Effective date: August 19, 2026
Ing. Oliver Herklotz ("I", "me", or "my"), operating the websites listed below under the name "hrkltz", is committed to protecting your privacy. This Privacy Policy explains what those websites process, why, on what legal basis, how long anything is kept, and what rights you have over it.
The short version: no cookies, no analytics products, no advertising, no third-party services, no big-tech infrastructure. The detail below exists because "we collect nothing" would not be quite true — a web server cannot serve a page without seeing the request — and you are entitled to the specifics rather than the slogan.
This Privacy Policy covers the following websites:
My iOS apps have their own dedicated privacy policies: Astryn and Codaic Pocket.
The controller for the processing described here is:
Ing. Oliver HerklotzI have not appointed a Data Protection Officer. These are small personal and open-source projects run by one person; none of the thresholds that would require one (GDPR Art. 37, Swiss FADP Art. 10) is met.
I am based in Switzerland, so the Swiss Federal Act on Data Protection (FADP) applies to everything described here. Because these websites are also aimed at visitors in the European Union and the EEA, the GDPR applies in parallel under its Art. 3(2), and this policy is written to satisfy both. Where the two differ, I apply whichever is stricter.
Every request to a web server is seen by that server. Mine records, for each request: your IP address, the requested URL and query, the HTTP method and response status, the time, how long the response took, your browser's user-agent string, and a randomly generated correlation identifier.
This is the one place a raw IP address is processed, and it is never combined with the visit statistics below.
I count page views with my own software on my own server. For each view one record is written containing: the time, which of my domains was visited, the requested path and query, the HTTP method, your browser's user-agent string, the referring URL if your browser sent one, and a hash of your IP address. No other request headers are kept.
The IP address itself is never stored. What is stored is SHA-256 of the address combined with a secret salt that never leaves my server and with the current UTC date. Two consequences follow, and both are deliberate:
I want to be precise rather than flattering here: these records are pseudonymous, not anonymous. I hold the salt, so within a single day I could in principle test whether a specific address appears. I do not do this, the daily change caps the window at 24 hours, and the records are deleted anyway — but "cannot be traced back to you" would be an overstatement, so I am not making it.
Two of the websites have a contact form, and they ask for slightly different things:
Nothing beyond those fields is captured with a submission — no hidden identifiers are added to it, and the form does not read anything from your device.
I set no cookies at all — none for analytics, none for advertising, none for tracking, and none for anything else.
One site, openhanse.org, saves a single display preference (which of its two views you last had open) in your browser's local storage so the page looks the way you left it. That value never leaves your device, is not sent to my server, and identifies nothing about you. It is strictly necessary to provide the feature you yourself selected, which is why there is no consent banner: there is nothing to consent to. Clearing your browser's site data removes it.
I do not sell, rent, or share personal data, and I integrate no third-party analytics, advertising, or tracking services in my code. Web fonts are served from my own servers rather than from a font CDN, precisely so that visiting a page does not disclose your IP address to a third party. There are no embedded videos, no social media widgets, no consent-management platform, and no content delivery network in front of the sites.
The only third parties involved at all are:
Beyond these, personal data is disclosed only where I am legally obliged to do so.
The servers are in Germany, at Contabo GmbH. So if you are in the European Union or the EEA, everything described above — the request log, the visit records, contact form messages in transit — is stored and processed inside the EU, and there is no transfer to a third country for you to be concerned about.
The one movement of data out of the EU is me: I am based in Switzerland and administer the servers from there, so I access the data from a third country. Switzerland is recognised by the European Commission as providing an adequate level of data protection, so that access rests on an adequacy decision under GDPR Art. 45 and needs no further safeguards or consent from you. There are no transfers to any other country, and no data is stored outside the EU.
Under the GDPR and the Swiss FADP you have the right to:
To exercise any of these, write to gruezi@hrkltz.io. Exercising them is free and I will respond within one month. One practical caveat, which is a consequence of the design rather than a way of avoiding the request: for the visit statistics I have no way to find "your" records, because I hold no identifier of yours to search for — the stored hash cannot be worked backwards, and I would need your IP address to recompute it. If you send it to me I can look, but that means handing over more data than is currently stored about you, so in most cases the better answer is that the records are gone within 90 days regardless.
You have the right to object at any time, on grounds relating to your particular situation, to processing carried out on the basis of my legitimate interests (GDPR Art. 6(1)(f)) — which here means the request log and the visit statistics. If you object, I will stop that processing unless I can demonstrate compelling legitimate grounds that override your interests, rights and freedoms. An objection is enough on its own; you do not have to justify it beyond describing your situation. Send it to gruezi@hrkltz.io.
Since I do no direct marketing, the unconditional objection right in Art. 21(2) never arises — there is nothing to opt out of.
If you believe my processing infringes data protection law, you can lodge a complaint with a supervisory authority. Within the EU/EEA you may complain to the authority in the member state of your habitual residence, your place of work, or the place of the alleged infringement (GDPR Art. 77). In Switzerland the competent authority is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern.
You are welcome to raise the matter with me first, but you are not required to.
There is none. I do not carry out automated decision-making producing legal or similarly significant effects, and I do not profile visitors (GDPR Art. 22).
All sites are served over HTTPS only. The secret used to hash IP addresses is stored separately from the records it protects and never leaves the server. Each website runs as its own unprivileged service with no database of its own. Access to the server is restricted to me.
I may update this Privacy Policy from time to time. If I make changes, I will update the effective date at the top of this page.
Questions about this Privacy Policy, or any request under the rights listed above: gruezi@hrkltz.io. Postal address in my Imprint.