Privacy notice
Last updated: 5 October 2026.
This notice covers two things: the sign-up list for notifications about the book SwiftUI From the Inside, and the website aleahim.com. Each numbered section has a fixed number so that translations can follow the same structure.
1. Who is responsible
The person responsible for this sign-up list and this website is Mihaela Mihaljevic, personally. Address: Crna voda 38A, 10000 Zagreb, Croatia. Email: mihaelamj@me.com.
Contact for every request in this notice: mihaelamj@me.com.
2. What the book list stores
When you sign up for the book list, the server stores:
your email address;
the time of your sign-up;
the status of your entry: waiting for confirmation, confirmed, unsubscribed, blocked after a bounce or complaint, or erased;
a confirmation token, which is deleted when you confirm;
an unsubscribe token, created when you confirm;
when you confirm: the time, a form version (swiftui-book-1), and a salted hash of your IP address as proof that you confirmed.
The IP address itself is never stored. It is combined with a secret salt and turned into a one-way hash. The same kind of hash is also held in the server’s memory, never on disk, to limit how often one network can sign up in 15 minutes. That memory is cleared when the server restarts.
The list is used only for this book. It is separate from my other lists.
3. Why, and the legal basis
Purpose: to tell you when the book is available, and later to send mail about this book. Nothing else.
Legal basis: your consent, Article 6(1)(a) GDPR. The sign-up uses a double opt-in. You are on the list only after you click the link in the confirmation email. The IP hash and the time are the record of that consent.
4. Withdrawing consent and deleting your data
Every message I send has an unsubscribe link, and the mail program’s own unsubscribe button works too. One click is enough.
You can write to mihaelamj@me.com at any time to ask for your entry to be deleted.
5. How long data is kept
No automatic deletion exists today. Data stays until I remove it, as follows.
A confirmed entry stays until you unsubscribe or ask for deletion.
Unsubscribing stops all mail to you. The entry stays, so that you are not mailed again by mistake, until you ask for deletion.
A sign-up that is never confirmed is never mailed again after the confirmation email. The confirmation link stops working after 14 days. The address stays stored until I remove it on your request.
When I delete your entry on request, the email address is overwritten with a placeholder and the confirmation token is cleared. The row itself stays, so that counts stay correct. The unsubscribe token, the time and form version of your consent and the IP hash stay in that row.
A hard bounce or a spam complaint is recorded in a separate list of events, with the email address, the event and the time, so that the address is never mailed again. Deleting your entry does not remove that record.
If your sign-up appeared in the overview of unconfirmed sign-ups that I receive by email, the server keeps a record of that listing with your email address and the confirmation token. Deleting your entry does not remove that record.
When I unsubscribe or erase an entry by hand in the admin page, the server logs that action with the email address. Deleting your entry does not remove that log line.
The server records which issue was sent to which entry, and when, but not the address.
I keep a copy of the database every week on my own computer and keep the last eight, so for 8 weeks. A deleted address therefore disappears from these copies within eight weeks. The hosting provider also keeps daily snapshots of the server disk, for 5 days.
I can read the list through a password-protected admin page and a console on the server.
6. Who processes the data for me
| Role | Provider | Detail |
|---|---|---|
| Hosting of the sign-up server and its database | Fly.io | Region Frankfurt (fra) |
| Confirmation email | MailerSend | Used for most addresses |
| Confirmation and book mail for the Apple mailbox domains icloud.com, me.com and mac.com | Resend | Sent from the address newsletter@codeweaver.info |
| Mail about the book after sign-up | Mailjet | Used for most addresses |
No other service receives your email address for the book list.
7. The website
The pages of this website are served as static files from Codeberg Pages (codeberg.org). As for any web server, the host receives your IP address and the page you request when your browser loads a page. Its own privacy policy applies to that.
The four pages about the book list and the operator (this notice, the Impressum, the book page and the confirmation page) count page views with Umami, an analytics tool that I host myself. It reports which page was viewed and technical details of the visit, such as the referring page, browser, operating system and screen size. These pages do not record sessions.
Other pages of aleahim.com also load a session recorder from the same Umami server for a share of visits, and a small script that reports how far you scroll and whether you stay on an article for 30 seconds. To avoid all of it, block scripts from stats.aleahim.com and barcodehq-umami.fly.dev in your browser or content blocker. The site works without them.
The sign-up form on the book page sends only what you type into it, to archive.appleuiinsider.com, which is the server described above.
8. Your rights
You have the right to access your data, to have it corrected, deleted or restricted, to object, to receive it in a portable form, and to withdraw consent at any time without affecting the earlier processing. Write to mihaelamj@me.com.
9. Complaints
You have the right to complain to a data protection supervisory authority of your choice.
10. Changes
When this notice changes, the date at the top changes.