Paczesny° Back

This is an English translation provided for convenience. The Polish version is the legally authoritative text.

Legal document

Privacy Policy

Last updated: July 7, 2026

1. Data controller

The data controller is the owner of the Paczesny Analytics service (the "Service"), available at analytics.blonie.cloud. For matters concerning privacy and data protection, you can write to bartek@paczesny.pl.

When you connect a Google Search Console property, Paczesny Analytics acts as a processor of the Search Console data you authorise us to read, on your behalf and only on your instructions. The terms of that processing are set out in our Data Processing Agreement.

2. Data we process

Account data. Email address and authentication credentials (a hashed password, optionally MFA) necessary to create and secure your account.

Analytics data (cookieless). For the sites you connect, we collect visit events without cookies and without personal data. The visitor identifier is computed server-side as sha256(siteId + ip + user-agent + daily salt) — the raw IP address is never stored as part of visitor analytics data, and the identifier cannot track the same person across days. We keep raw events for up to 30 days, and afterwards only aggregated data.

Google Search Console data. If you choose to connect your Google account, we read the performance statistics of your verified sites in Search Console (clicks, impressions, CTR, average position — broken down by query, page, country and device).

Account-operations data. When you sign up or accept a legal document such as this Privacy Policy or our Data Processing Agreement, we record your IP address alongside that action in our legal-acceptance log. Unlike visitor analytics, this IP address is retained as evidence of contract and consent under GDPR Art. 6(1)(b) (performance of a contract) and Art. 6(1)(c) (compliance with a legal obligation); it is never used for visitor analytics.

3. Google Search Console — data scope and use

By default, the Google connection uses only the read-only scope https://www.googleapis.com/auth/webmasters.readonly, and no setting in your Search Console property is changed under that default connection. Separately, you may opt in to a read-write scope upgrade — a distinct, explicit action from the initial connection — which allows the Service to submit and delete sitemap entries in Search Console on your instruction. This write access is never granted automatically; it requires that additional consent step.

The fetched data serves a single purpose: presenting your search statistics in the Service's dashboard. We do not use it for advertising, do not share it with third parties, and do not use it to train models.

Paczesny Analytics's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

The OAuth refresh token is stored encrypted (AES-256-GCM). You can revoke access at any time — by disconnecting the integration in the Service's settings or in your Google account settings.

4. Storage and security

Data is stored in a self-hosted database (Appwrite) on a server under our control. We use connection encryption (TLS), encryption of sensitive tokens, and we restrict data access exclusively to the account owner.

Retention periods: raw event data is kept for 30 days; the alert delivery log for 90 days; aggregated statistics and heatmaps are kept until you delete the connected site or your account; records of legal acceptance are pseudonymised and retained as evidence of that acceptance rather than purged on a fixed schedule (GDPR Art. 17(3)(b)).

5. Cookies

The analytics tracker uses no cookies or other tracking techniques. The only cookie we use is a technical session token required to keep you signed in to the dashboard.

6. Recipients and processors

We do not sell or exchange data. We use the services of the following providers solely for the operation of the Service:

  • Google (Search Console API and PageSpeed Insights / CrUX) — retrieving performance data and speed metrics for your sites,
  • Groq — generating funnel suggestions based on aggregated, non-personal event paths.

We also rely on Resend (transactional email), Oracle Cloud Infrastructure (hosting) and — only if you enable them — Slack or Discord (alert channels). A full, current list of our sub-processors is available at /sub-processors.

7. Your rights

You have the right to access, rectify, delete, and object to the processing of your data (GDPR). You can disconnect the Google integration, delete connected sites or your entire account at any time. For these matters, write to bartek@paczesny.pl.

All data-subject requests are handled through a single channel: write to bartek@paczesny.pl. We respond within the timeframes required by the GDPR.

8. Policy changes

We may update this policy. We signal significant changes with the "Last updated" date at the top of the page.