Effective date: July 19, 2026

This Privacy Policy explains how h4ck3d.com (the “Site”), operated by Patrick Clinger, handles information. The Site is a personal technical blog. It does not offer user accounts, comments, paid services, or direct payment processing. It does not display advertising, use affiliate links, or publish sponsored recommendations.

This policy describes the Site’s current intended configuration. It is not a promise that a particular privacy law applies or does not apply, and it is not legal advice.

When you request a page, normal web infrastructure receives information needed to deliver and protect it. This may include your IP address, request time, requested URL, referring page, browser or device information, and security or diagnostic signals.

The Site is hosted on Cloudflare Pages. Cloudflare may process request and operational log data to deliver, secure, and diagnose the service under its own agreements and policies. Learn more in Cloudflare’s Privacy Policy.

The Site does not intentionally ask Cloudflare to collect sensitive personal information. Patrick’s access to logs and their retention depend on the Cloudflare account and services in use.

The production Site may use Google Analytics 4 (“GA4”) to understand aggregate usage, such as which pages are visited and the general types of devices used. The Site’s GA4 measurement identifier is configuration data; analytics is disabled in local development, automated tests, and Cloudflare preview deployments.

The Site uses a basic consent approach. Google’s analytics script is not requested and no analytics measurement is sent to Google unless you choose “Allow analytics” in the Site’s analytics control. Declining leaves GA4 unloaded. The Site stores your allow or decline choice in your browser so it can honor that choice on later visits.

If you allow analytics, GA4 may set first-party analytics cookies and process device and usage information. Network requests necessarily carry an IP address to Google. Google states that GA4 uses IP addresses at collection time to derive coarse location and discards them before data is logged in Analytics. Google has also announced that encrypted IP addresses may flow to a linked Google Ads account for some traffic outside the EEA, UK, and Switzerland. The Site’s GA property is not intended to be linked to Google Ads or used for advertising.

Patrick does not configure GA4 to receive email addresses, contact details, article content, User-ID values, or other directly identifying custom parameters. The Site denies advertising consent types and is intended to disable Google Signals, advertising personalization, unnecessary product links, and unnecessary custom events. Those account-side settings must be verified before production analytics is enabled because this repository cannot enforce every setting in Google’s administration interface.

Google’s current documentation explains how Google Analytics safeguards data and how Consent Mode works. Google may process data in countries other than your own under its terms and transfer mechanisms.

When analytics is enabled for the production Site, you can allow or decline it in the initial prompt and later change your choice from this section. Revoking a choice prevents future GA4 loading; it cannot retract data already processed. Clearing browser storage will also clear the saved choice and the Site may ask again.

The Site uses limited first-party browser storage:

  • Theme preference: if you choose System, Light, or Dark, the selection is stored locally so the Site can display your chosen theme. This is functional and is not sent to Patrick.
  • Analytics choice: when production analytics is enabled, an allow or decline choice is stored locally so the Site can respect it. GA4 is not loaded for a declined or absent choice.
  • GA4 cookies: these may be set only after you allow analytics. Their names and duration can change with Google’s service and configuration.
  • Substack embed: the subscription form is not loaded until you activate it. After activation, the third-party frame may use cookies or similar browser storage under Substack’s policies and your browser settings. The Site does not control that storage.

The Site does not use advertising cookies or its own cross-site tracking. Browser settings can clear or block storage, although doing so may reset the theme or analytics choice.

The Site offers both a normal link to Patrick’s Substack subscription page and a click-to-load Substack signup form presented in a modal dialog. The iframe is absent when the Site page first loads, so merely visiting a page does not request the form from Substack. The interface explains the third-party connection before activation and sends no email address to Substack unless you enter and submit one.

If you activate the embedded form, your browser requests content directly from patrickclinger.substack.com. Substack may receive information ordinarily associated with that request, such as your IP address, browser or device information, request time, and usage within the embedded form. The iframe uses a no-referrer policy so h4ck3d does not intentionally send the page address in the referrer header. Substack may use cookies or similar technologies within the frame according to Substack’s Privacy Policy, its applicable terms, and your browser settings.

Whether you use the embedded form or the direct link, Substack handles the subscription, confirmation, email delivery, subscription records, and unsubscribe process. The direct link remains available if you prefer not to load embedded third-party content.

The signup language explains what you are requesting. Newsletter messages should provide an unsubscribe method. You may unsubscribe using the link in an email or the controls Substack provides. Patrick remains responsible for using the resulting list appropriately and cannot transfer away legal responsibility merely by using a provider.

If you email Patrick, the message may include your email address, name, message content, attachments, and any information you choose to provide. This information is used to read, route, respond to, maintain reasonable correspondence records, prevent abuse, and protect legal or security interests.

Do not send passwords, private keys, health data, financial account details, or other sensitive information. The Site does not provide a contact form, and contacting Patrick does not create a confidential or professional relationship.

The Site may publish original photography, screenshots, diagrams, licensed images, and AI-generated illustrations. Image provenance is recorded in the publishing metadata where useful. AI-generated imagery is not intended to depict a real person or event unless that fact is clearly stated and supportable.

Blog posts may include code, screenshots, diagrams, citations, and links to third-party sites. Following a third-party link sends a request to that provider, which may collect information under its own policy. The first release does not embed social feeds or load third-party media players globally. Its only planned third-party frame is the Substack form described above, and that frame requires visitor activation. If a future post introduces another embed, this policy and the Site’s loading behavior should be updated before publication.

Information may be used to:

  • deliver, secure, maintain, and diagnose the Site;
  • understand aggregate readership after analytics consent;
  • manage newsletter subscriptions and delivery through Substack;
  • respond to direct communications;
  • comply with applicable law or valid legal process; and
  • establish, exercise, or defend legal rights and prevent abuse.

Service providers may process information for those purposes. The Site does not sell personal information and does not share personal information for cross-context behavioral advertising. It does not intentionally collect sensitive personal information. It may disclose information if reasonably necessary to comply with law, protect people or systems, or address fraud and security incidents.

Retention varies by context:

  • Cloudflare retains operational data according to the services and account settings in use.
  • GA4 user-level and event-level retention is controlled in the Analytics property and should be set to the available two-month option before production analytics is enabled. Google states that this setting does not control standard aggregated reports in the same way.
  • Substack retains subscription and delivery records under its settings and policies.
  • Contact messages are kept only as reasonably useful for correspondence, records, security, or legal needs, then deleted or allowed to age out through ordinary mailbox practices.
  • Theme and analytics choices remain in your browser until you change them, clear storage, or the Site changes the storage key.

No retention period should be read as a guarantee that data is kept for exactly that long; backups, security records, legal holds, and provider behavior may affect deletion timing.

You can decline analytics, change the saved analytics choice, clear browser storage, use browser tracking protections, unsubscribe from newsletter emails, and choose not to send contact information.

Depending on where you live and whether a law applies to the Site’s operation, you may have rights to request access, correction, deletion, restriction, objection, portability, or information about data practices. California residents may also have rights concerning sale or sharing; the Site states that it does not sell personal information or share it for cross-context behavioral advertising. The Site does not discriminate against a person for making a good-faith privacy request.

Requests can be made through the protected email method on the About page. Patrick may need enough information to understand and verify a request and may decline or limit a request where the law permits or where the Site cannot reasonably identify responsive data.

The Site is available internationally. Cloudflare, Google, Substack, and email providers may process information in multiple countries whose laws differ from those where you live. Where required, those providers may rely on contractual or other transfer mechanisms described in their materials.

Analytics consent rules vary by jurisdiction. The Site applies its no-Google-request-before-consent approach globally rather than attempting browser-only geographic detection. That conservative engineering choice is not a substitute for jurisdiction-specific legal review.

The Site is written for a general technical audience and is not directed to children under 13. It does not knowingly seek personal information from children. If you believe a child provided personal information directly, use the contact method below so the situation can be reviewed.

The Site uses static hosting, HTTPS, limited client-side JavaScript, restricted third-party loading, and security headers to reduce risk. No internet transmission or storage system is perfectly secure. Do not send secrets through the contact address.

This policy may change when the Site’s services, practices, or applicable guidance change. The effective date at the top will be updated. Material changes should be reflected in the actual implementation before or when the revised policy is published.

Privacy questions and requests can be sent using Patrick’s accessible, scrape-resistant email method on the About page.