Originaly effective:

ririum (https://riri.my/) is a personal website and personal project. It is not operated as a commercial service, online store, or customer platform. Nothing on this website should be understood as creating a business relationship, customer account, advice, or ongoing service obligation between me and visitors. This website is provided on an as-is and as-available basis to the extent permitted by applicable law.
My maximum liability shall not exceed one Serbian dinar (1,00 RSD).

I care about privacy and keep data collection to a minimum. This Privacy Policy explains what information may be processed when you use this website.

When you visit

The website may create a temporary PHP session, identified by a PHPSESSID session cookie. The same session mechanism is used to distinguish active visits for the concurrent-user counter and, when captcha verification fails, to preserve submitted comment text for another attempt. The session is not used for advertising, profiling, or cross-site tracking and expires when the browser session ends.

What I collect

I do not use analytics services, advertising trackers, profiling tools, or third-party tracking cookies on this website.

When you visit the website, the server may automatically create access logs. These logs may include technical data such as your IP address, date and time of access, requested URL, referrer, browser or user-agent information, response status, and similar server-level metadata.

If you submit a comment or guestbook message, I may process the name you enter and the content of your submission so it can be reviewed, displayed, moderated, administered, and deleted where applicable.

For comments submitted on or after July 31, 2026, the website creates a unique comment management credential associated with the submission. A corresponding self-service comment management link is displayed immediately after successful submission. The comment management credential is used only to authorize deletion of the associated comment and is not used for analytics, advertising, profiling, or visitor tracking.

If captcha verification fails during comment submission, I may use a temporary PHP session token, stored as a session cookie, so your comment text can be preserved and you do not have to retype it. This session is used only for that functional purpose and not for analytics, advertising, or profiling.

If you choose to contact me by sending an email directly to the address published on this website, I will receive whatever information you include in that email and any associated email metadata needed to receive and respond to it.

What I do not use

  • Analytics cookies.
  • Advertising cookies.
  • Third-party tracking cookies.
  • Behavioral profiling tools.
  • Newsletter signup forms.

Live visitor statistics

While there aren't any individual behavioural analytics, there is a a first-party aggregate counter. Acessible over at: https://ccu.riri.my. To calculate the number of visitors currently online, the site uses a first-party session cookie to distinguish active visits and temporarily stores a session identifier and the time that session was last active. Without this cookie, repeated requests from the same open browser could be counted as separate visitors. Aggregate counts and timestamps are stored for the public statistics history. I do not use this information for advertising, profiling, or tracking visitors across other websites. The session cookie expires when the browser session ends.

Why I process data

I process limited data only where necessary to operate the website and its basic features. This includes:

  • Serving pages and media.
  • Maintaining security and stability.
  • Detecting abuse, spam, and malicious activity.
  • Troubleshooting technical issues.
  • Displaying, moderating, managing, and enabling the deletion of comments and guestbook messages.
  • Generating and validating comment management credentials for comments submitted on or after July 31, 2026.
  • Preserving comment text temporarily if captcha verification fails.
  • Displaying and maintaining a publicly accessible concurrent-users counter.
  • Reading and replying to emails sent directly to me.

Grounds for processing

Privacy laws differ between jurisdictions. Where applicable law requires a grounds for processing for processing personal data, the applicable basis may include:

  • Your voluntary submission of a comment or guestbook message for review and public display.
  • Your voluntary decision to contact me and the need to receive and respond to that correspondence.
  • My legitimate interests in operating, securing, maintaining, moderating, and protecting the basic functionality of this personal website.

Submitting a comment, guestbook message, or email is optional.

Cookies and session data

This website does not use analytics cookies, advertising cookies, or third-party tracking cookies. A temporary essential session token may be used during comment submission to support captcha retry and comment recovery. This session mechanism is functional and short-lived, not a tracking system. This very same session mechanism is used to count you as an online user, on this website's concurrent-users counter .

Retention

By default, access logs are kept for up to 5 (five) days and are then automatically deleted. Logs may be purged manually earlier at my discretion.

PLEASE BE AWARE: While access logs on my server instances are short-lived, Oracle Cloud and your internet service provider may independently process technical connection data under their own policies and legal obligations. I do not control their independent logging or retention practices.

A log entry looks something like this on my end:

87.xxx.xxx.xxx - - - [1778014230.477 (05/May/2026:22:50:30 +0200)] 
"GET / HTTP/3.0" 200 3934 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)
AppleWebKit/537.36 (KHTML, like Gecko)
Chrome/147.0.0.0 Safari/537.36 Edg/147.0.0.0" host="-" sni="riri.my"
scheme=https request_time=0.000 cache=- ssl=TLSv1.3upstream_time=-
upstream_addr=- upstream_status=- bytes_in=463 pipe=.conn=5 conn_requests=1

Temporary session data used during visit, as well as comment submission. It is kept only for as long as necessary for that purpose. It may consist of a short-lived session cookie stored in your browser together with corresponding server-side session data.

Comment form data is retained only as necessary to process the current submission or captcha retry. The associated session expires automatically or is deleted after successful submission.

If a submission is successful, the comment is stored for moderation and, once approved, displayed publicly on the relevant page. For comments submitted on or after July 31, 2026, the associated comment management credential remains valid for as long as the comment remains available and is permanently invalidated when the comment is deleted.

Comments may remain stored and publicly visible for as long as the relevant post, guestbook, or website remains available. They may be removed earlier by a person holding a valid comment management link or by me for moderation, privacy, legal, security, technical, or administrative reasons.

When deletion is confirmed through a valid comment management link, the comment is removed from the live website and active comment database. A residual copy may remain temporarily in an existing backup until that backup is replaced or deleted.

If you email me directly, I may retain the email for as long as reasonably necessary to handle the correspondence, keep records of the exchange, or protect against abuse.

Comments

When posting, users are solely responsible for ensuring compliance with all applicable local, national, and international laws. Do not post anything that could incriminate you, your family and friends, or anyone else for that matter.

In this policy, “comments” include both comments submitted underneath individual blog posts, referred to on this website as “diary” posts, and messages submitted through the guestbook page.

The comment system does not require an account or email address. The active comment database does not store an IP address, email address, user account, or another persistent identity marker alongside a comment. Server access logs are stored separately, are short-lived, and are maintained for technical and security purposes rather than to identify commenters or establish ownership of comments.

For comments submitted on or after July 31, 2026, a unique self-service comment management link is displayed immediately after successful submission. The link is displayed only once, and the website does not provide a way to display or recover it later.

Opening a valid comment management link displays the associated comment and asks for confirmation before deletion. Possession of the link is treated as sufficient authorization to delete the corresponding comment, and no additional identity verification is required.

Anyone who obtains a valid comment management link may be able to delete the associated comment. This same link serves two other purposes, and not the deletion functionality alone. You may use the comment management link to modify your comment, or download your copy. You should therefore keep the link private and store it securely if you may wish to delete the comment later. After deletion is confirmed, the comment is removed and the link is permanently invalidated.

Comments submitted before July 31, 2026, do not have comment management links. If your request concerns an older comment, or if you have lost a comment management link, you may contact me using the address below.

I will review the request and may ask for information reasonably necessary to identify the relevant comment and assess whether the request is genuine. Because comments are not connected to accounts, email addresses, or persistent identity markers, I may be unable to fulfill a request where the relevant comment or authorship cannot reasonably be identified or verified.

I do not collect or retain additional identifiers solely to make future verification of comment ownership possible.

Data storage

Website content, submitted comments, comment management credentials, temporary comment-session data, and server access logs are hosted on servers in Italy using Oracle Cloud, a United States-based hosting and infrastructure provider.

Comment data, such as your chosen name and comment content, are stored in plaintext. Your raw comment management token is not stored. Instead, an Argon2 hash of the token is stored and used to verify deletion requests.

Oracle Cloud may process limited technical and hosting data as necessary to provide infrastructure, storage, networking, security, and related services.

To operate, moderate, maintain, and back up the website, limited website data may also be accessed or temporarily stored on my local devices outside Italy and, depending on my location, in a country different from the country in which you are located.

Because this website may be accessed internationally, data may be processed in a country different from the country in which you are located. I use reasonable technical and organizational measures to protect the limited data involved.

If the website’s primary hosting location changes, this policy will be updated accordingly.

Sharing and service providers

I do not sell personal data or use it for advertising, behavioral profiling, or third-party marketing.

I use Oracle Cloud as the website’s hosting and infrastructure provider. Oracle Cloud may process limited data where necessary to provide hosting, networking, storage, security, and related technical services.

If you contact me by email, the email providers (both your and mine) and network services involved in delivering and storing the message may process its contents and associated metadata as necessary to provide those services.

Information may be disclosed where reasonably necessary to comply with an applicable and valid legal obligation, respond to abuse, fraud, spam, or malicious activity, investigate or address a security incident, protect the website, its operator, visitors, or other persons, or establish, exercise, or defend a legal claim.

Your rights

Depending on your location and the laws that apply, you may have rights concerning personal data that relates to you. These may include rights to request access, correction, deletion, restriction, objection, or a copy of certain data. These rights may be subject to applicable legal, technical, and verification requirements.

For comments submitted on or after July 31, 2026, you can independently delete the comment by using the unique comment management link displayed immediately after successful submission. Opening the link allows you to review the associated comment before confirming deletion. Possession of a valid link is treated as sufficient authorization, and no additional identity verification is required.

For comments submitted on or after July 31, 2026, the comment management link may also be used for downloading a copy of your data tied to this specific comment, as well as a way to rectify, edit, or correct the contents of the comment. Anyone with the correct link may perform any of these actions on your behalf. Possession of a valid link is treated as sufficient authorization, and no additional identity verification is required.

The link is displayed only once, and the website does not provide a way to display or recover it later. If you lose the link, or if your request concerns a comment submitted before July 31, 2026, you may contact me using the address below.

Because comments do not require an account, email address, or persistent identity marker, I may not always be able to identify particular data as belonging to you or verify that a request comes from the original commenter. I may ask you to provide information reasonably necessary to identify the relevant comment, data, or correspondence and to protect other visitors against unauthorized access, alteration, or deletion.

I do not collect or retain additional personal information solely to make future identity verification possible. If you provide sufficient information to allow the relevant data and request to be reasonably identified, I will review the request in accordance with applicable law. If the relevant data or authorship cannot reasonably be identified or verified, I may be unable to fulfill it.

Depending on your jurisdiction, you may also have the right to contact or lodge a complaint with the data protection or privacy authority responsible for your location.

Children’s and Minors’ Data

This website is intended for a mature audience and is not directed at children. I do not knowingly or intentionally collect personal information from children or minors. Comments may be submitted using any name, no identity or age verification is performed, and I generally cannot determine whether a commenter is a child or minor.

I do not knowingly solicit or intentionally collect personal information from anyone below the minimum age required to consent to data processing under applicable law. Anyone who cannot legally provide consent should not submit comments or other personal information without the involvement of a parent or legal guardian.

Comments are not linked by me to IP addresses, email addresses, or other identifiers. If I become aware that a comment contains personal information belonging to a child, I may remove it when it can be reasonably identified, but I may be unable to verify the commenter’s identity or age.

Security

I take reasonable technical and organizational measures to protect this website and the limited data processed through it.

comment management links function as private authorization credentials. Anyone who obtains a valid comment management link may be able to delete the associated comment. comment management credentials are used only for that purpose and are permanently invalidated when the corresponding comment is deleted.

Connections to this website are encrypted in transit where supported by the visitor’s browser, device, and network. Specific transport technologies or protocol versions may change over time as part of normal operation and maintenance, so they are not guaranteed as a permanent feature. HTTP/3, QUIC, and TLS 1.3 are transport and security technologies, but they are operational details disclosed for transparency.

Contact

This website is owned and operated by one individual under the public identity used on this website.

For privacy-related questions or requests, you can email me at: ri [@] riri [.] my

Please include enough information for me to understand your request and, where relevant, identify the affected comment, message, or other data.

Changes

I may update this Privacy Policy from time to time by publishing a revised version on this page. Changes become effective when the revised version is published, unless otherwise stated.

Last updated: