Skip to content
archeus

Legal

Privacy policy

These websites collect nothing from you. There is no form, no account, no newsletter and no analytics. What follows is mostly about the one thing that does happen anyway — a web server writing down that a request arrived.

Effective · Babar Muhammad Anas, Italy · babarh174@gmail.com

Who is responsible

Babar Muhammad Anas, an individual established in Italy, operates https://claudectl.space and https://docs.claudectl.space and is the data controller for them.

There is no company behind this, no marketing department and no data team. It is one person publishing a free, MIT-licensed tool.

What the sites collect: nothing

Not "nothing much" — nothing. This is a static site and it has nowhere to put anything you typed.

  • No form, input field, contact form, newsletter, waitlist or comment box exists on either site.
  • No account, no login, no profile.
  • No analytics, no tag manager, no pixel, no session recorder, no A/B tool, no error reporter.
  • No advertising, no profiling, no automated decision-making, and nothing is sold or shared with a data broker.
  • The two "copy" buttons run entirely in your browser and send nothing anywhere.

The pages are built ahead of time and served as files. Fonts come from your own operating system, and every image is served from the same domain as the page, so simply reading the site contacts nobody else.

What the hosts log

A request has to reach a server, and a server writes down that it happened. This is the only personal data processed in connection with these sites.

https://claudectl.space is served by Vercel. https://docs.claudectl.space is served by Vercel and by GitHub Pages from the same build. Like any web host, they record request data — typically the IP address, the user agent your browser sends, the page requested and the time — to deliver the page, keep the service available and defend it against abuse.

That processing rests on legitimate interests under Article 6(1)(f) GDPR: a website cannot be delivered or protected without it. The logs are the hosts’, not this project’s — they are kept and deleted on the hosts’ own schedules, and are not used here to build any profile of a visitor. Because those providers operate globally, serving a page can involve a transfer outside the EEA under the safeguards described in their notices.

Cookies

There are none, which is why there is no consent banner.

Neither site sets a cookie or writes anything to your device — no cookie, no local storage, no session storage, no database in the browser. The cookie policy says so at more length, and says what would have to change for that to stop being true.

Donations

If you choose to support the project, you do that on Ko-fi, and the payment is taken there rather than here.

The Support link is an ordinary hyperlink. There is no Ko-fi widget, button script or iframe on these sites, so nothing about Ko-fi loads or runs until you click through. Once you do, you are on Ko-fi’s website and their privacy policy and terms govern what happens there. Your card details go to their payment provider and never reach this project.

What a recipient can see about a supporter is decided by Ko-fi, not here. Read their notice for the current answer rather than taking a description of it on trust.

Donations are voluntary. They buy nothing: there is no tier, no perk, no member role, no private channel, no early access and no name in a credits file, and nothing about the software or the support you receive changes because you did or did not give.

Where this project is published, and what that costs you

The sites load nothing from anyone else. The README does, and it is worth being explicit about it, because most people meet this project on GitHub or PyPI rather than here.

  • The README’s status badges are images fetched from img.shields.io, and its screenshots are fetched from raw.githubusercontent.com. Whenever a page renders that README — on GitHub, on PyPI, or in another tool — your browser requests those images, and that request carries your IP address and user agent to those third parties.
  • Following any outbound link — GitHub, PyPI, npm, RubyGems, Ko-fi, the documentation of another project — takes you to somebody else’s site, under their policies.
  • The software itself is separate from these websites: it runs on your machine, and what it does with your data is described in the manual, not here.

Your rights

Under the GDPR you can ask for access to your personal data, and for it to be corrected, erased or restricted; you can object to processing based on legitimate interests; and you can ask for a copy in a portable form.

In practice there is very little to ask about, because this project holds nothing: no list, no database, no mailing list, no visitor record. Requests about the hosts’ own server logs are best made to them, and the notices linked above say how. Anything else, write to babarh174@gmail.com and you will get an answer.

If you are not satisfied you can complain to a supervisory authority — in Italy that is the Garante per la protezione dei dati personali, and you may also complain to the authority where you live or work.

Changes to this policy

This policy is effective from 16 September 2026. If the sites ever start collecting something — an analytics script, a form, a Ko-fi widget — this page changes before that ships, and its effective date changes with it. The history of every change is public in the repository.

This is a plain description of how these sites work, not legal advice.