Skip to content

Privacy policy

I take your privacy seriously

This policy explains how John Andersen, trading as Webstudiet, handles personal data when you browse the website, use the contact form, URL Analyzer, Email Deliverability Test or Password Tool, or work with me on a project. I collect only the information needed to run these services, protect the website, respond to enquiries, and deliver agreed work.
  • Data controller and contact. John Andersen, Webstudiet, is responsible for the processing described here. Questions and privacy requests can be sent to ja@webstudiet.com or through the contact page.
  • Contact form and enquiries. When you use the contact form, I receive your name, email address, optional project URL, message, and selected language. Resend processes these fields to deliver the email. Cloudflare Turnstile may process the challenge token, IP address, and technical request data to prevent spam and abuse.
  • URL analyzer. When you submit a public URL, the analyzer fetches that page and checks its HTML, response headers, redirects, DNS, robots and sitemap signals. Your IP address is used temporarily to enforce a limit of five analyses per hour and may be sent to Cloudflare Turnstile for abuse prevention. Completed results, including the submitted and final URL, may be cached for up to 24 hours. The analyzer may request supporting evidence from Google PageSpeed Insights, MDN HTTP Observatory, Cloudflare DNS, and the website being analyzed. Do not submit private URLs, credentials, tokens, or addresses that should not be fetched by these services.
  • Email Deliverability Test. When you create an email test, the service provides a private, temporary address that accepts one message for 30 minutes. Resend receives the message and makes its body and headers available to Webstudiet for analysis. Webstudiet processes that content in memory, does not download attachments, and stores only derived findings, the sender domain, body formats, attachment count, message type, and timestamps for up to 24 hours. The private report token remains in the URL fragment in your browser. Your IP address is hashed for rate limiting and may be sent to Cloudflare Turnstile for abuse prevention. Do not submit confidential messages, credentials, sensitive personal data, or attachments that Resend and Webstudiet should not process.
  • Password Tool and encrypted sharing. Password generation and checking happen locally in your browser; the entered or generated password is not sent to Webstudiet. When you create a one-time share, your browser encrypts the secret before upload. Webstudiet stores the ciphertext, initialization vector, a one-way key check, and timestamps. The active record is deleted when claimed; expired links are refused immediately and cleanup is scheduled for the selected expiry of 15 minutes, one hour, or 24 hours. Provider recovery retention is described below. The decryption key remains in your browser and, unless you choose to send it separately, in the URL fragment. The tool does not collect a recipient email address or send an email; you copy the resulting link into your chosen communication service. Your IP address is hashed to enforce separate limits of five new shares per hour and 30 retrieval attempts per 15 minutes. Hashing does not make an IP address anonymous. Anyone who obtains both the link and key before expiry can reveal the secret.
  • Browsing and security data. Cloudflare hosts and protects the website. Like other hosting and security providers, it may process IP addresses, request headers, timestamps, requested paths, and security events needed to deliver the site, prevent abuse, and diagnose faults.
  • Cookies and local storage. The site stores only your light or dark theme preference in local storage. It does not store contact-form entries in your browser. Cloudflare Turnstile may use technically necessary browser storage or cookies when performing a security challenge. No advertising, cross-site profiling, or audience analytics scripts are currently installed. If that changes, this policy and any required consent controls will be updated first.
  • Why the data is used. Contact details are used to answer your enquiry, prepare requested work, and communicate about a possible or active contract. Technical request data, encrypted password-share data, email-test data, rate limiting, caching, and Turnstile are used to provide, secure, and operate the website and its tools. These activities rely on steps requested before a contract, performance of a contract, legal obligations where applicable, and Webstudiet's legitimate interests in providing secure and reliable services. Consent is used only where a feature specifically asks for it.
  • AI-assisted work. I may use AI-assisted development or writing tools for analysis, code review, debugging, drafting, or summarising public and technical material. I do not intentionally send confidential client material, credentials, private customer data, or sensitive personal data to AI tools without agreement. AI output is reviewed before use, and no automated decisions with legal or similarly significant effects are made about clients or visitors.
  • Service providers and processors. The main providers used for the public website are Cloudflare for hosting, security, caching, DNS and Turnstile; Resend for contact-email delivery and receiving messages submitted to the Email Deliverability Test; Google PageSpeed Insights and MDN HTTP Observatory for optional analyzer evidence; and the operators of any website submitted to the URL Analyzer. Providers may process data outside your country. Where data-protection transfer rules apply, the transfer relies on the provider's applicable contractual and legal safeguards. I do not sell personal data.
  • Data retention. URL Analyzer results and derived Email Deliverability Test reports are stored for no more than 24 hours. Email test addresses stop accepting messages after 30 minutes. Encrypted password shares are removed from active storage when claimed, and automatic cleanup is scheduled at expiry. Expired shares cannot be retrieved even if cleanup is delayed. Cloudflare SQLite Durable Objects support point-in-time recovery for up to 30 days, so encrypted data may remain in provider recovery history after active deletion. This is not a promise of immediate physical erasure; the decryption key is not stored with that data. IP addresses used for rate limiting are hashed before they become Cloudflare Durable Object lookup keys, and expired counters are deleted automatically. Resend currently retains received email content according to the retention period of the Webstudiet account, which may be longer than Webstudiet's 24-hour report period. Contact messages and project correspondence are kept only while needed to answer the enquiry, deliver the work, document the relationship, or meet applicable accounting and legal obligations. Provider security and delivery logs follow the provider's configured or contractual retention periods. Your theme preference remains in your own browser until you clear it.
  • Your rights. Depending on the law that applies, you may request access, correction, deletion, restriction, or portability of your personal data, and object to processing based on legitimate interests. You may withdraw consent where consent is the legal basis. A request may be limited where retention or processing is required by law or necessary to establish, exercise, or defend a legal claim.
  • Complaints and questions. Send questions or requests to ja@webstudiet.com. You may also complain to the data-protection authority responsible for your location. In Denmark, that authority is Datatilsynet.
  • Policy updates. This policy was last updated on 21 September 2026. It will be revised when the website's processing, providers, or legal obligations change materially.