Privacy
Privacy
Last updated: July 12, 2026
Visitor Notes
If you leave a drawing on the visitors board, this site stores the drawing image, the display name, the optional message, note color, placement metadata, and the submission time. This data is used to show the note on the public visitors board and to let the site owner moderate submissions.
Visitor note images are stored in Cloudflare R2. Visitor note metadata is stored in Cloudflare D1. Public API responses do not expose private storage object keys.
Cloudflare Turnstile
Public visitor-note submissions are protected with Cloudflare Turnstile in invisible mode. Turnstile runs a browser challenge in the background and sends a token that this site verifies on the server before accepting a note.
Cloudflare describes the client-side signals it processes and how it uses them in the Cloudflare Turnstile Privacy Addendum.
Admin Security
Admin-only areas use Cloudflare Access, passkeys, sessions, rate limiting, and audit logging. The site converts client IP addresses into keyed identifiers that rotate monthly before storing session, audit, or rate-limit records. Audit records can also include credential identifiers, user agents, action names, target records, timestamps, and change details. D1 audit records are retained for 90 days and archived daily to R2. Expired sessions and stale rate-limit counters are removed by the same daily job.
Contact
For privacy or moderation requests about visitor notes, contact the site owner through the public links on the home page.