confirmation email would only make it easier to lose a message.
- No records of processing activities (Article 30). Publicly available, but the organisation is one person with one toolbox: the table in section 3 is the register.
- No DPO. See section 1.
- No encryption at rest of the SQLite file. See section 7.