Privacy & cookies
Last updated: 14 September 2026.
This website is a hobbyist creative project. This notice explains the technical data and external services actually used by miyukiaizawa.com.
1. Controller and contact
The controller is a natural person operating a hobby internet project under the pseudonym “Miyuki Aizawa”. For safety reasons, the controller's private details are not published on the website. For privacy matters, exercising your rights or requesting information about the controller's identity, contact: [email protected].
2. Data that may be processed
- Nginx server logs: the address of the Cloudflare infrastructure node handling the request, date and time, requested URL including its parameters, response code, response size, referrer and browser or bot information;
- technical data processed by Cloudflare, including the visitor's actual IP address, request data and information needed to protect and deliver the website;
- privacy settings stored in a signed cookie in the user's browser;
- a signed Flask session stored in the browser, required for administrator sign-in and protected features or - after the visitor's consent - recognising one visit in the basic counter;
- data voluntarily provided in email correspondence, such as the sender's address, message content, signature and attachments;
- data sent to a selected provider after you voluntarily load external content.
The site's own counter stores only the total number of visits and daily totals. It does not save IP addresses, requested URLs or user identifiers in the statistics file. An IP address may be used temporarily for security measures such as limiting administrator sign-in attempts, but it is not stored in the counter file.
The application journal may contain service start-up information, the request method and path, and technical details of an error. It is not used as a visitor log and does not intentionally record form contents.
3. Purposes and legal bases
- security, abuse prevention, error diagnosis and delivery of the website through the server and Cloudflare - the controller's legitimate interest;
- sign-in and features selected by the user - providing the requested website function;
- handling correspondence - taking action at the sender's request or the legitimate interest in responding; handling privacy rights requests - compliance with a legal obligation;
- basic analytics and external embeds - consent, which may be withdrawn at any time.
4. Cookies and similar technologies
The miyuki_privacy and session cookies are stored on the user's device. The website does not maintain a separate database containing these cookies. Their signatures allow the application to verify that their values have not been altered.
| Name / type | Purpose | Duration | Category |
|---|---|---|---|
| miyuki_privacy | Remembers selected privacy settings on the user's device. Its value is signed and unavailable to JavaScript. | 180 days | Essential |
| session | A Flask session stored in a signed cookie. It is used by the administrator and users of protected features; for an ordinary visitor who has consented, it remembers that the current visit has already been counted. | Until the browser is closed; protected-gallery access for up to 1 hour | Essential for a selected feature / analytics after consent |
| Cloudflare | Website protection, abuse filtering and secure connections; Cloudflare may set essential cookies, for example while verifying traffic. | Depends on the security mechanism | Essential |
| External services | Cookies or local storage used by providers of voluntarily loaded embeds. | According to the provider's policy | Optional |
5. External services
After consent, the website may connect to YouTube, Meta/Instagram, Spotify, GitHub/Giscus, Ko-fi and Behold. These providers may receive your IP address and browser information and may use their own cookies under their respective policies.
Comments submitted through Giscus are stored publicly in GitHub Discussions. Voluntary support and messages submitted through Ko-fi are handled on the Ko-fi platform and may be visible to the owner of the Miyuki account.
Ordinary external links do not load a provider until you follow them.
6. Recipients and transfers outside the EEA
Technical data may be processed by the hosting provider and Cloudflare. Correspondence is also processed by the email provider. After an embed is voluntarily loaded or an external feature is used, data may also be received by the providers listed in section 5. Some operate outside the European Economic Area. Transfers may rely on an adequacy decision or the provider's standard contractual clauses.
7. Retention
The current Nginx configuration rotates logs daily and retains up to 14 rotated log files. Older archived files may exceptionally remain after a server migration until technical housekeeping is completed. Aggregated, non-identifying daily statistics may be retained for longer. Privacy preferences remain valid for 180 days, while an ordinary visitor's session generally lasts until the browser is closed. Correspondence is retained for as long as needed to respond and document the matter, and longer where necessary to comply with a legal obligation or defend legal claims. Cloudflare and external providers apply their own retention periods.
8. Your rights
Depending on the legal basis, you may request access, correction, deletion or restriction, object to processing and withdraw consent without affecting earlier processing. You may also lodge a complaint with the Polish President of the Personal Data Protection Office (UODO).
The aggregated counter cannot be used to locate data about a particular person. For enquiries about server logs, an approximate visit time, requested URL and browser information may help locate a relevant entry. The controller does not collect additional data solely to identify someone who cannot be identified from the information already held.
You can reopen your choices at any time using “Cookie settings” in the footer.