Privacy

Short, because there is little to say.

This website

helmetduck.com is a static page. It sets no cookies, runs no scripts, loads nothing from third parties and has no analytics. The content delivery network keeps standard access logs, which record the address, the path, the time and the browser of each request; they stay in the owner's account, expire after 90 days, and are read only by a program that counts requests and looks for abuse, and by the owner. No address from them is ever published. An address that sends hundreds of requests within a few minutes is refused for an hour. Your browser's connection to the network is protected by TLS.

The Helmet Duck plugin

Everything the plugin records stays on your machine, under ~/.helmet-duck: the decisions its gates make, the read ledger for the current session, the dissent ledger and the mirror's sweep of your own transcripts. Nothing is transmitted anywhere. The plugin opens no network connection except one you start yourself: activating a licence key sends that key and a label for your machine to the licence vendor, once, so the key can be recorded as used.

Payments and sponsorship

Money never passes through this site. Sponsorships are handled by GitHub Sponsors, purchases by a merchant of record named at checkout, and invoices by Stripe. Each of them collects what a payment requires under its own privacy policy. The site's owner receives the name and email a buyer chooses to provide, uses them only to deliver what was bought and to answer questions, and does not share or sell them.

Mail

Mail sent to an address at helmetduck.com is received by Amazon SES in the United States, kept in the owner's account for 90 days, forwarded to the owner's mailbox, and answered from there. Messages that SES flags as spam or malware are not forwarded. Nothing about them is shared or sold.

Contact

Questions about this page: @garitac on GitHub.

Back to helmetduck.com