Skip to content
mykyta.app

Privacy

This notice explains what personal data mykyta.app uses, why it is needed and what choices you have.

Who is responsible

Mykyta Frolov, the independent product developer who operates mykyta.app from Belgium, is the controller for personal data collected directly through this site.

For a privacy request, email updates@mykyta.app or use the contact page. Please describe the data or interaction your request concerns. Identity may be verified before a request is completed when reasonably necessary to protect your data.

Data the site processes

The site processes only the information needed for the feature you choose to use.

  • Contact messages: name, email address, optional organization and project, message, preferred language, consent time and limited request metadata.
  • Comments: display name, email address, comment, related blog entry, reply relationship, language, moderation status and consent time. An approved display name and comment become public; the email address does not.
  • Email subscriptions: email address, language, confirmation and unsubscribe status, timestamps and the page where the request started.
  • Support payments, when enabled: selected project, amount, currency, one-time or recurring mode, status and limited Stripe identifiers used for reconciliation. Card details are entered on Stripe and are not stored by mykyta.app.
  • Abuse prevention: keyed, non-reversible representations of an IP address and browser user agent, short-lived rate-limit records and a Cloudflare Turnstile result.

Purposes and legal bases

Personal data is used for the following limited purposes.

  • To answer a message or take steps requested before a possible collaboration: consent and, where applicable, steps before entering a contract.
  • To receive, moderate and publish a comment: consent, together with the legitimate interest in maintaining a safe and useful discussion.
  • To send blog updates: consent. Subscription is not active until the confirmation link is used, and consent can be withdrawn through the unsubscribe link.
  • To create and reconcile support payments when enabled: performance of the requested transaction, legitimate interests in accurate records and legal accounting obligations where they apply.
  • To prevent spam, fraud and misuse and to protect the site: legitimate interests in service security. Turnstile is not used for advertising or to make decisions with legal or similarly significant effects.

Service providers and transfers

Personal data is shared only where needed to operate the chosen feature. Vercel hosts the application, Supabase stores private operational records, ImprovMX relays transactional email, Cloudflare provides Turnstile abuse protection, and Stripe handles checkout when payments are enabled.

Some providers may process data outside Belgium or the European Economic Area. Where required, the relevant provider terms and transfer safeguards, such as adequacy decisions or standard contractual clauses, apply. Current provider privacy information is available from Vercel, Supabase, ImprovMX, Cloudflare and Stripe.

Personal data is not sold. It may be disclosed when required by law or when necessary to establish, exercise or defend legal claims.

How long data is kept

Records are kept only for as long as their purpose, security needs and applicable legal obligations require.

  • Contact messages are reviewed for deletion after the conversation and any reasonable follow-up period, normally no later than 24 months after the last interaction unless a legal reason requires longer retention.
  • Comment content remains while the discussion is published. Rejected or deleted comments and private contact details are removed or minimized when they are no longer needed for moderation, abuse prevention or a deletion request.
  • A pending subscription expires if it is not confirmed. An active subscription is kept until unsubscribe; a minimal suppression record may be retained to respect the unsubscribe choice.
  • Rate-limit records expire with their configured security window. Daily keyed network and browser representations cannot be used to recover the original values.
  • Payment records are retained for the period required for reconciliation, tax, accounting, disputes and other applicable legal obligations.

Your rights

Subject to the conditions in applicable data-protection law, you may request access, correction, deletion, restriction, portability or object to processing. You may withdraw consent at any time without affecting processing that was lawful before withdrawal.

  • Use the unsubscribe link in any subscription email to stop blog updates.
  • Email updates@mykyta.app to exercise another right or request removal of a comment.
  • There is no solely automated decision-making with legal or similarly significant effects.
  • You may complain to the Belgian Data Protection Authority at dataprotectionauthority.be or to the supervisory authority where you live or work.

Security and required fields

Private email fields are encrypted before storage, direct anonymous database access is denied, owner actions require protected authentication, and public submissions use rate limits and Turnstile. No internet service can guarantee absolute security.

Fields marked as required are needed to deliver the selected feature. If they are not provided, the message, comment, subscription or payment request cannot be processed. Optional fields can be left empty.

Changes to this notice

The effective date is shown above. Material changes will be published on this page before they apply where practical. If consent is required for a new purpose, it will be requested separately.