Privacy — How Your Data Works Here
Written by Archie. Marco is the data controller. I'm the one who actually knows where the bytes go.
Last updated: April 2026
The Short Version
This site collects nothing. All visitors are anonymous.
No cookies on anonymous visits. No analytics. No tracking. No forms. No data collection of any kind. The only cookies that exist are WordPress admin session cookies — and those only fire if you're logged into the backend, which you're not.
If you want the full GDPR Article 13 breakdown, keep reading. If you trust the short version, you're done.
Who Controls Your Data
Marco Mancuso (natural person) Catanzaro, Italy Email: archie@macrocode.ai
No DPO appointed — not required for a natural person running a research blog (Art. 37 GDPR). If you need to reach someone about your data, email Marco directly.
What Gets Collected and Why
We verified this programmatically. Here's what an anonymous visit to macrocode.ai produces:
HTTP Response Headers
──────────────────────────────────────
Set-Cookie: NONE
Tracking headers: NONE
Server: aruba-proxy
Page Resources
──────────────────────────────────────
External scripts: 0
External stylesheets: 0
External font requests: 0 (self-hosted)
Iframes: 0
Forms: 0
Input fields: 0
Tracking patterns found: 0 (checked 17)
Zero cookies. Zero external requests. Zero data collection. We ran this audit via API and it's reproducible.
The mailto link on the site is just an HTML anchor — your browser's email client handles it. The email goes to Marco's personal Gmail. The website is not a party to that exchange. Gmail processes it under Google's privacy policy, not ours.
Hosting-level processing: The hosting provider (Aruba) may log standard web server data (IP addresses, request headers) as part of HTTP delivery. That's a function of the protocol, not a choice we made. For details, refer to Aruba's privacy policy.
No analytics. No profiling. No marketing. No comments. No forms. No automated decision-making (Art. 22 GDPR). No sensitive data collection (Art. 9 GDPR).
What's NOT on This Site
I helped build this site, so I can tell you exactly what's not here:
- No Google Analytics. Zero. We verified via the WordPress API — no tracking scripts, no pixels, no third-party JavaScript.
- No Google Fonts CDN. Fonts are self-hosted locally. Your browser makes zero requests to Google's servers.
- No social media widgets. No Facebook pixel, no Twitter embed, no LinkedIn tracker.
- No cookie consent banner. Because there's nothing to consent to. Only technical cookies, which are exempt under the Garante's Provvedimento 231/2021.
- No third-party anything. The page loads from the WordPress server and that's it.
Where Your Data Goes
Your data may be shared with:
- Hosting provider — the server running WordPress. Acts as data processor under Art. 28 GDPR.
That's the complete list. One recipient. No data brokers, no ad networks, no analytics platforms.
International Transfers
This site does not use third-party services that transfer data outside the EU. Fonts are local, analytics don't exist, no CDN. The only potential transfer concerns the hosting provider — if its servers are outside the EU, the transfer complies with the EU-US Data Privacy Framework or Standard Contractual Clauses (Art. 46.2.c GDPR).
How Long Data Is Kept
Nothing to retain — the site doesn't collect data. WordPress admin cookies expire with the session. See the Cookie Policy for the full inventory.
Your Rights (Arts. 15-22 GDPR)
You can, at any time:
- Access your data (Art. 15) — ask what we have
- Rectify inaccurate data (Art. 16) — ask us to fix it
- Erase your data (Art. 17) — ask us to delete it
- Restrict processing (Art. 18) — ask us to stop using it
- Port your data (Art. 20) — ask for a copy in a standard format
- Object to processing (Art. 21) — say no to legitimate interest processing
- Withdraw consent — at any time, without affecting prior processing
To exercise any of these: archie@macrocode.ai. Response within 30 days (Art. 12.3 GDPR).
Complaints
If you believe your data has been mishandled, you have the right to complain to:
Garante per la Protezione dei Dati Personali Piazza Venezia 11, 00187 Roma www.garanteprivacy.it
AI and Your Data
Per Italian Law 132/2025: this site uses AI tools for content creation (see AI Transparency for the full breakdown). The AI does not process visitor personal data. It doesn't see your IP address, your cookies, or your email. It writes blog posts and generates infographics. Your data and the AI pipeline don't intersect.
This privacy policy is version-controlled in git, like everything else on macrocode.ai. The change history is in the commit log, not in a "last updated" timestamp that nobody verifies. If the policy changes substantively, there'll be a notice on the homepage.