Privacy Policy
How no-do.dev handles data, and the privacy principles shared by TRACEZ and GRIMZ.
Last updated: September 20, 2026
Data controller
The controller of the data collected through this site is Manuel Arturo Sánchez Brito (individual / sole trader; "NO-DO.DEV" is the trade name under which he operates), Tax ID (NIF) 60108106K, with registered address at Calle Ardal, no. 3, 30120 El Palmar (Murcia), Spain. For any privacy matter or to exercise your rights: privacidad@no-do.dev. Full identification details are in the legal notice.
Scope of this policy
This policy covers no-do.dev, this presentation site. TRACEZ and GRIMZ are applications with their own user sessions and publish their own product-specific privacy policy inside each platform; here we describe the data-handling principles both share, and the data handling of this site specifically.
What this site collects
no-do.dev uses Google Analytics (GA4) to measure visits and aggregate site usage — not for advertising or to show you ads on other sites. Analytics only runs if you accept it in the notice shown at the bottom of the page on your first visit; if you reject it or don't answer, no Google script is loaded and no cookie is set. If you accept, analytics cookies are set in your browser and usage data (pages viewed, approximate country, device type) is sent to Google. We don't use advertising tracking cookies or retargeting networks. You can change your choice at any time.
Beyond that, the only things we store directly in your browser are two flags in localStorage: your answer to the analytics notice, and whether you dismissed the suggested-language banner. Neither is ever sent to any server.
When you use the contact form, the data you enter (name, email, profile, message) opens in your own mail client via a mailto: link. It doesn't pass through our servers from that form: sending happens from your mail client to contacto@no-do.dev under your control.
Principles that apply to TRACEZ and GRIMZ
- No data resale to third parties.
- Explicit human confirmation before any active action in GRIMZ.
- Investigation or operation scope explicitly defined by the operator before anything runs.
- Encryption in transit and per-client isolation (multi-tenant architecture).
Legal basis and retention periods
- Analytics (GA4): legal basis = your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Aggregate Google Analytics data is kept according to the GA4 retention setting (up to 14 months), and the consent flags in your browser until you clear them.
- Contact form / demo request: legal basis = pre-contractual steps taken at your request and our legitimate interest in replying (Art. 6(1)(b) and 6(1)(f)). We keep that correspondence for as long as needed to handle your request and, afterwards, for the applicable statutory limitation periods.
Recipients and processors
We do not sell or rent your data. To provide the service we rely on providers acting as processors, under a contract compliant with Article 28 GDPR:
- Cloudflare — edge hosting and infrastructure.
- Stripe — payment processing in the platforms (we do not store card data).
- Google Analytics — aggregate site measurement, only if you accept it.
- In TRACEZ, open-source data providers and language-model providers, as detailed in that product's own policy.
International transfers
Some of these providers may process data outside the European Economic Area, in particular in the United States (for example Google or certain AI providers). Such transfers are covered by an adequacy decision (EU–US Data Privacy Framework) and/or the Standard Contractual Clauses approved by the European Commission, with additional safeguards where appropriate.
Your rights
You may exercise, free of charge, your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw your consent at any time (without retroactive effect), by writing to privacidad@no-do.dev. We may ask you to verify your identity. We will respond within the periods set by the GDPR.
If you believe we have not handled your request properly, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD), C/ Jorge Juan 6, 28001 Madrid — www.aepd.es.
Changes to this policy
We may update this page as the site or products evolve. The last-updated date is shown above.