DATA PROTECTION
PRIVACY POLICY
The short version
This website sets no cookies and runs no advertising, pixels, fingerprinting or profiling of any kind. There is one contact form; it sends only what you type into it, and only when you press send. There is one tool in the Lab; it takes a web address, checks that page and stores nothing. On page load the site calls one outside service — a cookieless analytics beacon — which costs two requests: the script that measures, and the measurement it posts back. A third request exists only for failure: if a request to us never completes, your browser reports that failure to Cloudflare, which already hosts this site. A page that loads sends nothing. Everything else — fonts, scripts, images, video, audio — is served from our own domain.
Below is the long version, including the two items we store in your own browser and why.
Controller
Black Oar Studio L.L.C.
1209 Mountain Road Pl NE, Ste N
Albuquerque, NM 87110
United States of America
Email: privacy@blackoarstudio.com
Where the General Data Protection Regulation applies to us under Article 3(2) — because we offer services to people in the European Union — we process personal data in accordance with it.
Hosting and server logs
This site is hosted on Cloudflare Pages, operated by Cloudflare, Inc. Serving a page necessarily involves your IP address reaching the server, and Cloudflare records standard access data for delivery, security and abuse prevention: IP address, timestamp, the resource requested, the response status, and the browser's user-agent and referrer string.
We set Referrer-Policy: no-referrer site-wide, so no referrer is sent when you
follow a link away from this site.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is delivering the site reliably and defending it against attack.
Cloudflare acts as our processor under a data processing agreement. Cloudflare, Inc. is a US company; transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, its certification under the EU–US Data Privacy Framework.
Network error reports
Cloudflare adds two headers, NEL and Report-To, to every response
from this site. They ask your browser to report requests to us that fail at the network level
— a connection that never opens, a name that does not resolve, a timeout. The sampling rate
in the NEL header is success_fraction: 0.0, and that means exactly
what it says: a request that succeeds is never reported, so a page that loads sends nothing.
Only a failure produces a report, and it goes to a.nel.cloudflare.com —
Cloudflare, the host already described above, not a further third party. Such a report
carries the address that was requested, the kind of failure and how long it took, plus your
IP address in transit, as any HTTP request must. Both headers sit in the response headers of
every page here; your browser's network panel shows them.
Legal basis: Article 6(1)(f) GDPR, the same interest as the logs above — we cannot repair a delivery fault we never hear about. Your browser remembers the reporting instruction for as long as the header says, the way it remembers any response header: that is a note about where to send a failure, not a cookie, not site storage, and not data about you.
Analytics
We use Cloudflare Web Analytics. It is the only third-party service this site loads.
It is deliberately the least invasive option available to us:
- It sets no cookies and writes nothing to your browser storage.
- It assigns no identifier to you, and cannot follow you across websites.
- It performs no fingerprinting.
- We see aggregate figures — page views, referrers, countries, device categories — never individuals, and never a path through the site attributable to one person.
It takes two requests, both to Cloudflare: the script beacon.min.js loads from
static.cloudflareinsights.com, and the measurement it takes is posted to
cloudflareinsights.com/cdn-cgi/rum. Open your browser's network panel and you
will see those two leaving our domain; on a visit where nothing fails, there is nothing else.
The only thing that can join them is the error report described under
Hosting and server logs. Both carry your IP address in transit, as any
HTTP request must. Neither is used to build a profile of you.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is understanding, at the level of totals, whether the site works and where visitors arrive from. Because the technique stores nothing on your device and identifies no one, we take the view that it does not require consent under Article 5(3) of the ePrivacy Directive or § 25 TDDDG. If you disagree, a tracker-blocking extension or browser will stop the beacon and the site will work normally.
What we store in your browser
Two entries, both functional, both first-party, neither containing personal data. Neither requires consent, because both exist solely to honour a choice you made yourself.
bos-motion — local storage, persistent
Written only when you press the MOTION control in the footer. Holds the single value
off when you have switched animation off, and is removed entirely when you
switch it back on. It exists so the site does not re-enable motion on you on every page.
Clear your site data to remove it.
bos-ambient — session storage, temporary
Written when you use the ambient audio player. Holds whether the track is playing and the playback position in seconds, so audio continues across page navigation instead of restarting. Your browser deletes it when you close the tab.
Nothing else is written. There are no cookies on this site, and no IndexedDB.
Contacting us
The contact panel offers two routes. You can copy our address and write from your own mail program — nothing reaches us until you send that message yourself. Or you can use the form, which submits your name, your email address and your message to us directly. The form sends nothing until you press send, sets no cookies, and keeps no draft outside your own browser window.
All three fields are required: the form will not send without them, and we cannot answer a message that carries no way to reply. Nothing obliges you to provide any of it — the only consequence of leaving it out is that no enquiry reaches us. The copy-and-write route needs nothing from you at all until you decide what to put in the mail yourself.
Two quiet defences sit on that form, both ours, neither a CAPTCHA. One is a field you cannot see: hidden from the page and skipped by the keyboard, so only an automated script ever fills it in. It is submitted with every message like any other field, and from a person it arrives empty — that emptiness is the whole check. The other is time — the form notes how many seconds pass between opening it and sending, because a bot posts instantly and a person does not. A submission that trips either check is discarded instead of delivered; in practice that only catches software, since two seconds is faster than anyone can write an enquiry. Neither check writes anything to your device, and neither involves a third party.
When you write to us — by either route — we receive and process what you send: your name, your email address, and the content of your message, together with anything else you choose to include. Messages sent through the form additionally carry the two-letter country code that Cloudflare derives from your IP address, so that we know which timezone we are answering into. We use all of it to answer you and, if we go on to work together, to run the engagement.
Legal basis: Article 6(1)(b) GDPR where the correspondence concerns a contract or its negotiation, otherwise Article 6(1)(f) — our legitimate interest in replying to people who write to us.
Retention: enquiries that lead nowhere are deleted within twelve months. Correspondence belonging to a project is kept for the life of the engagement and afterwards for as long as commercial and tax record-keeping obligations require.
Mail addressed to our domain reaches us in two stages. Cloudflare Email Routing accepts it first and forwards it to our mailbox. It does not keep the message, but it records delivery metadata — sender, recipient, timestamp and outcome — which we can see in a routing log. The mailbox itself is Gmail, operated by Google, and that is where the message is stored.
Messages from the form take a different path towards that mailbox: they are received by a Cloudflare Pages Function on our own domain and handed to Resend, our sending provider, which processes the contents in order to deliver them.
All three act as our processors under data processing agreements. Cloudflare, Inc., Google LLC and Resend are US companies; transfers rely on Standard Contractual Clauses and, where applicable, certification under the EU–US Data Privacy Framework.
Retention we do not set ourselves: Cloudflare's access and security logs, its analytics aggregates, the routing log for inbound mail and Resend's delivery log each run for the period that provider operates for the service. We hold no separate copy of any of them and cannot extend them. Where a provider documents a period, that period governs; where it does not, the data exists only as long as delivery, troubleshooting and abuse prevention require. The message itself, once it is in our mailbox, follows the twelve-month rule above.
The Machine Readability Check
Our Lab hosts a tool that takes the address of a web page and reports whether a machine can reach, read, identify and quote it. It asks nothing of you beyond that address: no name, no email, no account, and it sets nothing in your browser.
What happens when you press the button: the address travels to a Cloudflare Pages Function on
our own domain. That function requests the page once, plus the two files any crawler may ask
for — robots.txt and llms.txt — evaluates twelve fixed criteria and
returns the result. The request goes out from our servers, not from your browser, so the site
being checked sees us and not you. No outside service is involved, and the same two quiet
defences as on the contact form apply: an invisible field and a minimum fill time, neither of
which writes anything to your device.
We keep no record of what was checked. The finished report is held in Cloudflare's edge cache for fifteen minutes, keyed by the address, so that several people checking the same site do not make us knock on that site several times. That cached report describes a public web page, not you. The request itself appears in the ordinary server logs described under Hosting and server logs; nothing beyond that is written anywhere.
A web address is not normally personal data. It can be, if you enter one that identifies a person — a profile page, for instance — and in that case the address is processed exactly as described above and nowhere else. Legal basis: Article 6(1)(f) GDPR, our legitimate interest in providing the function you asked for.
What we do not do
For the avoidance of doubt, and verifiable by reading this site's source:
- No advertising, retargeting or conversion tracking of any kind.
- No Google Analytics, Tag Manager, Meta pixel, LinkedIn Insight tag, TikTok pixel, Hotjar, Clarity, Plausible, Fathom or Matomo.
- No cookie banner, because there are no cookies to consent to.
- No fonts, scripts, stylesheets, images, video or audio loaded from a third-party CDN.
- No embedded YouTube, Vimeo, Google Maps or social widgets. No iframes at all.
- No error-reporting or session-replay SDK — the browser's own network error reporting is described under Hosting and server logs.
- No newsletter, no mailing list, no marketing automation behind the contact form.
- No automated decision-making and no profiling within the meaning of Article 22 GDPR.
- We do not sell, rent or trade personal data. We never have.
Your rights
Where the GDPR applies, you have the right to obtain confirmation of and access to your data (Art. 15), to have it corrected (Art. 16) or erased (Art. 17), to have processing restricted (Art. 18), to receive it in a portable form (Art. 20), and to object to processing based on legitimate interests (Art. 21). Where we rely on consent, you may withdraw it at any time with effect for the future.
Write to the address above and we will respond within one month.
You may also complain to a data protection supervisory authority in the EU Member State where you live, work, or where you believe an infringement occurred. Exercising these rights costs you nothing and needs no particular form.
External links
Links to our demo projects and to our profiles on X (Twitter), Instagram, Facebook and LinkedIn leave this site. Once you follow one, the privacy practices of that destination apply, not ours. We have no influence over them.
Changes
We will update this page when the site changes. The date at the top always reflects the current version. We do not maintain an archive of superseded versions; if you need to know what it said on a particular date, ask us.