Privacy policy
Last updated:
One policy for every site under ehlers.tv: what each one records about you, why, who else handles it, how long it is kept, and what you can ask of me.
Who is responsible
I am Christian Ehlers, a private person in Eindhoven, the Netherlands. I run every site under ehlers.tv myself and decide what they record, so I am responsible for the personal data on this page (its controller, in the words of the GDPR).
Write to hostmaster@ehlers.tv about anything on this page. It arrives in my own Microsoft 365 mailbox, which nobody else uses, and I use what you write only to answer you.
This policy covers:
- www.ehlers.tv, my homepage, with this policy and the terms of service;
- md.ehlers.tv, my own copy of my markdown viewer, where I publish markdown pages from time to time, and markdown-amplified.ehlers.tv, the viewer's public demo;
- ai-valley.ehlers.tv, public, read-only views of archived AI Valley runs;
- forum.ehlers.tv, the forum for my own projects;
- stats.ehlers.tv, visitor statistics drawn from the server's access log, behind a sign-in only I use;
- a few administration addresses that answer only from my home network; a request to them from anywhere else leaves only the access-log line.
It replaces the policy of June 2026. None of these sites shows advertising.
On every site: Cloudflare and the server's log
Every request to these sites goes through Cloudflare first. Cloudflare runs the DNS for the names, ends the encrypted connection from your browser and passes the request on to my server (for markdown-amplified.ehlers.tv, to AWS Amplify instead; see the markdown demo), so it sees each request in full: your IP address, the address you asked for, your browser's headers and any cookies sent with it. On ordinary visits Cloudflare sets no cookies of its own. If it takes a request for an automated one and challenges it, it may set a short-lived cookie (cf_clearance or __cf_bm) to remember that you passed.
Cloudflare also asks your browser to report network errors on these sites to Cloudflare for seven days after a visit (Network Error Logging). Only failed requests are reported, and only browsers that support it send reports, such as Chrome, Edge and others built on Chromium. A report holds the address, the referring page, the server's IP address and the kind of error.
My server is a virtual machine at Amazon Web Services in Stockholm, Sweden. In front of the sites it runs one proxy, which writes one access log for all of them. Each line holds the site's name, your full IP address, the time, the address you asked for (including anything after a ?), the response code and size, the referring page and your browser's user-agent string. The log is rotated daily and kept for about 30 days. The proxy's error log, which can also hold your IP address, is kept the same way.
From that log, stats.ehlers.tv builds visitor statistics with GoAccess: visitors per day, the pages visited (without the part after a ?), referring sites, browsers and operating systems, and a list of IP addresses, each with the country, city and network it belongs to. The location is looked up on my server in a copy of MaxMind's GeoLite2 databases; nothing is sent to MaxMind. Today the statistics have no end date and go back to 23 September 2026.
Each program on the server also keeps its own short log, at most 30 MB per program, deleted whenever the program is replaced, as at every update. What a site's own log holds is said under that site.
Why: to deliver the pages, to keep the sites safe from attacks and abuse, and to see how much they are used. That is my legitimate interest in running them, and you can object to it (see Your rights).
www.ehlers.tv
The pages on www.ehlers.tv, this one included, set no cookies and load nothing from anyone else's site. The homepage asks ai-valley.ehlers.tv, also mine and on the same server, how many runs its archive holds; that request carries no cookie and is logged like any other. If you pause the homepage picture, your browser remembers that in its local storage (see Cookies and browser storage). Otherwise a visit leaves only the access-log line and the statistics described above.
On the homepage, Cloudflare rewrites the email addresses to hide them from harvesters, and adds a small script, served from www.ehlers.tv itself, that turns them back into links. The script sets no cookie and stores nothing.
Before 5 October 2026 the markdown demo set its cookies for the whole ehlers.tv domain, so if you used it before then, your browser may still send those cookies to www.ehlers.tv and the other sites here until they expire (see the markdown demo). The homepage does not read them, and the access log does not record cookies.
The markdown viewer: md.ehlers.tv and markdown-amplified.ehlers.tv
md.ehlers.tv is my own copy of my markdown viewer, Markdown Amplified, where I publish markdown pages from time to time. Google Analytics is switched off there: it shows no cookie banner and loads nothing from Google. markdown-amplified.ehlers.tv runs the viewer's public demo, with Google Analytics on to show the feature.
Google Analytics
On markdown-amplified.ehlers.tv nothing is loaded from Google until you accept analytics in the cookie banner: before that, and if you reject, your browser makes no request to Google at all. If you accept, your browser loads Google's tag (gtag.js, for the Google Analytics 4 property G-N3QQ0T8RE9), which sets its cookies for markdown-amplified.ehlers.tv only and records the pages you view, where you came from, your browser and operating system, and your approximate location. Advertising consent is always refused, and Google signals and ad personalisation are switched off. Google says that Google Analytics 4 does not store IP addresses and uses them only to estimate location; see how Google uses information from sites that use its services.
Until 5 October 2026 www.ehlers.tv and md.ehlers.tv ran this same viewer with the same property, so the property also holds visits to them from before that date.
All of Google Analytics' data-sharing settings are off, and Google handles the data as my processor under its data processing terms.
Why: the cookies, and what Google Analytics records once you accept, rest on your consent.
Your choice is kept in your browser's local storage. To change it, use the Cookie settings
button in the corner of every page; turning analytics off deletes the Google Analytics cookies and reloads the page without Google's tag.
The request log
On md.ehlers.tv the viewer's server writes every page request to its own log: your full IP address, the address you asked for (including anything after a ?), the referring page and your browser's user-agent string. This is the program log of at most 30 MB described above, kept for the same reasons as the access log.
Password-protected pages
A page can be locked with a password. If you unlock one, your browser keeps the password itself in a cookie (ma-unlock-…) for 90 days, so the page stays open. If you sign in to the read-only admin of the demo on markdown-amplified.ehlers.tv, a cookie (ma-admin) keeps the sign-in token the server gives you, also for 90 days. Both cookies are for the site's own address only; before 5 October 2026 they were set for the whole ehlers.tv domain, and those older cookies expire within 90 days. Neither is set unless you use these features.
Your theme choice and the viewer's back and home navigation are kept in your browser only.
The second copy
markdown-amplified.ehlers.tv runs on AWS Amplify in Stockholm, delivered through Amazon CloudFront rather than through my server. Amplify keeps the app's log in Amazon CloudWatch for 30 days. Like md's request log, it holds each page request with your full IP address, the referring page and your browser's user-agent string.
markdown-amplified.ehlers.tv has its own privacy page, linked from its banner. Where the two differ, this page applies.
ai-valley.ehlers.tv
Public, read-only views of archived AI Valley runs. The villagers in them are simulated characters, each played by a language model, not real people.
The site has no accounts, sets no cookies and loads nothing from other sites. Its server records nothing about visitors: no IP address and no browser details. It logs only the address of a page that failed with a server error. A visit leaves only the access-log line and the statistics described above.
Your view settings (tabs, filters, toggles, where you were on the start page) are kept in your browser's local and session storage and never sent to the server.
forum.ehlers.tv
The forum for my own projects runs on NodeBB, with its database on my server in Stockholm. Anyone can read it; to write, you need an account, and you must be at least 13 years old to have one.
Reading needs nothing from you beyond what every visit leaves: the session cookie and your IP address, both described below. To write you need an account, and for that the forum needs your GitHub or Google id, name and email address; without them it cannot create one. Everything you add beyond that is up to you.
Signing up
You sign up and sign in with your GitHub or Google account. Members have no forum password.
- GitHub: the forum asks GitHub for your email addresses (scope
user:email) and keeps your GitHub user id; your GitHub username, which becomes your forum username; your display name, kept as your full name and hidden from other members; your primary email address; and the web address of your GitHub profile picture. - Google: the forum asks Google for your basic profile and email address and keeps your Google account id; your Google name, which becomes your forum username, so it is usually your real name; your email address; and the web address of your Google profile picture.
The forum does not store the sign-in token. If a forum account with the same email address already exists, the sign-in is linked to it. A Google sign-up gets a mail asking you to confirm your address; a GitHub address is taken as confirmed.
GitHub and Google see that you signed in to the forum and keep a record that you allowed it; that part is theirs, under their own privacy policies. You can remove the forum's access in your GitHub or Google account at any time; your forum account stays until you delete it.
Your account is created as soon as you sign in for the first time.
On your first sign-in the forum shows its rules and asks you to accept them, and asks you to confirm that you have read this policy, that you are at least 13, and that it will send you account emails. It records that you did. These are confirmations, not consent to the processing: your account rests on the service you sign up for (see Why below), and notification and digest emails stay off unless you turn them on.
What your account holds
- Your username and the ones you had before, your email address and the ones you had before, your full name, your picture, and what you add to your profile, such as an about-me text, a signature or a birthday.
- When you joined and were last online, how many posts and topics you have written, your settings, the topics you watch, the members you follow, your votes and your bookmarks.
- Your notifications, for 30 days.
- Your sign-ins: at most ten open sessions, each with the IP address, browser and time it began, ending after 14 days or when you sign out. Your account's Sessions page shows them and lets you end any of them.
- Every IP address you have signed in from, with when it was last used, for as long as the account exists.
- If you turn on two-factor sign-in: its secret, your backup codes and the names of your security keys.
- If you turn on push notifications for a device: the address of that browser's push service, its keys, and the browser and operating system.
What is public
- Topics and posts can be read by anyone, without an account, by search engines and through the forum's RSS feeds.
- Your profile page is public too: your username, your picture, what you write in it, when you joined and were last online, and your post count, reputation and followers. Your full name is hidden from other members, and so is your email address unless you choose to show it.
- Anyone can see who upvoted a post. Who downvoted it is visible only to moderators and administrators.
- When a post is edited, its earlier versions are kept, and signed-in members can see them.
- Images you upload to a post can be opened by anyone who has their address, and they stay on the server after the post is gone unless I delete them. Location and camera details (EXIF) are removed from them first.
- Pictures from GitHub and Google accounts are shown straight from GitHub's and Google's servers, so every reader's browser fetches them from there.
- Chats are visible only to the people in them. They are stored unencrypted, with the sender's IP address, and as administrator I can read them in the database.
Moderation
Posts by new members wait for approval before they appear (today, until another member has upvoted one of their posts). A waiting post is stored with its text and your IP address, and leaves the queue when it is approved or rejected.
IP addresses
Every page view on the forum, by guests too, puts the visitor's IP address in a list used to count unique visitors; entries leave it after 48 hours. Besides the addresses you sign in from, IP addresses are stored with chat messages, with waiting posts and in the forum's administration log.
The administration log
The forum's event log records administrative actions with the administrator's IP address, and some account events with the member's email address: a confirmation mail sent, a change of address, and the deletion of an account, with the username, email address and IP address. Nothing removes these entries automatically today.
Forum mail comes from no-reply@ehlers.tv and is sent through Mailgun's EU region. The forum sends a mail to confirm the address of a Google sign-up, and a mail if your account is banned. Notification mails come only for the kinds you switch to email in your settings, and digests only if you choose one: daily, weekly, every two weeks or monthly. Mailgun receives each mail's recipient and content. Open and click tracking is off, and Mailgun keeps its delivery logs for one day.
Push notifications
You can turn them on for each device in your settings. Each notification, with its title and a short excerpt such as the start of a reply, travels through your browser maker's push service: Google for Chrome, Mozilla for Firefox, Apple for Safari, Microsoft for Edge. It is encrypted end to end, so the service sees only where it goes, when, and how large it is.
Export and delete
Export. Your account's Your Rights & Consent
page (/user/<your name>/consent) lets you download your profile (a JSON file with your account record without the password, your settings, your last ten IP addresses, your sessions, your username and email history, your own chat messages, bookmarks, watched topics, votes and follows), your posts (CSV) and your uploads (ZIP). The files stay on the server until your next export replaces them, also after you delete your account.
Delete. The Delete Account button on your profile's Edit page removes your account record, sessions, IP addresses, username and email history, votes, follows, notifications, uploaded profile picture and the link to your GitHub or Google account. Your posts and topics stay, shown as written by a former member. These stay too, today: your chat messages (with your IP address), images you attached to posts, reports (flags) you filed, your two-factor data, your push subscriptions, your export files, and the administration-log entries that name you (confirmation mails, changes of address and the deletion itself, with your email address). Write to me to have your posts or any of the rest removed.
Why
- Your account, your posts and showing them: that is the service you sign up for.
- IP addresses, the post queue and the administration log: my legitimate interest in keeping the forum free of spam and abuse, and in counting its visitors.
- Notification mails, digests and push notifications: your choice in your settings, which you can undo there at any time.
Backups
No scheduled backups of the forum exist yet. Before a change to the server I may copy the forum's database, to restore it if the change goes wrong. Such a copy is kept on the server and on my own computer at home until I delete it, and an account deleted after the copy was made stays in it until then.
What the forum does with Google and GitHub data
When you sign in with Google, Google gives the forum your basic profile and email address, and the forum keeps four things from it: your Google account id, your name, your email address and the address of your profile picture. It uses them only to create your forum account, sign you in, send you the forum's mail, and show your name and picture publicly on the forum. It does not use them for advertising, does not sell them, does not use them to train AI models, and shares them with no one except the services that run the forum, named below. The same holds for what GitHub gives the forum.
They stay as long as your forum account does. Deleting the account removes them, apart from the leftovers listed under Export and delete (your export files and the administration-log entries that name you). How the data is protected says how they are kept safe.
Cookies and browser storage
Everything a site keeps in your browser, site by site. The cookies a feature needs to work (the forum's session, the demo's unlock and admin cookies, my statistics sign-in) need no consent; Google Analytics' cookies do. Local storage stays until you clear it; session storage ends when you close the tab. Neither is sent to the server by itself.
| Name | What it is for | How long | Set when |
|---|---|---|---|
| www.ehlers.tv | |||
ehlers.tv.hero.pausedlocal storage | That you paused the homepage picture | Until you press Play or clear it | When you press Pause |
| md.ehlers.tv and markdown-amplified.ehlers.tv | |||
_ga, _ga_N3QQ0T8RE9cookies for markdown-amplified.ehlers.tv only | Google Analytics: tells visitors and visits apart | 2 years | Only after you accept analytics |
ma_cookie_consent, ma_cookie_consent_datalocal storage, markdown-amplified.ehlers.tv | Your answer to the cookie banner | Until you clear it | When you accept, decline or save |
themelocal storage | Light or dark | Until you clear it | When you use the theme switch |
md-nav-stack, md-nav-home, md-nav-backsession storage | The demo's back and home navigation | The tab | While you browse |
ma-unlock-…a cookie for the site's own address, and session storage | The password of a demo page you unlocked | 90 days; session storage: the tab | When you enter a page password |
ma-admina cookie for the site's own addressadmin-token, admin-readonlysession storage | Your sign-in to the demo's read-only admin | 90 days; session storage: the tab | When you sign in to the admin |
| ai-valley.ehlers.tv | |||
analytics.*, aivalley.start.pausedlocal storage | Your view settings: tabs, filters, toggles, sort order, whether the start page's tour is paused | Until you clear it | When you change a setting |
aivalley.start.v1session storage | Where you were on the start page | The tab | While you use the start page |
| forum.ehlers.tv | |||
express.sidcookie | Your session: whether you are signed in, and the token that protects forms from forgery | 14 days | On your first visit, guests included |
| Drafts, reading position, the editor's size and preview, search preferences, a dismissed bannerlocal storage | Convenience: an unsent post, where you stopped reading | Until you clear it | While you write, read or search |
Service worker/service-worker.js | Lets the forum work as an app and receive push notifications; keeps no data itself | Until you clear the site's data | On your first visit, guests included |
| Push subscription | Push notifications to that device | Until you turn push off on that device | When you turn push on |
| stats.ehlers.tv | |||
stats_sessioncookie | My sign-in to the statistics | 30 days | Only when I sign in |
| Every site, set by Cloudflare | |||
| Network Error Logging policykept by the browser, not a cookie | Reports of failed requests to Cloudflare | 7 days, renewed on each visit | On every response |
| github.com and accounts.google.com | |||
| Their own cookies | Your sign-in with GitHub or Google, on their own sites | Their choice | Only when you sign in to the forum with them |
Who else handles data
These services handle personal data for the sites. A linked name goes to the provider's own privacy policy.
| Service | What for | Where |
|---|---|---|
| Amazon Web Services | My server and its disks; for markdown-amplified.ehlers.tv also AWS Amplify, Amazon CloudFront and Amazon CloudWatch | Stockholm, Sweden; CloudFront from its own edge servers |
| Cloudflare | DNS for the names, the encrypted connection, the proxy in front of every site, caching of the homepage's files, the email-link script, error reports | Cloudflare's worldwide network; a US company |
| Mailgun | The forum's mail | Mailgun's EU region; a US company owned by Sinch of Sweden |
| Microsoft 365 | My mailbox, and a shared mailbox where mail to webmaster@, hostmaster@ and abuse@ehlers.tv and replies to no-reply@ehlers.tv arrive | The account's directory is in Microsoft's EU region |
| Anthropic | The AI assistant Claude, which helps me build and run the sites; what it reads while it works passes through Anthropic's service | A US company |
| Google Analytics on markdown-amplified.ehlers.tv, and on www.ehlers.tv and md.ehlers.tv until 5 October 2026, as my processor | A US company; Google Ireland for the EEA | |
| Google and GitHub | Sign-in to the forum, and the profile pictures shown from their servers. Here they act for themselves, not for me: your account with them is theirs. | US companies |
| Push services | Push notifications from the forum, if you turn them on | Google, Mozilla, Apple or Microsoft, by browser |
Outside the European Union
The server, the forum's database and the forum's mail service are in the EU: in Sweden, and in Mailgun's EU region. But Cloudflare, Google, GitHub, Microsoft, Amazon and Mailgun are US companies or part of US groups, and Cloudflare handles every request on its worldwide network, so data can reach the United States and other countries. These providers rely on the EU–US Data Privacy Framework or on the EU's standard contractual clauses in their data processing terms. The framework's list is public at dataprivacyframework.gov; the clauses are part of each provider's published data processing terms. Anthropic, which provides the AI assistant, is a US company too; what the assistant reads while it works is processed there under Anthropic's terms.
How long things are kept
| What | How long |
|---|---|
| The proxy's access and error logs, for every site on my server | About 30 days |
| Visitor statistics on stats.ehlers.tv | No end date today; they go back to 23 September 2026 |
| Each program's own log on the server, the demo's request log included | At most 30 MB per program; deleted when the program is replaced |
| Server disk snapshots, kept to restore the server, which also hold the access log and the statistics | Until I delete them; no end date is set |
| Google Analytics data | Event data 2 months; user data 14 months, counted from your last visit |
| The second demo's log in Amazon CloudWatch | 30 days (see the markdown demo) |
| Logs of retired AWS Amplify apps in Amazon CloudWatch, May to September 2026 | Deleted from AWS on 5 October 2026; no copy is kept. |
| The demo's unlock and admin cookies | 90 days |
| Forum account, profile, username and email history, sign-in IP addresses | As long as the account exists |
| Forum sessions and their cookie | 14 days |
| The forum's visitor-count list of IP addresses | 48 hours |
| Forum notifications | 30 days |
| Waiting posts | Until approved or rejected |
| Posts, topics, their edit history and uploads | Until deleted; they stay after you delete your account unless you ask me to remove them |
| Chat messages | Until deleted; not removed with your account |
| Two-factor data and push subscriptions | Until you turn them off; not removed with your account |
| Forum export files | Until your next export replaces them |
| Email confirmation codes | Usable for 24 hours; the record goes when you confirm, when a new code is sent, or with your account |
| The forum's administration log | No end date today (see The administration log) |
| Copies of the forum's database | None scheduled; a copy taken before a change stays until I delete it (see Backups) |
| Mailgun's delivery logs | One day (see Mail) |
| Mail you send to webmaster@, hostmaster@ or abuse@ehlers.tv, or in reply to no-reply@ehlers.tv | Kept in one shared mailbox and deleted at the latest one year after it arrives |
| Cloudflare's request data and error reports | Set by Cloudflare's own policies |
| Your browser's local storage and session storage | Until you clear it; session storage until you close the tab |
How the data is protected
- Every site answers only over an encrypted connection (HTTPS); a plain request is redirected to it.
- I administer the server and the forum myself. The server accepts SSH sign-ins only with a key, never with a password, and my forum administrator account uses two-factor sign-in.
- The forum's database cannot be reached from the internet, and the forum itself only through the proxy. Copies of the database are readable only by my own user account.
- Members have no forum password: they sign in through GitHub or Google, and the forum does not keep the sign-in token.
I use an AI assistant, Anthropic's Claude, to help build and run these sites. It can reach the servers and the forum's administration, and handles personal data only as part of that work, on my instructions. On the forum it has its own account, claude, with which it reads and writes posts; what it writes there is machine-generated.
Your rights
Under data protection law (the GDPR) you can ask me:
- for a copy of the personal data I hold about you;
- to correct it;
- to delete it;
- to limit what I do with it while a question about it is open;
- for the data you gave the forum in a form you can take elsewhere; the forum's own export does this (see Export and delete);
- to stop using it where I rely on my legitimate interest, unless I have compelling reasons to go on.
No decision about you is made by automated means alone: I approve waiting posts on the forum by hand.
Where something rests on your consent, you can withdraw it at any time, which does not undo what happened before: on the markdown demo with its Cookie settings
button, on the forum in your settings.
Write to hostmaster@ehlers.tv. For a forum account, write from the address on the account or tell me the username, so I know the request is yours. I answer within one month.
You can also complain to a data protection authority: in the Netherlands, where I live, the Autoriteit Persoonsgegevens, or the authority of the country where you live or work.
Changes
When I change this policy, I change the date at the top.