Privacy Policy

Last Updated: July 31, 2026

The Simple Version

I respect your privacy. Any data collected through services I offer will not be sold, shared, or otherwise provided to anyone unless legally required to do so.

Data Collection

If you use any services I provide, I may collect minimal data necessary for the operation of those services. This could include:

Data Usage

Your data is used solely for:

Data Sharing

I will not:

Embedded Content

Some posts embed third-party content, usually videos. Where I do that, I use privacy-enhanced embeds that don’t set tracking cookies unless you actually press play.

Loading the page does still contact the provider, which tells them your IP address and which browser you’re using - the same thing that happens when you visit any website. I don’t see any of that, I don’t receive it, and I don’t collect it. It goes from your browser to them without passing through me.

Where it’s logically possible, I’ll put a plain link next to an embed, so if you’d rather it didn’t happen at all you can go and view the thing on your own terms instead.

I did consider going further, and having the page load nothing at all until you click a placeholder. I decided against it. That’s more moving parts on a site maintained by one person in his spare time, and a privacy control that quietly stops working is worse than a simple one you can see and reason about - it looks like protection while doing nothing. So you get a plain embed, described honestly above, with a link beside it. If that trade stops being a fair one, say if these ever start appearing on every page rather than the occasional post, I’ll revisit it.

I should be honest about the wider version of this, too. I run a lot of software I didn’t write - the site generator, the mail stack, the various pieces underneath them - and that software can carry its own embeds, outbound calls and logging that I never asked for and am not necessarily aware of. I don’t go looking for ways to track anyone, and I turn this stuff off where I find it. But “I didn’t intend it” is not the same as “it isn’t happening,” and I’d rather say that plainly than imply a personal compute lab has been audited line by line.

DMARC Reporting

To be a good internet citizen while hosting my own mail server, I participate in DMARC aggregate (RUA) reporting. This means I send and receive standard DMARC reports to and from other mail providers to help fight email spoofing and abuse.

These reports contain only summary information — such as sending IP addresses, authentication results (SPF/DKIM/DMARC pass or fail), and message counts. They do not include the content, subject lines, or recipients of any email message. This data is used solely to combat abuse and improve mail security and deliverability.

Your Rights

You have the right to:

Security

I make reasonable efforts to protect your data, but let’s be honest - this is a personal compute lab. See the main page for my track record on uptime and reliability.

Changes to This Policy

I may update this privacy policy from time to time. Any changes will be posted on this page.

Contact

If you have questions about this privacy policy or your data:


This privacy policy applies to all services offered by The Fat Hacker.

Disclaimer, as ever: this policy was written with the help of Claude Opus, and as ever I’ve read and approved every word. I am not a lawyer, this is not legal advice, and it’s a plain-language description of how a personal compute lab handles data - not an airtight legal contract. If you need the real thing, go pay someone who passed the bar.