Privacy Policy
Last updated: August 6, 2026
This website, diegoramosretamal.info, is operated by Diego Ramos Retamal. For any question about data processing on this site, contact hello@diegoramosretamal.info.
This page describes the analytics service used on this website and the cookies it sets. It will be extended to cover other data processing as it is documented.
Umami Cloud
This site uses Umami Cloud, a cookie-free, first-party web analytics service operated by Umami Software, Inc., to understand how visitors use the site in aggregate.
Data processed: pages viewed (URL path and any query parameters present in the address), the referring page (if any), device type, browser, and an approximate country. Your IP address is processed briefly to derive the approximate country and is not stored.
No cookies, no cross-site tracking, no profiles: Umami does not set cookies and does not use local or session storage to identify you. It does not track you across other websites, and it does not build a profile of you as an individual visitor. Data is only used in aggregate, alongside other visitors.
Legal basis: this processing relies on Art. 6(1)(f) GDPR — our legitimate interest in measuring, in aggregate, how the site is used, so we can understand what content is useful.
Hosting: Umami Cloud processes this data on servers located in the EU (Germany). No transfer outside the EU takes place for this service.
Processor: Umami Software, Inc. acts as a processor under Art. 28 GDPR. Processing is governed by Umami's Data Processing Agreement, available at umami.is/dpa.
Retention: aggregated analytics data is retained for the period specified by the Umami Cloud plan in place for this site, after which it is deleted automatically.
Hosting analytics: Vercel Web Analytics is also enabled through the hosting adapter and processes aggregate page-usage data under Vercel's privacy and data-processing terms.
First-party visit notifications
When you visit this site, a server-side notification may be sent to the site owner in real time. Notifications use an ntfy server configured by the site owner; if no custom server is configured, the integration defaults to the hosted service at ntfy.sh. No advertising network or cross-site tracker is involved.
Data processed: pages viewed, the referring site (if any), device type, operating system, browser, screen size, browser language, timezone, and an approximate location (city level) derived briefly from your IP address by the hosting provider. Your IP address itself is not stored and is not included in the notification. Messages you type into the site's chat assistant are also delivered to the site owner in real time — please don't include personal data you don't want to share.
Session identifier: a random, meaningless identifier is kept in your browser's session storage so that page views within a single visit can be grouped together. It contains no personal data, is not a cookie, cannot identify you, and is deleted automatically when you close the tab or browser.
Legal basis: this processing relies on Art. 6(1)(f) GDPR — our legitimate interest in knowing, in real time, that the site is being visited and which content is viewed.
Retention: this site does not store notifications in its own database. Delivery and retention by the configured ntfy server are governed by that server's settings and privacy terms.
OpenAI processing
When you use the chat assistant, your current conversation, active page title and route, and any selected project context are sent to OpenAI to generate a response. The latest message and limited session context may also be sent to the configured ntfy service so the site owner can receive it.
Data processed: chat messages, conversation history sent with the request, page context, and project context. Do not include sensitive personal data.
Legal basis: processing is necessary to provide the chat response you request and relies on Art. 6(1)(b) GDPR; related service monitoring relies on Art. 6(1)(f) GDPR.
Recipients and transfers: OpenAI acts as an external service provider. Its processing and any international transfers are governed by OpenAI's applicable data-processing terms and privacy policy. The configured ntfy provider may also receive notification content.
Local retention: conversation history is stored in your browser's session storage and is deleted when the tab or browser session ends. This site does not store chat history in its own database.
Case study access cookie
Some case studies on this site are protected by a password. When you enter the correct password, this site sets a single first-party cookie named cs_unlocked so you are not asked for the password again on each visit. It is the only cookie this site sets.
What it contains: a version number, an expiry timestamp, and an HMAC signature. It contains no personal data or visitor identifier, does not contain the password, and is not used to recognise or track you beyond remembering access to protected case studies.
Technical characteristics: the cookie is first-party, marked HttpOnly, Secure, and SameSite=Strict, and expires automatically after 7 days. It is never sent to third parties.
Legal basis: this cookie is strictly necessary to provide a service you explicitly request — access to password-protected content — and is therefore exempt from consent under the ePrivacy rules (Art. 5(3) ePrivacy Directive). The associated processing relies on Art. 6(1)(f) GDPR.
How to remove it: you can delete the cookie at any time through your browser settings; the protected case studies will simply ask for the password again.