Privacy.
What this site collects, why, and how long it’s kept.
Last updated: 24 July 2026
tapia.us is a personal website operated by an individual. This policy explains the limited data the site processes when you visit it or use its tools. Plain language, no dark patterns.
What is collected
The site is intentionally minimal. It sets no advertising or cross-site tracking cookies. Data is limited to:
- Server logs. Like almost every web server, requests are logged. Each entry may include your IP address, the requested URL, the date and time, HTTP status, referrer, and browser user-agent string.
- Rate limiting. The interactive tools throttle abusive traffic using an in-memory record of your IP address and the last time it made a request. This is transient, held only in memory, and not written to a database.
- Analytics (if enabled). Aggregate, cookieless analytics may be used to count visits and see which pages and referrers are popular. It does not build a profile of you or track you across other sites.
- Email. If you email the contact address, your message and email address are processed so a reply can be sent.
The site does not have user accounts, does not ask for personal details through forms, and does not process payments.
The tools
The utilities under /tools (such as the request inspector, encoders, and TLS certificate inspector) run each request on the server and return a result. Input you submit is processed to produce that result and is not stored beyond the standard server logs described above. The TLS inspector connects to the domain you enter in order to read its public certificate.
Why it’s collected
- To run and secure the site — logs and rate limiting help keep the service available and defend against abuse.
- To understand usage — aggregate analytics show which pages are useful, without identifying individuals.
- To respond to you — if you choose to make contact.
Where GDPR applies, the basis for this processing is legitimate interest in operating and securing a personal website, and — for email — responding to your request.
Retention
Server logs are rotated and deleted on a rolling basis, typically within 90 days. Rate-limit records exist only in memory and disappear within seconds. Analytics data, where used, is aggregate and retained only as needed to see trends. Emails are kept as long as needed to handle the conversation.
Sharing
Your data is not sold. It is not shared with advertisers. It may pass through infrastructure providers strictly needed to run the site (for example, the server host and, if used, an analytics provider), and may be disclosed if genuinely required by law.
Your choices
Because no tracking cookies are set, there’s nothing to opt out of in your browser for this site. Depending on where you live, you may have rights to access, correct, or delete personal data the site holds about you. To make a request, or to ask anything about this policy, email hello@tapia.us.
Changes
This policy may be updated as the site evolves. The “last updated” date above reflects the current version.
This document is provided for transparency and is not legal advice.