Last updated: 22 August 2026
MeasuredRun (“we”, “us”, “the site”) publishes measurement logs from AI tools and workflows that we run ourselves. This page explains what personal data the site handles, why, for how long, and what you can do about it.
We have written this policy to satisfy both the Republic of Korea’s Personal Information Protection Act — under which the operator is a personal information controller — and the EU/UK General Data Protection Regulation, which applies because this site is written for an international readership.
We collect as little as the site can function on. We do not sell personal data, and we do not build advertising profiles ourselves.
1. Who is responsible
- Site: MeasuredRun, https://measuredrun.com
- Operated by: Stig (pen name), sole operator
- Contact for privacy matters: havegoodin7@gmail.com
We are not a company, and there is no team here: one person is accountable for everything on this page, and that person can be reached at the address above. Where the Personal Information Protection Act asks for the name of a privacy officer or of the department that handles privacy work and complaints, we give a designation for that function — “MeasuredRun Privacy” in section 11 — rather than a legal name, because the site is published under a pen name. The designation and the single accountable person are the same thing described two ways; it does not mean there is a separate department behind it.
2. What we collect
2.1 Information you give us deliberately
| What | When | Why |
|---|---|---|
| Your name (or a pen name) and email address | If you leave a comment | To display the comment and, if needed, reply |
| Your email address and message content | If you email us | To answer you |
| Your email address | Only if you subscribe to updates, where such a form exists | To send the updates you asked for |
You are never required to give us any of this in order to read the site.
2.2 Information collected automatically
- Server logs. Our hosting provider records the IP address, the time of the request, the page requested, the referring page, and your browser’s user-agent string. This is standard web-server behaviour, used for security and fault diagnosis.
- Analytics data. Google Analytics 4 is connected to this site and its tag loads on every page. It records how pages are used — pages viewed, approximate location derived from IP, device and browser type, and how you arrived. Google Analytics 4 does not store full IP addresses. Section 4.3 explains the cookies it sets and how to refuse them.
- Advertising data. See section 4.2.
- Security and delivery data. Cloudflare provides DNS for this domain. It is not currently proxying traffic, so it does not receive your connection metadata and does not set cookies here. If we turn proxying on, Cloudflare will process connection metadata (including IP address) to route traffic, cache files and filter abusive requests, and this page will be updated on the same day.
2.3 Information we do not collect
We do not ask for, and have no use for, your postal address, telephone number, date of birth, payment details or government identifiers. There is no account system on this site.
2.4 Sensitive information
We do not collect sensitive personal information as defined in the Korean Personal Information Protection Act or in Article 9 of the GDPR — including data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation. Because we do not collect it, there is no option to make it public or to keep it private. (Article 30(1) item 3-3 of the Personal Information Protection Act requires a privacy policy to state where sensitive information may become public and how you may choose to keep it private. This paragraph is that disclosure.)
2.5 Pseudonymised data
We do not process pseudonymised information, we do not combine pseudonymised data sets, and we do not supply data for statistical, research or archival purposes. (Article 30(1) item 4-2 of the Personal Information Protection Act requires this disclosure on the handling of pseudonymised information.)
3. Why we process it — purposes and legal basis
(Article 30(1) item 1 of the Personal Information Protection Act requires a privacy policy to set out the purposes for which personal data is processed.)
| Purpose | Status | Data used | Legal basis (GDPR) |
|---|---|---|---|
| Displaying and replying to comments | Active | Name, email, comment text, IP | Consent (Art. 6(1)(a)), given when you submit the form |
| Answering emails you send us | Active | Email address, message content | Consent, and our legitimate interest in responding (Art. 6(1)(a) and (f)) |
| Keeping the site available and secure | Active | IP address, request metadata | Legitimate interest in operating the site safely (Art. 6(1)(f)) |
| Understanding which articles are useful | Active | Analytics data | Consent (Art. 6(1)(a)) where consent is required. No consent mechanism is in place yet, so those cookies are currently set without it — see section 4.3 for how to refuse today and what we are doing about it |
| Showing advertising, including personalised advertising | Not in use | Advertising cookies and identifiers | Consent (Art. 6(1)(a)), to be collected through the consent banner before any advertising cookie is set. We have not applied to any advertising programme; this row is here because we intend to |
| Meeting legal obligations | As required | Any of the above, as required | Legal obligation (Art. 6(1)(c)) |
Where consent is the basis, you may withdraw it at any time. Withdrawing consent does not affect processing that already happened lawfully before you withdrew it.
4. Cookies and other automatic collection
A cookie is a small text file placed on your device by a website. This section is also our disclosure under Article 30(1) item 7 of the Personal Information Protection Act, which requires us to explain the installation and operation of devices that collect personal information automatically, and how you can refuse them. If you would rather read the same thing in ordinary language, with a table of what each cookie is for, see our Cookie Notice.
4.1 Cookies this site needs to work
WordPress, which runs this site, sets cookies when you leave a comment so your name and email are remembered, and when an administrator logs in. These rest on our legitimate interest in a working, secure site. Cloudflare is not proxying this site at present and therefore sets no cookie on it; if proxying is turned on it sets one to distinguish legitimate visitors from automated abuse.
4.2 Advertising cookies
We have not applied to the Google AdSense programme; we intend to apply later. No advertising cookies are set on this site at present. This section describes what will happen if advertising is enabled, and this page will be dated again on that day.
- Google, as a third-party vendor, would use cookies to serve ads on this site.
- Google’s use of advertising cookies would enable it and its partners to serve ads to you based on your visit to this site and/or other sites on the internet.
- You may opt out of personalised advertising at https://www.google.com/settings/ads.
- You can read how Google uses information from sites that use its services at https://policies.google.com/technologies/partner-sites.
- Third-party vendors and ad networks other than Google may also serve ads here once advertising begins. You can opt out of many of them at https://www.aboutads.info/choices or, in Europe, at https://www.youronlinechoices.com.
If you are in the European Economic Area, the United Kingdom or Switzerland, we will present a consent message before any personalised advertising cookie is set, using a consent management platform certified by Google, as Google requires of publishers serving personalised advertising to those regions. Your choice will be recorded and you will be able to change it at any time — see section 4.5. No such message is running today, because no advertising cookie is being set.
4.3 Analytics cookies
Google Analytics 4 is connected to this site. It sets cookies to distinguish one visit from another and to measure how the site is used, and it does so on an ordinary visit, as the page loads.
No consent message is running yet, so where consent is required these cookies are being set before it is given. We are putting that mechanism in place. Until it is running, you can refuse analytics immediately: install Google’s opt-out add-on at https://tools.google.com/dlpage/gaoptout, block cookies for this site in your browser, or read in private mode. If you want the analytics data associated with your visits deleted, write to the address in section 1 and we will ask Google to delete it.
4.4 What we never do with cookies
We do not use cookies to identify you by name, and we do not attempt to link analytics or advertising identifiers to any comment or email you have sent us.
4.5 How to refuse or remove cookies
- On this site: no consent banner is running yet. For analytics, that means its cookies are set without asking — use the analytics opt-out in section 4.3, which works today. For advertising, there is nothing to refuse yet because none is running; once it begins, the consent controls in the banner will apply and a persistent control will be available to reopen those settings.
- In your browser: every major browser lets you block or delete cookies, usually under Settings → Privacy. Blocking all cookies may stop comments working; the articles remain readable.
- For advertising specifically: use the opt-out links in section 4.2.
5. Who else receives data
(Article 30(1) item 3 of the Personal Information Protection Act requires this disclosure of personal data provided to third parties.) We do not sell personal data and we do not share it for anyone else’s independent marketing.
5.1 Third parties that receive data through this site
| Party | Status | What it receives | Why | Their policy |
|---|---|---|---|---|
| Google LLC (Analytics 4) | Active | Analytics events, coarse location, device and browser data, from every visit | To measure site usage | https://policies.google.com/privacy |
| Google LLC (AdSense) | Not in use | Nothing today. If advertising starts: advertising cookies and identifiers, IP address, page context | To serve and measure advertising | https://policies.google.com/privacy |
| Google advertising partners | Not in use | Nothing today. If advertising starts: advertising identifiers, where you have consented | To select and measure advertising | Listed inside the consent message, once there is one |
| Cloudflare, Inc. | DNS only | DNS queries for this domain. Connection metadata, including IP address, only if proxying is turned on | Domain name resolution now; content delivery and abuse filtering if proxying is enabled | https://www.cloudflare.com/privacypolicy/ |
| Cafe24 Corp. | Active | Server log data | Web hosting | https://img.cafe24.com/txt/rule/common/cafe24_privacy_20260805.html |
5.2 Processing entrusted to others (처리위탁)
Under Article 30(1) item 4 of the Personal Information Protection Act, which requires a controller to disclose processing it entrusts to others, we disclose that hosting — the storage and transmission of the data described above — is carried out by Cafe24 Corp. on our behalf and on our instructions. Cloudflare, Inc. provides DNS for this domain and processes the DNS queries that reach it; it is not proxying traffic at present, so no visitor connection data is entrusted to it. If proxying is turned on, Cloudflare will also carry out content delivery on our behalf and this section will be updated on the same day. We do not entrust personal data to any other party for processing.
5.3 Disclosure required by law
We will disclose personal data if legally compelled to — for example by a valid order from a court or competent authority. We will not do so voluntarily.
5.4 International transfers
We operate from the Republic of Korea. Google receives analytics data from this site today, through Google Analytics 4, and processes it in the United States and elsewhere. Advertising is not running, so no advertising data reaches Google. Cloudflare provides DNS only and is not proxying this site, so it receives no visitor connection data; it does process the DNS queries for this domain, in the United States and elsewhere. If advertising is enabled, or Cloudflare proxying is turned on, those providers will process further data in the United States and elsewhere. Where personal data of EEA or UK residents is transferred outside those areas, those providers rely on transfer mechanisms approved under the GDPR, including the European Commission’s Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework. Details are in each provider’s privacy policy, linked above.
6. How long we keep it
(Article 30(1) item 2 of the Personal Information Protection Act requires a privacy policy to state the period for which personal data is processed and retained.)
| Data | Status | Retention |
|---|---|---|
| Comments and the details submitted with them | Active | Kept while the article is published, so the discussion stays readable. Deleted on request |
| Emails you send us | Active | Kept for up to two years, then deleted |
| Server logs | Active | Kept for a short operational period by our hosting provider, typically not more than three months |
| Analytics data | Active | Held by Google since Analytics was connected, for the retention period configured on our Analytics property, after which Google deletes the event-level data. Aggregated reports are not affected |
| Advertising data | None held | If advertising starts: held by Google according to Google’s own retention practice |
Where a legal obligation requires a longer period, we keep the data for that period and no longer.
7. How we destroy it
(Article 30(1) item 3-2 of the Personal Information Protection Act requires a privacy policy to state the destruction procedure and method.) When personal data reaches the end of the retention period in section 6, or when the purpose for processing it has been achieved, we destroy it without undue delay. Electronic records are deleted from the live system by a method that makes recovery impossible, and are removed from backups as those backups expire in the ordinary rotation. Where data is held by a processor named in section 5, we instruct that processor to delete it. We do not maintain paper records.
8. Your rights
(Article 30(1) item 5 of the Personal Information Protection Act requires a privacy policy to state the rights of data subjects and their legal representatives, and how those rights are exercised.) You may, at any time:
- Ask what we hold about you and receive a copy (access);
- Have inaccurate data corrected (rectification);
- Have data deleted (erasure);
- Ask us to pause processing while a dispute is resolved (restriction);
- Object to processing that relies on our legitimate interest;
- Receive data you gave us in a portable format (portability);
- Withdraw consent you previously gave, at any time;
- Not be subject to a decision based solely on automated processing producing legal or similarly significant effects. We do not make such decisions.
To exercise any of these, email havegoodin7@gmail.com.
How quickly we answer. Korean law works in two layers here, and we state both because they are not the same duty. The Act itself requires a controller to investigate and act on a correction, deletion or suspension request without undue delay (지체 없이) — Article 36(2) for correction and deletion, Article 37(2) for suspension of processing. The Enforcement Decree then fixes the deadlines that carry a number, and they are of two different kinds:
- Performing access is itself due within 10 days. Article 35(3) of the Act gives you access “within the period prescribed by Presidential Decree”, and Decree Article 41(4) sets that period at 10 days. This is a deadline to let you see the data, not merely to write to you about it.
- Notifying you of an outcome is due within 10 days, separately: the access notice (Article 41(5)), a notice postponing or refusing access (Article 42(2)), the result of a correction or deletion (Article 43(3)), and the result of a suspension of processing (Article 44(2)).
We hold ourselves to all of it: we act without undue delay, we give access within 10 days, and we tell you the outcome within 10 days. Where the GDPR applies instead, we answer within one month. Where a request is complex we will tell you before the deadline, not after it.
We may ask for information sufficient to establish that the request is really yours — that check protects you, not us. A legal representative may exercise these rights on behalf of a data subject. If we refuse a request, we will tell you why and how to challenge that refusal.
9. Children
This site is written for adults working with software tools. It is not directed at children, and we do not knowingly collect personal data from children under 14 (Republic of Korea) or under 16, or the lower age set by an EEA member state. If you believe a child has given us personal data, contact us and we will delete it.
10. How we protect it
Measures proportionate to a small site that deliberately collects very little:
- The site is available over HTTPS, and that is the address we publish and link to everywhere. Plain HTTP is still reachable and is not yet redirected to HTTPS; we are fixing that, and this line will be updated when it is done. We do not use HSTS at present.
- Administrative access uses individual accounts, limited to the smallest number of people who need it. Automated publishing uses revocable application-specific credentials rather than a shared password.
- WordPress installs its own security updates automatically; plugins and the theme are updated by hand, and we do that rather than leaving them to drift.
- A web application firewall filters requests to this site. We have tested what it stops, and what it stops is real, but no filter catches everything.
- We rely on our host’s backup arrangements. We have not independently verified how those backups are taken or how long they are kept, and we would rather say that than imply a guarantee we have not checked.
- We minimise collection in the first place. The most reliable protection for data is not to hold it.
No system is perfectly secure and we will not claim otherwise. If a breach occurs that is likely to result in a risk to your rights, we will notify the competent supervisory authority and, where required, affected individuals, within the deadlines the law sets.
11. Privacy officer
(Article 30(1) item 6 of the Personal Information Protection Act requires a privacy policy to name the privacy officer, or the department handling privacy work and related complaints, together with contact details.)
- Responsible for privacy and complaints: MeasuredRun Privacy, operated by Stig
- Contact: havegoodin7@gmail.com
You can raise any question about this policy at that address, including requests under section 8.
12. If you are not satisfied
Complain to us first if you like. You may also go straight to a regulator.
In the Republic of Korea:
- Personal Information Infringement Report Centre (개인정보 침해신고센터) — dial 118, or https://privacy.kisa.or.kr
- Personal Information Dispute Mediation Committee (개인정보 분쟁조정위원회) — dial 1833-6972, or https://www.kopico.go.kr
- Personal Information Protection Commission (개인정보보호위원회) — https://www.pipc.go.kr
In the European Economic Area or the United Kingdom:
You may lodge a complaint with the supervisory authority where you live or work, or where you believe an infringement occurred. In the UK this is the Information Commissioner’s Office, https://ico.org.uk.
13. Changes to this policy
If we change what we do with personal data, we change this page and update the date at the top. Where a change materially affects your rights we say so prominently rather than relying on you to notice.
We do not backdate this page. If you want to know what it said before, ask us.