Privacy by design

No banner.
No tracking.

Every site built on our new system starts with nothing to declare: no advertising cookies, no trackers, no tracking consent banner. Analytics that count without identifying anyone, maps that load without Google, forms protected without a puzzle, fonts served from our own domain. This page is built the same way, and it can prove it.

Diagrams are illustrative where marked.

01 · Counting without identifying

Analytics that never learn who you are.

We run our own instance of Umami, an open-source analytics tool, on our own server. It counts pages and visits. It sets no cookie, stores no IP address, keeps no profile, and we strip the screen size before the data even leaves your browser.

Illustrative

How one visit is counted

Day 1

01 · Your visit

From your browser to our door

Sent by your browser

Pagecounted
/expertise/privacy
Referrercounted
duckduckgo.com
Browsercounted
Firefox · macOS
Devicecounted
Desktop
Screen sizeremoved before sending
1440 × 900

Seen at the door

IP addresshashed, never stored
203.0.113.42
Countryread from the address
Canada

02 · One-way hash

At the door of our own server

Waiting for a visit

Today
7fd5 da15 d917 630b…

siteaddressbrowsersaltNo way back to the address

03 · The count

What is kept

12Pageviews today
5Visits today

Counted from this visit

  • —
Pageviews by dayIllustrative numbers

Illustrative pageviews by day: between 24 and 52 on earlier days, 12 so far today.

Send a visit and follow it from your browser to the count.

What we can see

  • Pages visited
  • Referrers
  • Countries
  • Browser and system
  • Device class
  • Visits over time

What we never have

  • Names
  • Email addresses
  • Raw IP addresses
  • Cross-site profiles
  • Screen sizeremoved before sending
  • Cookiesnone is set

The mechanism is Umami’s, run on our own server. The browser, system, device, screen and first referrer are yours, read in this tab and sent nowhere; the address, the hashes and the numbers are examples.

02 · Maps

A map that loads without Google.

A map on a site usually means Google, and Google means cookies, scripts and a request to Google before you have touched anything. We draw ours with MapLibre, an open-source engine, on open map tiles: no account, no cookie, no script from an advertising company.

© OpenStreetMap · OpenMapTiles · OpenFreeMap

LiveRead from your browser

Requests this map has made

0
None yet
  • Map tiles0
  • Letters0
  • Icons0
  • Style0
  • Tile index0

The last 60 seconds

Each square that lights up on the map is one of these requests.

Latest requests

Nothing yet. The map asks for nothing until you reach it.

Requests to Googlewhole page, so far

0
Before you touch anything
An embedded Google mapDescribed, never loaded hereThis mapCounted live
As the page opensYour browser contacts Google before you have touched the map.Your browser asks an open tile host for squares of map, and only once you reach it.
Code on the pageGoogle’s scripts load and run inside the page.MapLibre, open source, served from our own domain.
CookiesGoogle sets its cookies before any click.None. No account, no key, no advertising script.

The tile host sees which squares you load, like any image server. It sets no cookie and runs no code here.

03 · Forms

Protected without a puzzle.

Our forms are protected by Cloudflare Turnstile, which checks that a browser is a browser without cookies, without traffic lights to click and without following you afterwards. What you write goes into our own database, through a role that can only write, and nowhere else.

Illustrative · the mechanism is real

Choose a station to see what it can read, or send an example through.

What each station sees of one submission
What travelsYour browserCloudflare TurnstileOur serverA database functionThe inbox
What you writename, message, phone, businessAlex · “A new site?”typednever sees itchecks itstores itread by us
Your emailto write back to youalex@example.comtypednever sees itchecks ithmac b41e…90d2kept · its hash countsto write back
Your IP addresssent with every request203.0.113.24sentsees the connectionchecks the token with ithmac 7f3a…c19ehashed, then droppednot stored
The check’s tokenproof of a real browserissuedverified · droppednot stored
Cookiesset by the form or the check0None, at any station
01

Your browser

Where you type

The form leaves for our own server, and only there.

Can see

  • Everything you write, as you write it.
  • A small Cloudflare frame that runs the check, on the contact page only.

Never

  • A cookie, from us or from the check.
  • A puzzle to solve.

04 · Fonts, video, embeds

Nothing loads from elsewhere until you ask.

Fonts are served from our own domain. Video plays from our own storage. A player from YouTube or Vimeo is not contacted until you choose to play it, and where the platform offers one, its privacy-enhanced mode is used.

Illustrative · a common pattern, no particular site

Move through time and watch what each page asks for, and from where.

Ours

Talked to so far

  • mystya.com
  • our storage
  • analytics.mystya.com
Typical

Talked to so far

  • example.com
  • a tag service
  • a fonts service
  • a consent service
  • a video platform
  • an ad network
  • a social network

A page we build

  1. The pagemystya.com
  2. Our stylesmystya.com
  3. Our fontsmystya.com
  4. Our imagesour storage
  5. Our analyticsanalytics.mystya.comproduction only · no cookie
  6. Embedded videonothing yetLoads only when you press play

A typical site with a consent banner

  1. The pageexample.com
  2. Stylesexample.com
  3. Tag managera tag service
  4. Fonts from a CDNa fonts service
  5. Imagesexample.com
  6. Consent bannera consent service
  7. Embedded playera video platformbefore anyone presses play
  8. Advertising pixelan ad network
  9. Social pixela social network
From elsewhere
0
Banner
None
From elsewhere
6
Banner
Yes
  • The site’s own domain or storage
  • Somewhere else
  • Can set cookies
  • Waits for you

05 · The law

Privacy law, without the theatre.

PIPEDA, Québec’s Law 25 and the GDPR differ in scope, but they share a practical principle: collect only what you need, explain what you collect and why, and protect it appropriately. The simplest privacy posture starts by collecting less in the first place. On a site we build, what is collected is what you send through a form, with only the details needed to handle it, and the policy says so in plain words.

Data map · a site built here

Illustrative
5fields, two optional

Choose a question. Arrow keys work too.

01 / 04

What is collected

What you send, and only the details needed to handle it.

The contact form

  • NameRequired
  • EmailRequired
  • PhoneOptional
  • BusinessOptional
  • MessageRequired

Kept with it

  • The language you wrote in
  • The time you sent it

To stop repeat sends

Email · IP addressKeyed hashes

Never the addresses themselves, nor the check’s token. Old hashes are cleared at the next send.

Page visits are counted by our own analytics, without a cookie and without knowing who you are. See section 02

02 / 04

Where it lives

In the studio’s own database. Not in someone else’s tool.

  1. Your browserSends the form over HTTPS
  2. The siteHosted by VercelWrite only
  3. The databaseNeon · where the message is kept
Media · Images and video on Amazon S3, never your data.

Every provider is named in the privacy policy. Some host in the United States, and the policy says so.

Read the privacy policy

03 / 04

Who reads it

The studio, in a local application. Nobody else.

  • The studioReads the inbox in a local application.Reads
  • The siteCan write your message. Cannot read it back.Writes only
  • Cloudflare TurnstileChecks the browser, never the message.Checks only

Never passed to

  • Marketing tools
  • Third-party CRMs
  • Data buyers

04 / 04

What you can ask

To see it, correct it or withdraw it. One email is enough.

  1. SeeAsk what the studio holds about you.
  2. CorrectHave anything inaccurate fixed.
  3. WithdrawTake back your consent to its use.

The person responsible for personal information reads this address.

What a site built here does not do

By design
  • No advertising cookiesNothing is set for an advertiser.
  • No retargetingLeaving the site means leaving it.
  • No social pixelsNo platform script watches the page.
  • No fingerprintingNo device probing, no cross-site identifier.
  • No tracking consent bannerNo non-essential tracking to consent to.

Three laws, three demands, one answer.

A summary, not legal advice.
DemandPIPEDACanadaLaw 25QuébecGDPREuropean UnionThe answer, by design
MinimiseCollect littleLimiting collectionOnly what is necessaryData minimisationFive fields, two optional. No cookie, no lasting identifier, no profile.
SaySay what you collectOpennessA policy in clear, simple termsTransparencyOne policy in plain words. Every provider named, hosting abroad disclosed.
ProtectKeep it safeSafeguardsReasonable security measuresIntegrity and confidentialityA write-only door, hashed rate limits, an inbox read by the studio alone.

The practice

Privacy is a design decision.

It is not a banner added at the end. It is decided page by page: which script earns its place, which service touches your visitors, which default is the right one. We make those decisions in your favour, and we show our work.

What this page shows is our new system, the way we build today. Sites we delivered before it may not include it.

Want a site with nothing to declare?

Tell us what you have today. We will tell you what it loads.