Privacy Policy
The short version: the apps run in your browser. Your videos, your text and your activity data are processed on your device and are not uploaded to a server I control. This site counts page views and, if you use the contact form, stores what you send me. I do not sell, rent or trade your data, and I never use it for advertising.
This policy explains what happens to data when you use doniwirawan.xyz or any of the apps I build — Ascent, Bike Fit Analyzer and Aksara Bali (each an “App”). The rules of use live separately, in the Terms of Use.
1. Who is responsible
These are personal projects run by one individual, Doni Wirawan (“I”, “me”, the “Operator”), who is the data controller for anything described here. There is no company behind them. You can reach me at doniwirawan166@gmail.com.
2. The general rule
The Apps are static sites. There is no application database holding your personal content on a server I control. As a rule:
- What you feed an App — a video, a block of text, your activity history — is processed in your browser, on your device.
- What is remembered between visits (preferences, saved results, tokens) lives in your browser's own local storage, and clearing your browser data deletes it.
- I do not sell, rent or trade your data, and I do not use it for advertising.
3. This website (doniwirawan.xyz)
Analytics
Page views are counted with Vercel Web Analytics, which is cookieless, does not profile you, and does not follow you across other sites. It records things like which page was opened, the referrer, and a coarse country and device type.
Google Tag Manager
This site also loads Google Tag Manager, which can place cookies and send data to Google depending on the tags configured in it. That is Google's processing, under Google's own privacy policy, and it is separate from the Apps themselves — the Apps do not load it.
The contact form
If you send me a message through the contact form, the name, email address and message you type are stored in a database (Supabase, hosted in Tokyo) so that I can read and reply to them. Only I can read them: the database policy allows anyone to submit a message and nobody but me to read one back. I keep messages for as long as they are useful to me and delete them when they are not. If you would rather not use the form, email me directly instead. Consent is the legal basis for this, and you may withdraw it by asking me to delete your message.
The reading list
The Reading section on the home page is fetched from my public Goodreads shelves through a server-side function on this site, so your browser never talks to Goodreads for the data itself. The book cover images, however, are served from Goodreads' own image CDN, which will see your IP address and browser as any image request would.
The blog
Reading the blog requires no account and sets no cookie of mine. Posts are fetched from the same Supabase database; images embedded in posts may be served from Supabase storage or, for older posts imported from Medium, from Medium's own CDN, which will see your IP address as any image request would.
4. Ascent (Strava dashboard)
What it accesses
With your authorisation through Strava's OAuth, Ascent can read your profile (name, photo,
athlete ID, gear, totals), your activities (distance, time, speed, elevation, heart rate, power,
cadence, GPS routes, photos, names, dates) and your segments and efforts. It requests the
read, activity:read_all, profile:read_all and
activity:write scopes. Write access is used only when you explicitly choose
to reassign gear on activities you select — it is never used to post, edit or delete anything else.
Where it goes
Your OAuth tokens, preferences and a copy of your recent activities are stored on your device in
browser localStorage. Activity data may be cached to speed up loading. You can
disconnect at any time by revoking Ascent's access in your Strava settings and clearing your
browser storage. Consent is the legal basis for this processing, and you may withdraw it at any time.
Your use of Strava data through Ascent also remains subject to Strava's own Privacy Policy. Full text: Ascent Privacy Policy
5. Bike Fit Analyzer
Your video
Your video is never uploaded. It is read and analysed by your own browser, on your own device, and no copy is kept after you leave the page. Camera access is requested only at the moment you press Record. Saved results and your language choice are stored in your browser's local storage only. The one thing that does leave your device is the download of the pose-detection model and runtime (MediaPipe, from jsDelivr and Google's storage servers) — those servers see your IP and browser, as any file download would, and receive nothing about your video.
The source is published so anyone can audit this claim rather than take my word for it. Full text: Bike Fit Privacy
6. Aksara Bali
The text you type is converted on your device. It is not sent to a server, it is not logged, and there are no accounts.
7. Third parties
The site and the Apps depend on third-party services — Strava's API, Google's MediaPipe, jsDelivr, Google Tag Manager, Vercel hosting and analytics, and Supabase for the blog, contact form and Ascent caching. Those services have their own privacy policies, which govern their own handling of any data they receive. I am not responsible for how third parties operate their services.
8. Your rights
Most of what the Apps hold about you is on your own device, so you can delete it yourself by clearing your browser storage, and you can revoke Ascent's access from inside Strava at any time. For anything I do hold — essentially, contact form messages — you may ask me for a copy, ask me to correct it, or ask me to delete it, and I will. Email doniwirawan166@gmail.com.
9. Children
These are not services aimed at children, and I do not knowingly collect anything from them.
10. Changes
These are active projects, so this policy may change. The date at the top says when it last did. Where an individual App publishes its own, more detailed privacy policy, that document is the authoritative one for that App and prevails over this summary in the event of a conflict.
11. Contact
Questions, corrections and privacy requests: doniwirawan166@gmail.com, or open an issue on GitHub.