CR Tools

Privacy notice

This page describes what php.cristianrenosto.party does with personal data. It is a subdomain of cristianrenosto.party and it runs on the same machine as the main site, but it is a separate application: separate code, separate database, separate cookies. No data from this subdomain is sent to the main site or to any third party.

Last updated: 30 September 2026

1. Who is the controller

The controller is Cristian Renosto, reachable at [email protected] and at https://cristianrenosto.party.

No Data Protection Officer has been designated (Article 37). The processing is occasional, limited to a personal toolbox with a single user, does not require large-scale processing, and does not include special-category data, so the designation is not mandatory. This is a judgement call, stated openly: if the use of this application changes, this paragraph has to be revisited.

2. What this subdomain is

It is a set of small tools (JSON, regex, hashes, QR codes, colour contrast, cron, timestamps, diffs and similar) plus a private workspace for the owner: code snippets, notes, bookmarks, a time tracker, an uptime monitor and the inbox of the contact form.

The workspace requires an access token. It is not a multi-user system: there are no accounts, no registrations and no third-party authentication.

3. Personal data processed, purposes and legal bases

Three groups of data exist on this server. Everything else is stateless.

Data Where it comes from Purpose Legal basis Stored
Nothing. Text pasted into the tools (JSON, regex subject, hashes, colour values, URLs, diff inputs, QR content). You To produce the result you asked for Article 6(1)(b) — steps taken at your request, prior to any contract Not stored. The value travels in one HTTP request, is processed in memory and discarded when the page closes.
IP address (truncated to the network part: IPv4 /24, IPv6 /48), user agent Automatically, from the HTTP request Rate limiting and abuse prevention Article 6(1)(f) — legitimate interest in keeping the service available SQLite, cleared with the hit itself; see 5
Name, email address, subject, message body You, through the contact form To reply to you Article 6(1)(f) — legitimate interest in answering messages addressed to me SQLite (messages), max 12 months
Snippets, notes, bookmarks, tracked hours, monitored URLs The owner of this application Personal productivity Article 6(1)(f) — legitimate interest of the controller in his own working material SQLite, until deleted (one click in Data & backup, or the whole file)

Minimisation, in practice

  • The contact form asks for four things. Not a phone number, not a company, not a profile.
  • The IP is truncated before it is written: 203.0.113.42 becomes 203.0.113.0/24. Enough to recognise an abusive network, not enough to identify a person behind a shared connection.
  • Nothing typed into a tool is written anywhere. Open the browser devtools during a JSON formatting and watch the network tab: there is one request, and then nothing.
  • No fonts, scripts or styles are loaded from other people's servers. The fonts are served from this host, which is also why there is no consent banner: see cookies.

4. Cookies

Two cookies are set, both strictly necessary, neither used for profiling. No consent banner appears, because there is nothing to consent to: strictly necessary cookies used to provide a service the user explicitly requested do not require consent under the ePrivacy rules (Article 5(3) of Directive 2002/58/EC, as amended).

  • cr_tools — session cookie. Holds the CSRF token and the flash messages. Expires when the browser closes.
  • cr_theme — remembers whether you chose the light or dark theme. One year.

The full list, with purposes and lifetimes, is on the cookies page.

5. Retention

WhatHow longWho deletes it
Tool inputs and resultsNot stored at all—
Rate limit records24 hoursAutomatic, opportunistic cleanup
Contact messagesUp to 12 monthsAutomatic purge, plus a manual delete button
Search historySession onlyWhen the session cookie expires
Workspace contentUntil deletedThe owner, from Data & backup
Server logsAs configured by the host, typically 7-30 daysThe web server

6. Recipients and international transfers

No data is shared with anyone. There are no processors, no sub-processors, no analytics, no advertising, no error-reporting services, no fonts or scripts from third parties, no web fonts, no map embeds, no social widgets. The only outbound connections this application can make are the ones you ask for in the HTTP inspector and in the uptime monitor, and those go to the address you type.

Consequently there are no transfers outside the European Economic Area. If the application is hosted on infrastructure outside the EEA, the hosting provider becomes a processor and an appropriate transfer mechanism would be required — that is a deployment decision, and it is yours to make knowingly.

7. Security measures (Article 32)

  • HTTPS with HSTS, including subdomains.
  • A Content-Security-Policy that forbids inline and evaluated scripts (script-src 'self').
  • CSRF tokens on every POST, compared in constant time.
  • Strict session cookies: HttpOnly, SameSite=Lax, Secure under HTTPS, use_strict_mode on.
  • Rate limiting per IP on every write and a stricter one on the contact form.
  • An SSRF guard on the two features that make outbound requests: private, loopback, link-local and reserved addresses are refused, redirects are re-validated, and the response size is capped.
  • The workspace is behind a token compared with a constant-time comparison, and the session identifier is regenerated on unlock.
  • All output escaped by default; the Markdown renderer escapes HTML before applying any formatting, so injected markup stays text.
  • Direct access to storage/, app/, src/ and views/ is denied by the web server configuration.

What is not in place: the database file is not encrypted at rest, and there are no backups outside the server. Both are acceptable for a single-user toolbox on a private server, and neither would be acceptable for a service used by other people.

8. Your rights

You have the right of access (Article 15), rectification (16), erasure (17), restriction (18), portability (20) and objection (21), and the right not to be subject to automated decision-making (22).

How to exercise them here:

  • Access and portability: everything this application holds about you is in the Data & backup page, as a single JSON file. Ask for it and you get it, or download it yourself if you know the token.
  • Erasure: the same page deletes every record in one action. For contact messages there is a delete button next to each message.
  • Rectification, restriction and objection: write to [email protected]. The answer comes from a person, in a few days.
  • Complaint: the supervisory authority for Italy is the Garante per la protezione dei dati personali, whose contact details are published at garanteprivacy.it.

9. Automated decisions and profiling

None. No profiling, no scoring, no decisions taken by automated means, no behavioural advertising. The "password strength" tool computes an entropy estimate from the string you type, in the browser request, and never stores it.

10. Children

This site is not directed at children and collects no data knowingly from anyone under 16. If you believe data from a child has been submitted through the contact form, write to [email protected] and it will be deleted.

11. Changes to this notice

The date at the top of this page is the date of the last revision. Material changes (a new feature that stores data, a new third party, a new purpose) will be visible here and in the repository history, not buried.

12. What is deliberately not here

  • No cookie banner. With no non-essential cookies there is nothing to ask about. Adding an analytics script would require one, and would require changing this notice.
  • No double opt-in on the contact form. It is a mailbox for a personal site, not a newsletter; a confirmation email would only make it easier to lose a message.
  • No records of processing activities (Article 30). Publicly available, but the organisation is one person with one toolbox: the table in section 3 is the register.
  • No DPO. See section 1.
  • No encryption at rest of the SQLite file. See section 7.