Who we are
coresmith.dev is an independent engineering studio based in the Republic of Moldova. The site lives at https://coresmith.dev. For any privacy question or request, write to services@coresmith.dev. That mailbox is the data controller for everything described on this page.
What we collect
When you submit the project brief, you send us:
- Your email address — required, so we can send the scope back
- Two choices you tap: what kind of work it is, and when it starts
- Optionally, a short description of the project, in your own words — a free-text field, up to 4,000 characters. Whatever you type there is what reaches us; please don't put passwords, card numbers or anyone else's personal data in it
- A short-lived bot-check token from Cloudflare Turnstile
When you visit any page on the site:
- Aggregate page views via Umami Cloud — cookieless, no cross-site identifier
- Your browser type, OS, and country (derived from IP at the analytics edge, IP itself is not stored)
- Errors, only if something on the page actually breaks (via Sentry)
- Your IP address in our server's request logs, temporarily, for rate-limiting and bot-check
We do not collect: contact lists, photos, location data, payment information, biometric data, social-graph data, browsing history outside this site, or anything from minors.
Why we collect it (legal basis)
- Project brief data — to answer the request you sent and to scope the work. Legal basis: contract / pre-contractual measures (Art. 6(1)(b) GDPR).
- IP + bot check — to keep the form from being abused by spam or scrapers. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
- Analytics + error tracking — to know which pages people read and to fix bugs. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). We use a cookieless, privacy-friendly analytics tool specifically so this is proportionate.
Who else sees the data (sub-processors)
We rely on a short list of vendors. Each has their own privacy policy. None receive more than what's listed below.
| Vendor | What they see | Purpose |
|---|---|---|
| Resend | Your email + the project brief content | Sends the report email |
| Cloudflare Turnstile | Your IP + a browser fingerprint for the challenge | Bot check on the project brief form |
| Sentry | Error context (URL, status, stack). PII auto-attachment is disabled. | Error tracking |
| Umami Cloud | Aggregate page metadata (URL, referrer, browser, OS, country). No cookies, no user ID. | Visit analytics |
| Cal.com | Only if you click the “Book a call” link — they handle scheduling on their site. | Booking |
| VPS hosting | Your IP at the network edge, in nginx access logs | Serving the site |
We don't sell or rent data. We don't share it with advertising networks. We don't have advertising partners.
How long we keep it
- Application logs: emails and the full brief payload are redacted at the application layer before logs hit disk, so the long-lived log files never contain PII. Raw access logs (with IP) rotate within ~14 days on the VPS.
- Email records (Resend): retained per their policy — typically around 30 days for the delivered message body.
- Error events (Sentry): ~90 days on the free tier. Session replays are recorded only for sessions that hit an error (50%), and don't include any keystrokes or text input.
- Analytics (Umami Cloud): ~1 year of aggregate visit metrics. Never tied to a person.
- Your inbox copy of the report: as long as your own email retention keeps it. Outside our control.
If you'd like us to delete what we have sooner, email services@coresmith.dev. We'll confirm within a few days.
Your rights
Under the GDPR (and similar laws in other jurisdictions), you can ask us to:
- Tell you what we have on you (Art. 15)
- Correct it if it's wrong (Art. 16)
- Delete it (Art. 17)
- Provide a copy in a portable format (Art. 20)
- Object to the processing or restrict it (Art. 18, 21)
Send any of these requests to services@coresmith.dev. We'll respond within 30 days. If you're in the EU/EEA and unhappy with our response, you can complain to your local data-protection authority.
International transfers
Our server is hosted in Europe. Our sub-processors operate in Europe and the United States. Where data crosses the EU/EEA border (Resend, Sentry, Cloudflare), the transfer is covered by their Standard Contractual Clauses or equivalent transfer mechanism — those are listed in each vendor's data-processing addendum.
Children
The site is aimed at businesses. We don't knowingly collect any data from anyone under 16. If you believe a minor has submitted information here, email us and we'll delete it.
Changes to this policy
If we make material changes — a new sub-processor, a new type of data, a change in retention — we'll update the Last updated date at the top of this page and post a banner on the site for at least 14 days. Editorial changes (typos, clarifications) don't trigger a notice.
Contact
For anything related to your data — questions, requests, or complaints — email services@coresmith.dev. One human reads that inbox.