Skip to content

Privacy Policy

Last updated: September 9, 2026

CodexScribo is one person: Fernando Silveira, working from Brazil, and the controller of everything described below. This page says what this website collects, why, and how to reach me about it — write to hello@codexscribo.com. It is a business-to-business site, it is not directed at children under 13, and I do not knowingly collect anything from them.

The contact form

It asks for your name, your email address, your agency (optional) and your message. I use that to reply to you and to discuss the work you are asking about, and for nothing else: no mailing list, no marketing sequence, and nothing passed to anyone for their own purposes. I keep submissions while the conversation and any resulting engagement are live, plus a reasonable period afterwards for business records, and I will delete yours on request.

An invisible spam check runs when you first click into a field: your browser is given a small puzzle, and the answer is what proves you are not a script. There is nothing for you to do and nothing to click. It sets no cookie and no captcha company is involved — the check and the relay that carries your message to my inbox both run on servers I operate.

Cookies and Google Tag Manager

Nothing from Google loads on this site until you accept it. If you accept, Google Tag Manager runs: Google receives data about your visit, including your IP address, and may store cookies in your browser, and that data is transferred to the United States. Two things run inside it — analytics, and conversion measurement for my own advertising, which is how I tell whether an ad I paid for is what brought you here. If you send the contact form after accepting, the fact that a message was sent is reported to that measurement; what you wrote in it is not. If you reject, nothing is requested from Google at all. Accepting is entirely your choice, and you can change it whenever you like through “Cookie settings” in the footer of any page.

Two entries are kept in this site’s localStorage: your light / dark preference, and your answer to that banner. Neither is a cookie, neither holds personal data, neither is ever sent anywhere, and clearing your browser data removes both.

Analytics

Page views are counted by analytics software running on a server I operate, so those counts reach no analytics company. It is cookieless: no cookie, no identifier, nothing stored in your browser, and no tracking of you across sites or over time. What it records is the page you viewed, the page that referred you, and coarse details derived from your request — browser, operating system, device type and country.

Alongside those it records a short, fixed list of interactions, so I can tell which parts of the page do their job: which call-to-action button was pressed and where on the page it sits, which link out of the site was followed, how a contact form submission ended, and which answer you gave the cookie banner. That list is written into the source of this site and nothing is added to it while you are here. None of it carries anything you typed — when validation stops a submission, the event records which fields still need fixing, by name, and never a word of what is in them.

Your visit is also being recorded as a session replay — mouse movement, clicks, scrolling — so I can see where the page loses people. Every visit is recorded, not a sample of them. All text and every input is masked before the recording leaves your browser, and the contact form is excluded from recording entirely, so a replay shows me layout and interaction, never what anything said and never anything you typed.

The same recording also produces a heatmap: where clicks and cursor movement land on each page. It is that data seen a different way rather than a second collection, so the exclusion above covers it too — nothing you do inside the contact form reaches a heatmap either. Recordings stay on my own server and are deleted after thirty days.

Where it goes, and your rights

Everything above that is mine — the analytics and its replays, the spam check, the relay, the server logs and the inbox your message lands in — is operated and read from Brazil. A message sent from anywhere else leaves the country to reach me, and there is no other route to me I could offer you instead. Google is the one exception and only if you accepted it, in which case that data goes to Google and to the United States. The web server also keeps ordinary access logs — IP address, time, the path requested, user agent — for security and troubleshooting; they are rotated on a short schedule and never used to build profiles. My legal basis is your consent for anything involving Google, and my legitimate interest in replying to you and in keeping this site working and secure for everything else.

Wherever you are, you can ask me what I hold about you, ask for a copy in a portable form, ask me to correct it, ask me to delete it, object to my using it, and withdraw a consent you have given — the banner answer through the footer link, anything else by writing to hello@codexscribo.com, and I will answer within thirty days. I do not sell or share personal information, and I never have. If you think I have handled your data badly, you are also entitled to complain to your local data protection authority.

Changes, and reaching me

If this policy changes, the date at the top of the page changes with it, and material changes will be described here rather than made quietly. Anything about this policy, or about data I hold: hello@codexscribo.com.