Skip to content

Privacy Policy

A straight explanation of what this site collects, why, and what you control. No dark patterns, no data selling, no surprises.

Last updated September 22, 2026.

Who is responsible

This is a personal site published by Mattia Ciuni, founder and CEO of Noesia. For anything on this page, the person responsible for your data is Mattia Ciuni, reachable at [email protected]. The site is a personal publishing project: it is not a Noesia product page and it does not offer user accounts.

It is hosted on Cloudflare Pages. There are exactly three places where you can leave something behind: the newsletter form, the feedback form, and the analytics choice. Each one is described below.

The newsletter

The newsletter is optional. When you subscribe I collect your email address and the information needed to manage the subscription: which channel brought you here (campaign, source, medium, landing page and referring domain, the same fields you can read in the URL of an ad or a link), the date and time of signup, plus a suppression record if you unsubscribe.

The legal basis is your consent, given when you submit the form. You use it to receive the weekly email, the Welcome email right after signup, and nothing else. Unsubscribing takes one click in any email or one email to me.

The subscriber record lives in my own database on Supabase, with the email address, the attribution fields above, the subscription status and the dates. The same address is then kept inBrevo, which sends the list emails and where the list “Mattia Ciuni Newsletter” lives, and in Beehiiv, a second subscription platform I use to keep the list available if one provider fails. Resend sends the Welcome email right after signup. All four are processors, not owners: they cannot use your address for their own marketing, and they act under their own data processing terms.

The only people who ever see your address are you, me, and those providers. I do not sell it, rent it, share it with advertisers, or use it for anything other than this newsletter.

The feedback form

The feedback form in the Feedback section sends me what you write: the message (required), your name and email if you choose to add them, the page you sent it from, and the date and time. Your IP address is used transiently to limit automated traffic and is not saved with the feedback. Messages are stored in my own database on Supabase, together with the index of the review queue; if the database is ever unconfigured the same record goes to Cloudflare Workers KV instead, so a submission is never lost to a missing provider. A notification with the text is sent through Brevo so I can read it on my phone, and if you left an address, a confirmation is sent to you through Resend.

Two things about that confirmation, because they are the kind of detail usually left out: the recipient address of every email the site sends is recorded only as a hash, in a delivery log that exists to prove a message left and to avoid sending it twice; and the confirmation email is a receipt, not a subscription. It does not add you to the newsletter.

The legal basis is your consent, given by submitting the form, and my legitimate interest in keeping the queue free of spam. Rate limiting (three submissions per ten minutes per address) and a hidden anti-bot field keep automated traffic out.

Reviews are published only after I read them, and you decide how you appear: your name, your name with a link, or just an initial. A submission is not confidential correspondence with an expectation of secrecy: if you send something you would not want published, say so in the message and I will keep it private. You can ask me to delete any submission, published or not, at any time, and I will remove it and its notification.

The review dashboard

Feedback and the moderation queue are read in a private dashboard at /admin/feedback/, reachable by me and by Noesia's co-founder and CTO, each with their own credential plus a six-digit code from an authenticator app. Access is logged there: who acted, on what, when. It is not a public page, it is not indexed, and it is not measured by analytics.

Measurement: three tools, three rules

Three things measure this site and they are deliberately not the same kind of thing. The first is Umami, a counter that runs from the first page view without asking anything: it writes no cookie and no identifier on your device, it does not keep your IP address, it does not follow you to other sites and it cannot recognise you on a later visit. It counts the page, the referring domain, the country, the browser and the device in aggregate form. Since nothing about you is stored, there is nothing to consent to, and the notice on this site does not ask about it.

Beside those, every event is written to a copy in my own database, on Supabase. It is the one piece of this that does not depend on a provider staying in business: the measurement of the site cannot be lost because a plan changed or a service closed. That copy is anonymous by construction. Your address is read once, to compute a one-way fingerprint of that visit and that day, truncated, and is then discarded: the fingerprint cannot be reversed, it cannot be linked from one day to the next because the date is part of it, and nothing else about your device is kept, not the user agent, not a cookie, not an identifier. What is written is the page, the event, the time, the country, whether the device was a phone or a computer, and how you arrived. It is kept without a deadline: the whole point of the copy is that nothing is deleted from it.

The second is Microsoft Clarity, a session-recording and heatmap tool that runs from the first page view, like Umami, without asking anything. It records how pages are used: clicks, scrolls, dead clicks, rage clicks, and the movement of the mouse on the page, in aggregate heatmaps and per-session recordings. It is never used for advertising and Microsoft does not sell its data or run it for ad targeting. What it keeps: a session identifier in your browser (the cookies _clck and _clsk, listed on the Cookies page with their durations), your IP address and browser data in truncated, aggregated form on Microsoft's servers, and the interactions listed above. What it never sees: passwords or anything typed into any field on this site, which Clarity masks by default, and there are no forms on this site that Clarity is allowed to read. If a recording would capture a page containing personal text you submitted, the pages that render your own submissions are outside what the recordings replay, and no recording is ever linked to a name or an email address. The legal basis is my legitimate interest in understanding how the site is used, which does not conflict with your rights because the content you read and the text you type are masked and the identifier is not used to follow you anywhere else. You can read exactly what Microsoft keeps in Clarity's own documentation.

The third is Google Analytics 4, and it is optional and off until you allow it: it does keep an identifier in your browser, and that identifier is exactly the reason consent is required. If you choose “Allow” in the notice, it receives a measurement of how the site is used. Concretely, and completely, that is:

  • the pages you view, with the kind of content (an article, a note, the home page)
  • how you arrived: the referring domain, the campaign parameters in the link you followed (utm_source, utm_medium, utm_campaign, utm_content, utm_term), the click identifiers of paid campaigns when they are present, and the page you landed on
  • the source of your first visit, kept in your browser so a later visit is attributed honestly
  • how long each page stayed open and how far you scrolled through it, at four points: a quarter, half, three quarters, and the end
  • where you went next: the page you moved to, and the destination domain when you leave the site or close the tab
  • clicks on internal links and on links that lead outside, with the text of the link
  • how many pages the visit contained and how long the visit lasted as a whole

Advertising storage, advertising personalisation and ad user data are explicitly denied, no advertising features are enabled, and IP addresses are not stored or reported by Analytics: Google uses the address at collection time to derive an approximate location and does not retain it. Nothing here is personal, nothing is sold, and no measurement is linked to an identity.

Campaign attribution follows a strict first-touch and last-touch rule. The first meaningful source is never overwritten; a later meaningful campaign updates only last touch. The site records normalized source, medium, campaign, content, term, campaign ID, landing pathname, referrer domain and supported click IDs such as gclid and fbclid. Query strings are not stored wholesale, and no personal data is put into event parameters. A session copy is kept in session storage for the anonymous first-party measurement. The persistent first-touch copy is created only after Google Analytics consent.

The same events are exposed as a flat, vendor-neutral data layer for a future tag manager. It contains event names and operational values such as page type, CTA, form, destination and scroll percentage. It never contains names, email addresses, messages, tokens or raw query strings. The active real conversions are newsletter signup and feedback submitted. There is no customer, revenue or advertising conversion in this site yet.

The purpose is editorial for all of them: knowing which pages are read, which are abandoned halfway, where people arrive from and where they leave tells me what to keep writing and what to fix, which is the whole point of a site like this one. None of the three is used for advertising, profiling or decisions about you, and none is shared with anyone. Google retains its measurement for up to 14 months and acts as an independent controller for its own processing, described in Google's privacy policy; Umami keeps aggregate counts, not visits; Microsoft retains Clarity recordings for up to 12 months, under its own data protection terms. If you decline Google Analytics, nothing of it is loaded and nothing of it is measured, while the cookieless counter and Clarity keep running as described above. You can change your choice at any time by clearing this site's browser storage, as described in the Cookies page.

Hosting and technical logs

The site is served by Cloudflare, which sees the requests needed to deliver a page: IP address, user agent, the address requested and the answer. Cloudflare keeps those logs as a service provider for security and reliability, and they are not used by this site to build profiles. The newsletter and feedback endpoints log only anonymous outcomes (which kind of request, whether it succeeded, how long it took): never an email address, a message, an IP address or a provider credential.

What stays in your browser

A few values are stored locally so the site remembers your choices instead of asking again: the newsletter state, the analytics choice, the source of your first visit, and a handful of visit counters that measure one visit inside one tab (how many pages it has touched, when the current page was opened, and a flag that stops the same source from being counted twice). Microsoft Clarity keeps its own session cookies, _clck and_clsk, in the same browser: they are described on the Cookies page with their durations. None of them identify you personally, and the complete list is on the Cookies page.

Who else is involved

The processors listed above (Cloudflare, Supabase, Resend, Brevo, Beehiiv, Umami for the cookieless counter, Microsoft Clarity for session recordings and heatmaps, Google for the optional analytics) are the only third parties involved. They may process data outside the European Union, under their standard contractual clauses or an equivalent safeguard. There are no advertising networks, no trackers from social platforms, no data brokers, and no sale or rental of personal data ever. If I add a provider, this page is updated before it starts processing anything.

How long it is kept

Newsletter: for as long as you stay subscribed, plus the minimum suppression record needed not to contact you again. Feedback: until you ask me to delete it, or while it stays in the review queue; published reviews stay published until you ask me to remove them. Email delivery logs: metadata only, with the address hashed. Measurement: aggregate counts at Umami, the copy in my own database kept without a deadline because that is the reason it exists, session recordings and heatmaps at Microsoft Clarity for up to 12 months, and up to 14 months at Google for the optional analytics. Hosting logs: Cloudflare's own retention period. Nothing is kept “just in case”.

Your rights

You can ask for access to your data, correction, deletion, restriction, portability, or object to the processing, and you can withdraw consent at any time without any consequence. Write to [email protected] and I answer within 30 days. Unsubscribing from the newsletter is immediate and needs no explanation.

If you believe your data has been handled badly, you can complain to the Italian supervisory authority, the Garante per la protezione dei dati personali, or to your local authority.

Children

The site is written for people working in or interested in startups and payments, and it is not addressed to children under 16. If you believe a child has sent me data, write to me and I will delete it.

Changes and contact

If something changes, this page changes with it and the date at the top moves: there is no small print to spot. Questions, or a request to delete something, can go to [email protected]. The other documents are in the Legal Center.

Legal Center