Unlabelled

Privacy Policy

Effective: August 2, 2026

Who we are

Unlabelled SL (NIF ESB65395956), registered at Font de Cabrera 17, 08348 Cabrils, Spain, operates unlabelled.cc and the Unlabelled content management service (together, the “Service”). We are the data controller for the personal data described below.

Contact: privacy@unlabelled.cc

The short version

If you’re just reading unlabelled.cc — the blog, this page, the homepage — we don’t collect anything about you. No analytics, no advertising trackers, no cookies beyond a single non-tracking preference stored in your own browser.

If you have an Unlabelled account to edit a website, we hold your name, email and username to run that account, and — because of how the Service works — your name and email become part of the public commit history of the website you edit.

The rest of this page explains both of those in detail.

Visitors to unlabelled.cc

We don’t use cookies for analytics or advertising, and no analytics service is currently active on this site. The only thing stored in your browser is a light/dark theme preference, kept in localStorage — it never leaves your device and isn’t a cookie in the legal sense.

If you fill in no forms and create no account, we process no personal data about you at all.

Editor accounts

To write or edit content, you need an account, authenticated through our identity provider (Keycloak, which we operate ourselves, on infrastructure located in the EU). Creating an account means we hold:

  • Your name, email address and username
  • A record of the role(s) you’ve been granted (which pages or sites you may edit)
  • Session information needed to keep you signed in

Legal basis: performance of the contract between you and us — we can’t provide an editing account without this information.

A newly registered account has no access until it’s manually approved. Registering doesn’t grant any permission by itself.

Publishing writes your name into git history

This is the part most services like this don’t have, and we’d rather be upfront about it than bury it: when you publish or edit a post or page, the change is committed to the website’s source code repository (hosted on GitHub), and the commit is attributed to your name and the email address on your account. If that repository is public, your name and email on that commit are publicly visible — the same way any public GitHub commit is.

This is fundamental to how the Service works (every change is a version-controlled commit, which is also why nothing is ever silently lost), so we can’t offer editing without it. If this is a concern, use an email address you’re comfortable being attached to public commits, or ask us about a display name that isn’t your legal name at privacy@unlabelled.cc.

Who else sees this data

  • Google Cloud (European Union, europe-west1) hosts our identity provider and the editing application itself.
  • GitHub, operated by Microsoft and based in the United States, stores website content and, as above, commit authorship. Transfers to GitHub rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses.
  • Cloudflare sits in front of our sites as a content delivery network and reverse proxy.

We don’t sell personal data, and we don’t share it with anyone for advertising purposes.

How long we keep it

  • Editor account data is kept for as long as the account is active, plus a reasonable period afterward in case you return.
  • Git commit history is, by design, permanent and version-controlled — this is a genuine limit on our ability to fully erase past commit metadata without corrupting a shared repository’s history for everyone else using it. We’ll always remove what we can (your account, your access, future data) even where individual past commits can’t be surgically rewritten.

Your rights

Under the GDPR, you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate data
  • Erase your data (subject to the git-history limitation above)
  • Restrict or object to processing
  • Port your data to another provider
  • Complain to a supervisory authority — in Spain, the Agencia Española de Protección de Datos

To exercise any of these, email privacy@unlabelled.cc.

Data Protection Officer

Given the scale of our processing, we’re not required to appoint a Data Protection Officer under Article 37 GDPR. Direct any data protection questions to privacy@unlabelled.cc.

Children

This service isn’t directed at children, and we don’t knowingly collect data from anyone under 16.

Changes to this policy

If this policy changes materially, we’ll update the effective date above and, where we reasonably can, tell existing account holders directly.