← back to the site

privacy policy.

last updated: September 9, 2026

This is susmic’s personal website. This page covers susmic.dev and its official onion mirror, including the terminal, blog, demo store, and browser verification.

what reaches the server

Opening a page sends the usual web request information: the requested address, browser headers, and connection information. On the clearnet, this can include your IP address. The visit counter keeps an IP-based last-visit timestamp to avoid counting repeated visits within six hours. Comment rate limiting also keeps a last-action timestamp. These records are stored on the site’s server; six hours is the counting interval, not an automatic deletion deadline.

The site’s own code does not include advertising trackers or session-replay recording. Server or network error logs may contain technical request information needed to keep the site running.

things you choose to submit

Posting a comment stores your chosen name, comment text, an identifier, and the time it was posted. Store entries store their submitted name, description, price, and other displayed details. These contributions are public.

The store checkout is a demo: it stores the chosen buyer name, cart items, total, order identifier, status, and timestamp. No payment processor is connected and the decorative card fields are not submitted. Demo order history is also accessible through the site’s API, so use a nickname and do not put private information in these fields.

If you email me, your email provider and mine process the message, address, and any information you include.

cookies and storage on your device

The verification cookies are HttpOnly. They are host-specific, so the clearnet and onion mirror do not share the same verification session. Your browser may also cache images, fonts, scripts, and other assets; the onion mirror uses longer caching to reduce repeat downloads.

CAPTCHA, proof of work, and security canaries

Verification sends the challenge token, your answer or drag position, and a proof computed by your browser. The CAPTCHA client also sends basic interaction counts and elapsed time; the server does not store a recording of your typing or pointer movements.

Challenge state is stored temporarily on the server. CAPTCHA challenges expire after three minutes and proof-of-work challenges after ten minutes. Expired records are removed during regular verification traffic. Rate-limit identifiers are keyed and kept temporarily in server memory.

Some verification responses contain decoy tokens or URLs to detect automated misuse. Submitting a decoy or visiting its recovery URL can record an event type, challenge identifier, and timestamp on this server. Canary records do not contain raw IP addresses. They are limited to the most recent 10,000 records and records older than seven days are removed during regular verification traffic. No external canary service receives these events. Normal challenge-image and answer.jpg requests are not recorded as canary hits.

the “pull it apart” playground

Dragging, throwing, collisions, and sound effects run in your browser. Playground pointer movements and sound are not uploaded or saved by the playground. Sound is synthesized locally after you open it; the feature does not request microphone access. Closing it restores the original page.

Cloudflare, Tor, and outside links

The clearnet site uses Cloudflare for delivery and security. Cloudflare can process network and HTTP request information and may use its own security technologies. Its handling of that information is described in Cloudflare’s privacy policy.

The official onion mirror is reached through Tor instead of the Cloudflare tunnel. The site normally sees the local onion-service connection rather than your public IP address. Tor does not make information you voluntarily post anonymous: comments, names, and other identifying content can still identify you.

Links to other sites, social sharing, and any externally hosted media have their own privacy practices. Following an outside link leaves this site; externally hosted media can contact its host when loaded.

how long things stay, and your choices

Published comments, store entries, demo orders, and visit-counter records currently remain until manually removed. Backups may retain older copies. The shorter verification and canary retention periods are described above.

You can clear cookies and site storage in your browser. That resets preferences and verification passes and may require another check. Blocking JavaScript prevents interactive features and browser verification from working; this policy remains readable without JavaScript or a verification challenge.

For privacy questions or a request to access, correct, or remove information you submitted, email susmic@susmic.dev with the relevant page or record. Please do not send passwords or identity documents. Public material may have been copied by visitors, search engines, or archives; removing it here does not automatically remove their copies.

If the site’s data practices change, this page and its “last updated” date will be updated.