Learn how DCYFR Labs collects, uses, and protects your information. We prioritize privacy with minimal data collection and no tracking.
Last Updated: August 31, 2026
At DCYFR Labs, we believe in transparency and privacy by design. This policy explains how we collect, use, and protect your information when you visit our website.
Controller: DCYFR Labs is a trading name, not a registered company. The sites are run by one individual working as a sole proprietor in Colorado, United States, and that person is the data controller for everything described here. We name the arrangement rather than imply a corporate entity that does not exist. For any question about this policy, or to exercise the rights described below, contact us.
This policy is the canonical privacy policy for the DCYFR web estate. It covers dcyfr.ai and the sibling sites dcyfr.io, dcyfr.app, dcyfr.bot, dcyfr.codes, dcyfr.tech, dcyfr.work, and dcyfr.build.
Each sibling site carries its own short notice at /privacy listing the processors that site actually uses, because they are not identical: dcyfr.bot sends chat messages to a model provider, dcyfr.codes publishes snippets to GitHub, and the rest do not. Where a site notice and this policy differ on a detail specific to that site, the site notice is the accurate one.
Purpose: To respond to your inquiries and provide support. Storage: Contact form data is processed via Inngest and not permanently stored. We only retain your email in our inbox for correspondence purposes.
We store preferences locally in your browser to enhance your experience:
Search History: Recent searches in command palette
Bookmarks: Saved blog posts and pages
Likes: Activity engagement (blog posts, projects)
Purpose: Personalize your experience with saved preferences. Storage: Client-side only (not shared with server unless you log in). Control: Clear via browser settings or our UI.
For certain interactive features, we create temporary encrypted sessions:
Session identifier (randomly generated)
Temporary preferences
Purpose: To maintain state for interactive features. Storage: Encrypted in Vercel Redis (managed Redis service) with automatic expiration (24-48 hours). Security: All session data is encrypted using industry-standard encryption (AES-256-GCM). Provider: Vercel (powered by Upstash infrastructure, GDPR-compliant)
Purpose: Security monitoring, error detection, and performance optimization. Retention: Automatically deleted after 30 days (Vercel’s standard retention).
Cookies: We set no cookies of our own. Third-party content you choose to load (the giscus comment box, an embedded YouTube or Vimeo player) is served by those providers and may set their own cookies once loaded
Individual User Tracking: No cross-site tracking, user profiles, or behavioral analysis. Sentry Session Replay records a small sample of individual sessions for debugging; see Session Replay below
Invasive Analytics: No Google Analytics, Facebook Pixel, or similar tracking platforms that follow users across the web
Advertising Data: No ad networks or retargeting pixels
Social Media Tracking: No social media plugins that track you
Fingerprinting: We don’t create browser fingerprints or device identifiers
Sensitive Personal Information: No SSN, payment info, health records, or similar sensitive data
Our error monitoring includes Sentry Session Replay, which reconstructs what happened in the browser leading up to a problem.
When it runs: roughly 5% of sessions on dcyfr.ai, plus 50% of sessions in which an error occurs. Sibling sites sample about 1%.
What it captures: DOM mutations, clicks, scrolls, navigation, and network timing, which is enough to replay the sequence of events.
Masking: text content and media are masked at capture, in the browser, before anything is transmitted. A replay shows layout and interaction, not the words on your screen. Form inputs are masked on the same basis.
What it is used for: reproducing faults. It is not used for analytics, profiling, marketing, or measuring individuals.
Retention: replays are stored by Sentry and expire on Sentry’s retention schedule.
Opting out: block sentry.io in your browser, or use an extension that blocks error-monitoring scripts. Every site in the estate works without it.
We use Vercel Analytics and Speed Insights to understand how our website performs. Unlike traditional analytics platforms, these are privacy-first services:
Retention: Analytics data is retained for 30 days (Vercel’s standard retention). Opt-out: You can opt out by enabling “Do Not Track” in your browser settings. Learn More:Vercel Analytics Privacy Policy
Purpose: Comment threads on articles, backed by GitHub Discussions
Data Processed: Loaded in an iframe from giscus.app. If you sign in to comment, you authenticate with GitHub and your comment is public in the linked discussion
Cookies: giscus and GitHub may set cookies once the comment box loads
DCYFR Labs operates from Colorado in the United States. If you access our website from outside the United States, please be aware that:
Your information may be transferred to and stored in the United States
U.S. data protection laws may differ from those in your country
By using our website, you consent to this transfer and processing
For users in the European Economic Area and the United Kingdom, the rights listed above apply in
full, and the legal bases we rely on are set out at the end of this policy. Collecting little data
reduces how much is at stake, but it is not by itself compliance, so we describe what we actually do
rather than claim a verdict on it.
Article 27 of the GDPR requires a controller established outside the Union to designate a
representative inside it when the controller offers services to, or monitors the behaviour of, people
in the EU. The UK GDPR sets a parallel requirement for the United Kingdom.
No representative is currently designated for either. That is a gap, and we would rather state it
than leave the question unanswered. Until one is appointed, people in the EU and the UK can reach the
controller directly through our contact page, and every right described above is available
to them on the same terms as to anyone else. You may also lodge a complaint with the supervisory
authority in your country of residence, which you can do whether or not a representative exists.
Our website is not directed to children under 13 years of age. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately and we will delete it.
If you have questions, concerns, or requests regarding this privacy policy or our data practices, please contact us. We aim to reply within five working days. Where a request is one of the rights listed above, the GDPR allows a controller one month to answer it, and we will not take longer than that.