Last Updated: August 31, 2026
At DCYFR Labs, we believe in transparency and privacy by design. This policy explains how we collect, use, and protect your information when you visit our website.
Who We Are and What This Covers
Controller: DCYFR Labs is a trading name, not a registered company. The sites are run by one individual working as a sole proprietor in Colorado, United States, and that person is the data controller for everything described here. We name the arrangement rather than imply a corporate entity that does not exist. For any question about this policy, or to exercise the rights described below, contact us.
This policy is the canonical privacy policy for the DCYFR web estate. It covers dcyfr.ai and the sibling sites dcyfr.io, dcyfr.app, dcyfr.bot, dcyfr.codes, dcyfr.tech, dcyfr.work, and dcyfr.build.
Each sibling site carries its own short notice at /privacy listing the processors that site actually uses, because they are not identical: dcyfr.bot sends chat messages to a model provider, dcyfr.codes publishes snippets to GitHub, and the rest do not. Where a site notice and this policy differ on a detail specific to that site, the site notice is the accurate one.
Our Privacy Principles
- Minimal Data Collection: We only collect what’s absolutely necessary
- Privacy-First Analytics: We use privacy-respecting analytics that don’t track individuals or use cookies
- Transparent Processing: You know exactly what data we handle and why
- Secure Storage: All data is encrypted and protected
- Your Control: You can request deletion of your data at any time
Information We Collect
1. Contact Form Submissions
When you submit our contact form, we collect:
- Your name
- Email address
- Message content
Purpose: To respond to your inquiries and provide support. Storage: Contact form data is processed via Inngest and not permanently stored. We only retain your email in our inbox for correspondence purposes.
2. Browser Data (localStorage)
We store preferences locally in your browser to enhance your experience:
- Search History: Recent searches in command palette
- Bookmarks: Saved blog posts and pages
- Likes: Activity engagement (blog posts, projects)
Purpose: Personalize your experience with saved preferences. Storage: Client-side only (not shared with server unless you log in). Control: Clear via browser settings or our UI.
3. Session Data
For certain interactive features, we create temporary encrypted sessions:
- Session identifier (randomly generated)
- Temporary preferences
Purpose: To maintain state for interactive features. Storage: Encrypted in Vercel Redis (managed Redis service) with automatic expiration (24-48 hours). Security: All session data is encrypted using industry-standard encryption (AES-256-GCM). Provider: Vercel (powered by Upstash infrastructure, GDPR-compliant)
4. Server Logs
Our hosting provider (Vercel) automatically collects:
- IP address (anonymized)
- Browser type and version
- Pages visited
- Timestamps
Purpose: Security monitoring, error detection, and performance optimization. Retention: Automatically deleted after 30 days (Vercel’s standard retention).
5. Public Data (GitHub)
We display publicly available data from GitHub:
- Repository stars and forks
- Public activity feed
Source: GitHub’s public API. Note: This data is already publicly accessible on GitHub.
What We Don’t Collect
We explicitly do not collect or use:
- Cookies: We set no cookies of our own. Third-party content you choose to load (the giscus comment box, an embedded YouTube or Vimeo player) is served by those providers and may set their own cookies once loaded
- Individual User Tracking: No cross-site tracking, user profiles, or behavioral analysis. Sentry Session Replay records a small sample of individual sessions for debugging; see Session Replay below
- Invasive Analytics: No Google Analytics, Facebook Pixel, or similar tracking platforms that follow users across the web
- Advertising Data: No ad networks or retargeting pixels
- Social Media Tracking: No social media plugins that track you
- Fingerprinting: We don’t create browser fingerprints or device identifiers
- Sensitive Personal Information: No SSN, payment info, health records, or similar sensitive data
Session Replay
Our error monitoring includes Sentry Session Replay, which reconstructs what happened in the browser leading up to a problem.
- When it runs: roughly 5% of sessions on dcyfr.ai, plus 50% of sessions in which an error occurs. Sibling sites sample about 1%.
- What it captures: DOM mutations, clicks, scrolls, navigation, and network timing, which is enough to replay the sequence of events.
- Masking: text content and media are masked at capture, in the browser, before anything is transmitted. A replay shows layout and interaction, not the words on your screen. Form inputs are masked on the same basis.
- What it is used for: reproducing faults. It is not used for analytics, profiling, marketing, or measuring individuals.
- Retention: replays are stored by Sentry and expire on Sentry’s retention schedule.
- Opting out: block
sentry.ioin your browser, or use an extension that blocks error-monitoring scripts. Every site in the estate works without it.
Analytics (Privacy-First)
We use Vercel Analytics and Speed Insights to understand how our website performs. Unlike traditional analytics platforms, these are privacy-first services:
What We Collect
- Page Views: Aggregated visitor counts (no individual tracking)
- Performance Metrics: Page load times, Core Web Vitals
- Geographic Data: Country-level location (no precise location)
- Referrer Data: Where visitors come from (aggregated)
Privacy Protections
- No Cookies: Vercel Analytics does not use cookies
- No User Tracking: Does not track individuals across sessions or websites
- No User Profiles: Does not create profiles or behavioral data
- GDPR Compliant: Fully compliant with GDPR and privacy regulations
- Aggregated Only: All data is anonymized and aggregated
How This Differs from Traditional Analytics
Vercel Analytics is fundamentally different from Google Analytics, Facebook Pixel, and similar platforms:
- Does not track individual users or create identifiers
- Does not share data with advertisers or third parties
- Does not use cookies or persistent storage
- Does not follow users across different websites
- Uses edge computing to aggregate data before storage
Data Retention & Control
Retention: Analytics data is retained for 30 days (Vercel’s standard retention). Opt-out: You can opt out by enabling “Do Not Track” in your browser settings. Learn More: Vercel Analytics Privacy Policy
Third-Party Services
We use the following trusted third-party services to operate our website:
Vercel (Hosting & Infrastructure)
- Purpose: Website hosting, content delivery, and performance optimization
- Data Processed: Server logs (IP addresses, user agents, page visits)
- Privacy Policy: Vercel Privacy Policy
- Location: Data centers in the United States
Inngest (Background Jobs)
- Purpose: Processing contact form submissions and scheduled tasks
- Data Processed: Contact form data (name, email, message) - transient only
- Privacy Policy: Inngest Privacy Policy
- Retention: Job data deleted after 7 days
Sentry (Error Monitoring)
- Purpose: Error tracking, performance monitoring, uptime monitoring, and session replay
- Data Processed: Error messages, stack traces, anonymized user context, and masked session recordings (see Session Replay)
- Privacy Policy: Sentry Privacy Policy
- PII Scrubbing: Automatically removes sensitive information from error reports
Axiom (Web Vitals Analytics)
- Purpose: Real-time performance monitoring and Web Vitals tracking
- Data Collected: Core Web Vitals metrics (LCP, FID, CLS, FCP, TTFB, INP), user agent, device type, connection type, geographic location (country-level), route path
- Privacy Policy: Axiom Privacy Policy
- Retention: Performance data retained for 30 days
- Privacy Features: No individual user tracking, aggregate metrics only
Vercel Redis
- Purpose: Encrypted session storage for interactive features
- Data Stored: Encrypted session identifiers and temporary preferences
- Privacy Policy: Vercel Privacy Policy | Vercel Redis Integration
- Infrastructure: Powered by Upstash, managed by Vercel
- Data Centers: Global regions (GDPR-compliant)
- Retention: Automatic expiration after 24-48 hours
Resend (Transactional Email)
- Purpose: Delivering and tracking replies to contact form submissions
- Data Processed: Your name and email address, recorded as a contact so correspondence threads correctly
- Marketing: Contacts created from the contact form are stored unsubscribed. Submitting the form does not sign you up for anything
- Privacy Policy: Resend Privacy Policy
Cloudflare Web Analytics
- Purpose: A second, cookieless measure of page performance and traffic
- Data Processed: Page URL, referrer, user agent, and country, all aggregated, with no identifier that persists between visits
- Privacy Policy: Cloudflare Privacy Policy
giscus (Comments)
- Purpose: Comment threads on articles, backed by GitHub Discussions
- Data Processed: Loaded in an iframe from giscus.app. If you sign in to comment, you authenticate with GitHub and your comment is public in the linked discussion
- Cookies: giscus and GitHub may set cookies once the comment box loads
- Privacy Policy: giscus | GitHub Privacy Statement
YouTube and Vimeo (Embedded Video)
- Purpose: Playing embedded video within articles
- Data Processed: Loading a player shares your IP address and user agent with the provider, which may set cookies
- Privacy Policy: Google Privacy Policy | Vimeo Privacy Policy
Anthropic (dcyfr.bot only)
- Purpose: Generating agent replies in the dcyfr.bot preview chat
- Data Processed: The message text you send, transmitted to Anthropic to produce a reply
- Scope: This processor applies only to dcyfr.bot. No other site in the estate sends anything to a model provider
- Privacy Policy: Anthropic Privacy Policy
GitHub (Public Data)
- Purpose: Displaying public repository activity and project information
- Data Accessed: Public repository data only (stars, forks, activity feed)
- Privacy Policy: GitHub Privacy Statement
How We Use Your Information
We use the minimal data we collect only for these purposes:
- Communication: To respond to your contact form inquiries
- Security: To protect against abuse, spam, and malicious activity
- Performance: To optimize website performance and fix errors
- Legal Compliance: To comply with applicable laws and regulations
We never sell, rent, or share your personal information with third parties for marketing purposes.
Data Security
We implement industry-standard security measures to protect your information:
- Encryption in Transit: All data transmitted via HTTPS/TLS 1.3
- Encryption at Rest: Session data encrypted using AES-256-GCM
- Access Control: Strict authentication and authorization for all systems
- Security Monitoring: 24/7 automated security scanning and alerts
- Regular Audits: Monthly security audits and vulnerability scanning
- Incident Response: Documented procedures for security incidents
Data Retention
We retain data only as long as necessary:
- Contact Form Data: Not stored (transient processing only)
- Session Data: Automatically deleted after 24-48 hours
- Server Logs: Deleted after 30 days (Vercel retention policy)
- Error Logs: Retained for 90 days for debugging (Sentry)
- Session Replays: Retained on Sentry’s replay retention schedule, then deleted
- Email Correspondence: Retained in inbox until conversation complete
Your Privacy Rights
You have the following rights regarding your personal information:
- Right to Access: Request a copy of the data we have about you
- Right to Deletion: Request deletion of your data
- Right to Correction: Request correction of inaccurate data
- Right to Object: Object to processing of your data
- Right to Portability: Request your data in a portable format
To exercise these rights, contact us.
International Users
DCYFR Labs operates from Colorado in the United States. If you access our website from outside the United States, please be aware that:
- Your information may be transferred to and stored in the United States
- U.S. data protection laws may differ from those in your country
- By using our website, you consent to this transfer and processing
For users in the European Economic Area and the United Kingdom, the rights listed above apply in full, and the legal bases we rely on are set out at the end of this policy. Collecting little data reduces how much is at stake, but it is not by itself compliance, so we describe what we actually do rather than claim a verdict on it.
EU and UK representatives
Article 27 of the GDPR requires a controller established outside the Union to designate a representative inside it when the controller offers services to, or monitors the behaviour of, people in the EU. The UK GDPR sets a parallel requirement for the United Kingdom.
No representative is currently designated for either. That is a gap, and we would rather state it than leave the question unanswered. Until one is appointed, people in the EU and the UK can reach the controller directly through our contact page, and every right described above is available to them on the same terms as to anyone else. You may also lodge a complaint with the supervisory authority in your country of residence, which you can do whether or not a representative exists.
Children’s Privacy
Our website is not directed to children under 13 years of age. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately and we will delete it.
Changes to This Privacy Policy
We may update this privacy policy from time to time. When we do:
- We will update the “Last Updated” date at the top of this page
- For significant changes, we will provide prominent notice on our website
- We encourage you to review this policy periodically
Contact Us
If you have questions, concerns, or requests regarding this privacy policy or our data practices, please contact us. We aim to reply within five working days. Where a request is one of the rights listed above, the GDPR allows a controller one month to answer it, and we will not take longer than that.
Legal Basis for Processing (GDPR)
For users in the EEA, our legal basis for processing personal data is:
- Consent: When you submit a contact form or engage with interactive features
- Legitimate Interests: To operate our website, improve performance, and ensure security
- Legal Obligation: To comply with applicable laws and regulations
DCYFR Labs Privacy Policy