Privacy Policy
Last updated: 12 August 2026
ComputingCache is an independent, single-operator project based in the United States. This policy covers the computingcache.com homepage and the services operated under it: the Matrix homeserver, the Mastodon instance, the public Nostr relay, GitLab, Nextcloud and Trilium. It explains what is collected, why, how long it is kept, and what you can ask to have removed.
Who is responsible
The data controller for these services is the operator of ComputingCache, a sole individual based in the United States. All services run on hardware owned and administered by the operator; they are not resold from a third-party platform.
The operator's full legal name and postal address are on file with the United States Copyright Office as ComputingCache's designated agent, and are listed on the reporting and takedown page. If you need to identify the controller formally, for a data protection request or for legal service, that is the authoritative record.
ComputingCachePrivacy and data requests: admin@computingcache.com
Server logs
Like every web server, the reverse proxy in front of these services records basic request data: your IP address, the time of the request, the URL requested, the HTTP status, the referring page and your browser's user-agent string.
These logs exist for diagnostics, capacity planning, and investigating abuse or attacks. They are not used to build a profile of you and are not shared with anyone except where required by valid legal process. Logs rotate and are deleted automatically; the normal retention period is 14 days, extended only for a specific incident under investigation.
Analytics
Visitor statistics for this homepage are collected with Matomo, an open-source analytics package hosted on the same hardware as everything else. No data leaves ComputingCache infrastructure and no third party receives it.
The installation is deliberately conservative:
- Cookies are disabled, so no analytics identifier is stored on your device.
- IP addresses are anonymised before being recorded.
- The browser's Do Not Track signal is honoured; if you send it, nothing is recorded at all.
What remains is aggregate: which pages get visited, roughly where visitors arrive from, and which screen sizes to test against.
Cookies and local storage
The homepage sets no cookies at all. Nothing about your visit is attached to a request back to the server.
It does use localStorage, your browser's own storage, for exactly one
thing: remembering whether you picked the light or the dark theme. That value never
leaves your device, is not an identifier, and is not readable by anyone else. If you
never touch the toggle, nothing is stored and the site simply follows your operating
system setting. Clearing your browser data removes it.
The hosted applications do set cookies once you log in, because a session has to be remembered somehow. Those are strictly functional: a session identifier and CSRF protection. None of them are used for advertising or cross-site tracking.
Contact form
When you send a message through the form on the homepage, the name, email address and message you typed are emailed to the operator. Your IP address and user-agent are included in that email so that spam and abuse can be traced.
A copy of the name, email address and message is also written to a database as a backup against mail delivery failure. That copy does not include your IP address or user-agent, and is deleted automatically 12 months after it is received. The emailed copy lives in the operator's mailbox and is deleted when it is no longer needed.
The form uses a hidden field and a timing check to filter bots, and limits how many messages one IP address can send in ten minutes. No CAPTCHA service or other third party is involved. Ask at any time and your message will be deleted immediately.
Account data on hosted services
If you hold an account on Matrix, Mastodon, GitLab, Nextcloud or Trilium, that service stores what it needs to function: your username, a hashed password, the email address you registered with, your profile, and the content you create or upload. Access and moderation actions are logged.
Passwords are stored as salted hashes and are never visible to the operator. The operator does hold administrative access to the underlying servers, which is technically enough to read unencrypted stored content. That access is used for maintenance and for acting on abuse reports, not for browsing your files. Matrix rooms with end-to-end encryption enabled are not readable by the operator at all.
Backups are taken so that a disk failure is not the end of your data. A deleted account may persist in backup snapshots for up to 90 days before those snapshots are cycled out.
Federation: what leaves this server
This is the most important paragraph on the page. Matrix, Mastodon (ActivityPub) and Nostr are federated protocols. When you post, follow, join a room or send an event, copies are transmitted to every other server that is party to the conversation. Those servers are operated by other people under their own policies.
- Mastodon: posts, profile, follows and media are pushed to remote instances. Deleting a post here sends a delete request outward, but there is no way to guarantee every remote server honours it.
- Matrix: room history is replicated across every homeserver with a participant in the room. Redacting a message asks the others to remove it; it cannot be enforced.
- Nostr: the relay is public by design. Events written to it can be read by anyone and are routinely copied to other relays. Deletion requests (NIP-09) are honoured on this relay, but a copy on another relay is outside our reach.
Treat anything you publish on a federated service as permanently public. If that is not what you want, do not post it.
Federation also means this server receives and caches content from remote servers, including profile images and posts from accounts you follow. That cached remote content is deleted on request and expires on its own over time.
Third parties
The list is deliberately short:
- Google Fonts serves the two web fonts used on this page, so Google's servers see the request for those font files. Nothing else on the page touches a third party.
-
DreamHost relays outbound mail from the contact form and hosts the
computingcache.commailbox. - Let's Encrypt issues the TLS certificates. Certificate issuance is published to public Certificate Transparency logs, which is normal for all HTTPS sites.
- An upstream internet provider carries the traffic, as with any hosted service.
There is no advertising network, no analytics SaaS, no CDN inspecting your traffic, and no data broker. Nothing collected here is ever sold.
Legal disclosure
Data may be disclosed where there is a legal obligation to do so, such as a valid subpoena or court order issued by a competent United States authority, or where disclosure is necessary to protect the safety of a person or the integrity of the service.
Where the law permits it and no investigation would be prejudiced, affected users will be notified before anything is handed over.
Your rights
Regardless of where you live, you can ask for the following by emailing admin@computingcache.com from the address on your account:
- Access: a copy of the data held about you. Mastodon and Nextcloud can export this themselves from your account settings.
- Correction: anything inaccurate fixed.
- Deletion: your account and its content removed, subject to the backup and federation limits described above.
- Objection: tell us to stop a particular use of your data.
Requests are answered within 30 days and there is no charge. If you are in the EU, EEA or UK, these correspond to your rights under the GDPR; if you are in California, to your rights under the CCPA. Because no personal information is ever sold or shared for cross-context behavioural advertising, there is nothing to opt out of on that front.
Children
These services are not directed at children under 13, and accounts are not knowingly created for them. If you believe a child under 13 has an account or has supplied personal information, email admin@computingcache.com and it will be removed.
Security
Everything is served over HTTPS with modern TLS. Passwords are stored hashed. Access to the underlying machines is restricted to the operator over key-based authentication, and software is kept patched.
That said, this is a small independent operation, not a company with a security department. No method of transmission or storage is completely secure, and no guarantee of absolute security is offered. Keep your own backups of anything you cannot afford to lose.
Found a vulnerability? See security.txt. Good-faith reports are welcome and will not be met with legal threats.
Changes to this policy
This policy may be updated from time to time. Changes take effect when posted here, and the “last updated” date at the top reflects the most recent revision. A change that materially affects account holders will be announced from @CCAdministrator on the Mastodon instance.
Contact
Questions about this policy, or any request described above, go to admin@computingcache.com.