Privacy Policy
We set no cookies of our own. We use cookieless analytics, keep scrubbed error reports, and relay contact messages without saving them in our database.
Effective 25 August 2026.
Who we are
Numen Technologies Limited operates numen.ie and is the data controller for the processing described here.
Numen Technologies Limited
Work Hub, 77 Camden Street
Dublin D02XE80
Ireland
Registered in Ireland with the Companies Registration Office, company number 677823.
For any privacy question or request, write to us at [email protected].
What this policy covers
This policy covers the numen.ie website and nothing else. It is our company site: a homepage, a contact form, and links to the apps we make.
Each app has its own site and its own privacy policy, because each one does different things with different data. If you are looking for what an app does, read its policy:
This policy also does not cover other companies. When you follow a link from this site to somewhere else, that site runs under its own privacy policy.
The contact form
If you write to us through the form on the contact page, you send us your name, your email address, and your message. There is nothing else on the form.
Our API does not save form submissions to its database. The message is relayed to our mailbox by Mailgun, our email provider, and it then lives in our mail account for as long as we need it to answer you.
The form is protected by Cloudflare Turnstile, so Cloudflare receives the connection data it needs to tell a person from a bot, and by a per-IP rate limit.
The Discord badge
The contact page shows how many people are currently online in our Discord community. Your browser asks our own API for that number and gets a number back. Nothing about you is sent to Discord, and the badge works the same whether or not you have a Discord account.
If you click through and join the community, that happens on Discord's servers under Discord's own privacy policy, not ours.
Analytics
We measure how the site is used with Umami, which we host ourselves on our own infrastructure and serve from our own domain. There is no Google Analytics, no tag manager, and no advertising pixel anywhere on this site.
Umami sets no cookies and builds no cross-site profile. It records page paths, the query string an inbound link carries (including campaign tags and advertising click IDs), referrers, your browser, operating system, device type, screen size, browser language, and an approximate location down to city level, derived from your IP address. It also records named events such as a link click.
Your IP address is processed transiently to derive that approximate location and the daily-salted hash that groups a visit. It is not stored.
The legal basis is our legitimate interest in understanding how our own site performs. We weighed that against your interests and concluded it is proportionate: the measurement is first-party, cookieless, content-free, confined to this one site, and never shared with an advertising network.
Error reports
When something on the site breaks, your browser can send an error report to Glitchtip, which we also host ourselves. The report describes the failure so we can fix it.
Before a browser error report is stored, query strings are stripped from URLs and identifiers are removed. The legal basis is our legitimate interest in keeping the site working.
The same Glitchtip instance also receives performance measurements: ordinary page loads and requests are timed and sent there even when nothing breaks, scrubbed the same way. We use those measurements only to keep the site fast and working, on the same legal basis and with the same handling as the error reports.
Cookies and browser storage
We set no cookies of our own. Not one, not for analytics, not for preferences, not for anything. That is also why you have never seen a consent banner here: there is nothing to consent to.
Our CDN, Cloudflare, may set a short-lived cf_clearancecookie if it has to challenge suspicious traffic. That is a security measure to protect the site, not tracking, and it is listed in the table below with everything else.
The table below is the complete list of what keeps state in your browser on this site. None of it tells us who you are:
| Name | Type | Purpose | Duration |
|---|---|---|---|
| theme | Local storage, first-party | Remembers whether you chose the light or the dark theme. | Until you clear it |
| Cloudflare Turnstile | Third-party security challenge | Tells a person from a bot on the contact form. Turnstile keeps its own short-lived state in your browser while the check runs. | Per challenge, set by Cloudflare |
| cf_clearance | Cookie, set by Cloudflare | Appears only if Cloudflare has to challenge suspicious traffic, so that a visitor who passes the challenge is not asked again. It protects the site; it does not track you. On an ordinary visit it is never set. | Short-lived, set by Cloudflare |
We do not embed third-party video or social widgets on this site. If we ever do, the embed will not load until you click it.
Why we process data, and on what legal basis
| What we do | Data involved | Legal basis (GDPR) |
|---|---|---|
| Answer a message you sent us | Name, email address, message | Article 6(1)(b) and Article 6(1)(f), answering your request |
| Block bots and keep the contact form available | Connection data processed by Cloudflare Turnstile, and a per-IP rate limit | Article 6(1)(f), our legitimate interest in a form that survives abuse |
| Measure how the site is used | Cookieless, content-free page and event data | Article 6(1)(f), our legitimate interest in improving our own site |
| Diagnose errors | Error reports and performance measurements with query strings stripped from URLs and identifiers removed | Article 6(1)(f), our legitimate interest in a working site |
| Meet legal obligations, including accounting and tax | Records our accountants and the law require | Article 6(1)(c), legal obligation |
Who else is involved
We keep as much as possible in our own hands. Our analytics, our error tracking, and our databases are all operated by us, not bought as a service, so they are not third parties receiving your data.
These companies do process data on our behalf:
- DigitalOcean - hosting for our servers.
- Cloudflare - DNS, TLS, content delivery, Turnstile, and encrypted backup storage.
- Mailgun - delivery of messages sent through the contact form.
- Tailscale - the private network our machines talk to each other over. It carries traffic; it does not read it.
We do not sell personal data, we do not share it for cross-context behavioral advertising, and we do not use it to train AI models. We disclose data to a public authority only where the law requires it.
How long we keep things
Short, because there is little to keep:
- Contact form submissions: never written to a database. The message ends up in our mailbox and stays there for as long as we need it to deal with your request.
- Analytics: kept indefinitely as event records. Umami groups a visit using a hash that is re-salted every day, so there is no identifier that follows you from one day to the next, and the IP address the hash is derived from is not stored. Where an inbound link carried an advertising click ID, that ID stays part of the recorded URL.
- Error reports and performance measurements: kept while they are useful for fixing the fault or keeping the site fast, with query strings stripped from URLs and identifiers removed before they are stored.
Our servers are backed up nightly to encrypted storage at Cloudflare R2. Those backups can contain the analytics and the scrubbed error and performance records described above. The API does not save contact submissions in its database, but messages remain in our mailbox and follow that mail system's retention and backup process.
International transfers
We are an Irish company. The cloud servers that run this site and its API are hosted in European Union datacenters, in Amsterdam. Some of the providers listed above are established in the United States and may process data there or in other countries.
The safeguard for each transfer depends on that provider's current arrangement. We are verifying the applicable Chapter V mechanism with legal counsel and will update this policy after that review. Contact us if you need the current details for a particular provider.
Security
Traffic to the site is encrypted in transit. Our machines talk to each other over a private network. Backups are encrypted. Access to production systems is limited to the people who need it.
No system is perfect, and we will not pretend otherwise. If we ever suffer a breach that puts your rights at risk, we will notify the Irish Data Protection Commission and, where the law requires it, you.
Children
This is a company website. It is not directed at children, and we do not knowingly collect personal data from children. If you think a child has sent us personal data through the contact form, write to [email protected] and we will delete it.
Your rights
Which rights you have depends on where you live. To exercise any of them, write to [email protected]. We answer within the time the applicable law allows, and there is no charge. We may ask you for enough information to be sure the request is really yours, and no more.
One honest limitation: we hold little information about you. We may hold support messages, cookieless analytics records, and scrubbed website error reports, but the contact API does not save submissions in its database. If we cannot find data that identifies you, we will tell you so rather than invent a match.
European Union and European Economic Area (GDPR)
You have the right to access your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to receive your data in a portable format, and to withdraw consent at any time where we rely on consent. Withdrawing consent does not affect processing that already happened.
Where we rely on legitimate interests, you can object on grounds relating to your particular situation, and we will stop unless we have compelling grounds that override yours.
Our lead supervisory authority is the Irish Data Protection Commission. You can complain to it, or to the authority in the country where you live. The list of national authorities is published by the European Data Protection Board.
United Kingdom (UK GDPR and Data Protection Act 2018)
You have the same set of rights described above. You can complain to the Information Commissioner's Office at ico.org.uk.
United States state privacy rights
If you live in California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with a comprehensive privacy law, you may have the right to know what personal information we collect, to get a copy of it, to have it deleted, to correct it, and not to be treated worse for exercising those rights. Not every right exists in every state.
We do not sell personal information and we do not share it for cross-context behavioral advertising, in any state, for any price. Because there is no sale or sharing to stop, a Global Privacy Control signal has nothing here to opt you out of. We do not use sensitive personal information to infer characteristics about you.
To exercise a state right, write to [email protected]. If we cannot verify a request, we will say so and explain why.
Canada (PIPEDA)
You can ask what personal information we hold about you, how we use it, and who we disclose it to, and you can ask us to correct it. You can complain to the Office of the Privacy Commissioner of Canada.
If you are in Quebec, Law 25 gives you further rights, including rights around automated decisions and data portability. We do not make automated decisions that produce legal effects about you.
Brazil (LGPD)
You have the right to confirmation of processing, access, correction, anonymization or deletion of unnecessary data, portability, information about with whom we share data, and revocation of consent. You can complain to the Autoridade Nacional de Proteção de Dados.
India (Digital Personal Data Protection Act 2023)
You have the right to access a summary of your personal data and our processing, to correction and erasure, to nominate someone to exercise your rights if you die or become incapacitated, and to a grievance route. Send grievances to [email protected], which is our contact point for this purpose.
Changes to this policy
We update this policy when what we do changes. The effective date at the top always tells you which version you are reading. We keep a full revision history of this page, and we will share the relevant changes on request.
Contact us
Privacy questions, requests, and complaints all go to the same address: [email protected]
The terms that govern your use of this site are in our Terms of Use.