In short
- The website itself sets no cookies and stores nothing on your device that is not technically necessary. Details are under “Cookies and tracking”.
- The website has no analytics tools, no tracking and no advertising.
- Fonts, images and all other files come from this website itself. Nothing is loaded from other services.
- To deliver the pages and protect them against misuse, the hosting provider processes your IP address and other technical data of each request. The section “Hosting” says who that is and what the provider states about how long the data is kept.
- If you write me an email, I use it to answer you. My mailbox is hosted by Google.
- I do not sell personal data. Apart from the hosting provider and my email provider, both named below, I do not pass it on to anyone, unless the law requires me to.
This privacy policy explains which personal data is processed when you visit this website (https://coderoftime.dev) or write to me by email. The apps presented here have their own privacy policies, linked below.
Who is responsible
The controller under the EU General Data Protection Regulation (GDPR) is:
Benedikt Lesch
Merzig
Germany
Email: coderoftime@gmail.com
Further details are in the legal notice (Impressum).
Cookies and tracking
The website itself uses no cookies, local storage, tracking pixels, fingerprinting or similar techniques. There are no analytics tools, no advertising services and no social media plugins. The website does not embed content from other providers, such as videos, maps or externally hosted fonts.
Your browser keeps copies of pages and files in its cache, following the usual technical instructions that the server sends with them. You can clear the cache in your browser settings.
This storage is strictly necessary to provide the website you have requested. Under § 25(2) No. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG), it therefore needs no consent, and you will not see a cookie banner.
Hosting
When you open a page, your browser connects to the server that delivers it. The server receives or records the following technical data:
- your IP address,
- the date and time of the request,
- the address (URL) of the page or file requested,
- the referrer, that is, the page you came from, if your browser sends it,
- the user agent, that is, the type and version of your browser and operating system.
Of these, your IP address and the requested URL are needed to deliver the page; your browser usually sends the referrer and the user agent along with the request. The hosting provider processes this data to deliver the website to you and to protect it against attacks and misuse. The connection is encrypted (HTTPS). The legal basis is Art. 6(1)(f) GDPR. My legitimate interest is to make this website available reliably and securely. I do not use this data to identify visitors and do not combine it with other data.
Who hosts the website, what the provider says it records, and for how long:
GitLab Pages
The website is hosted on GitLab Pages, a service that runs on GitLab.com. GitLab’s privacy statement names GitLab B.V., Amsterdam, Netherlands, and GitLab Inc., San Francisco, USA, as the controllers of the personal data.
- What GitLab records: According to its privacy statement, GitLab collects server access logs for websites published with GitLab Pages. They contain visitors’ IP addresses, the time of access and the pages visited within the site. GitLab keeps these logs for 7 days and then deletes them on a rolling basis. GitLab gives the detection and prevention of fraud and abuse as the purpose of this data.
- Where: GitLab states that its services are hosted in the USA. Its list of sub-processors names Google LLC (USA) for cloud hosting.
- Role: I use GitLab Pages with a free account and have not concluded a data processing agreement (Art. 28 GDPR) with GitLab. GitLab describes these access logs in its own privacy statement. I have no access to them.
- Transfer to the USA: GitLab Inc. is certified under the EU-US Data Privacy Framework. Transfers to GitLab Inc. are therefore based on the European Commission’s adequacy decision for this framework (Art. 45 GDPR). Where the framework does not apply, GitLab states that it uses standard contractual clauses (Art. 46(2)(c) GDPR).
More information: GitLab Privacy Statement · GitLab sub-processors
Contact by email
This website has no contact form. If you write to me at coderoftime@gmail.com, I process your email address, your name if you give it, the content of your message and the technical information that comes with every email, such as the time it was sent. I use this data only to answer your message and deal with your request. The same applies if you reach me through another contact channel listed in the legal notice.
- Legal basis: Art. 6(1)(b) GDPR if your message concerns a contract with me or steps before entering into one. Otherwise Art. 6(1)(f) GDPR; my legitimate interest is to answer messages sent to me.
- Retention: I keep your message for as long as I need it to deal with your request, including any follow-up questions. After that I delete it, unless a statutory retention obligation requires me to keep it longer.
- Email provider: My mailbox is a Gmail account. Messages you send me are therefore stored and processed by Google as the provider of that account (for accounts in the European Economic Area: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Google processes them under its own privacy policy, which states, among other things, that Google analyses content to detect abuse such as spam and malware. Google may process data on servers outside the EU, including in the USA. Google LLC is certified under the EU-US Data Privacy Framework, so transfers to it are based on the European Commission’s adequacy decision for this framework (Art. 45 GDPR). Where required, Google states that it relies on standard contractual clauses (Art. 46(2)(c) GDPR).
- Security: Email is usually not end-to-end encrypted. Please do not send sensitive information such as passwords, PINs, TANs or bank details by email.
Links to other websites
This website links to other websites, for example to pub.dev and GitLab. These are ordinary links: nothing is loaded from those sites unless you click one. When you follow a link, your browser connects directly to the other website. That website then receives your IP address and, usually, the information that you came from this website. From then on, the other website’s privacy policy applies. I have no influence on what it processes.
App privacy policies
This privacy policy covers only the website. The apps presented here have their own privacy policies, which explain what each app does with your data:
Your rights
Under the GDPR you have the following rights regarding your personal data:
- access (Art. 15 GDPR),
- rectification (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- objection (Art. 21 GDPR, see below).
To exercise these rights, write to coderoftime@gmail.com. This is free of charge. I may first ask you to confirm your identity.
Data from a website visit is held mainly by the hosting provider (see “Hosting”), and I usually cannot link it to you. If your request concerns such data, I will help as far as I can. You can also contact the provider directly.
Right to object
If I process your data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object to this processing at any time, on grounds relating to your particular situation (Art. 21 GDPR). I will then no longer process the data, unless I can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
Please note that without your IP address and the requested URL, the website cannot be delivered to you.
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the EU member state where you live or work or where the alleged infringement took place. The authority responsible for me is the data protection authority of the German federal state in which I am based. A list of the German state authorities (in German) is available at bfdi.bund.de.
Providing data
You are not obliged to provide any personal data. Without your IP address and the requested URL, however, the website cannot be delivered to you. Whether you write to me is up to you.
No automated decisions
I do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
Changes
I update this privacy policy when the website, its hosting or the way I handle data changes. The current version is always available on this page. This version applies from 8 October 2026.