Skip to content

Privacy

This policy covers trussphp.com, the documentation site for Laravel Truss.

It does not cover the Laravel Truss package itself. Truss runs inside your own application, reads only your database structure, and sends nothing anywhere. See the Authorization guide for how access to it is controlled.

Last updated: 12 August 2026.

Who is responsible

This site is maintained by Alberto Arena, who is the data controller for it.

For anything in this policy, including a request to exercise the rights below, the contact address is hello@albertoarena.it.

What this site collects

Analytics, in aggregate and without cookies. The site uses Cloudflare Web Analytics, which is privacy-first by design: it does not use cookies, does not store any identifier in your browser, and does not build a profile of you or follow you across sites.

It records the page visited, the referring page, approximate country, browser and operating system, screen size, and page performance timings. This is used for one thing: knowing which documentation is actually read, so it can be improved.

Google Analytics, only if you accept it. Nothing belonging to Google is loaded until you press Accept. Not the script, not a cookieless ping, nothing. If you decline, or simply ignore the banner, no request is ever made to Google and no cookie is set.

This is stricter than the usual arrangement. Most sites load the Google tag immediately in a “denied” mode that still contacts Google with your IP address before you have agreed to anything. This site does not do that, which is why the sentence above can be written without a caveat.

If you do accept, Google Analytics records the pages you visit, the referring page, approximate location, device and browser, and clicks on links leading away from this site (for example to GitHub). It is configured with every advertising feature switched off: no ad personalisation, no ad storage, no Google Signals, no cross-site profiling. Data is retained for 14 months. Google acts as a processor and its own privacy policy applies.

Server logs. Like any web server, the host records standard access log entries, which include IP addresses, for security and troubleshooting. These are handled by the hosting provider under its own retention schedule and are not used for analytics.

Nothing else. There is no advertising, no profiling, no tracking pixels, no social media widgets, no comment system, and no account to create. Nothing you do here is sold or shared for marketing.

Cookies and browser storage

Unless you accept analytics, this site sets no cookies at all.

It uses your browser’s local storage for three things. Local storage is not a cookie: it is never sent to the server, and it never leaves your device.

KeyPurpose
starlight-themeRemembers whether you chose the light or dark theme
truss-themeOn the live demo and theme builder, remembers the palette you were previewing
truss-consentRemembers whether you accepted or declined analytics, so you are not asked again

Note that declining is remembered here rather than in a cookie, so refusing leaves nothing on your device that any server can read.

If, and only if, you accept analytics, Google sets its own cookies (_ga and _ga_<id>) to tell repeat visits apart. Declining means they are never created.

You can clear any of this at any time through your browser’s site data settings. Clearing truss-consent simply means you will be asked again.

Changing your mind

Use Cookie settings in the site footer. It clears your stored choice and shows the banner again, and the page reloads so that anything previously loaded stops immediately.

The live demo and the theme builder are full-screen pages with no footer, so the control is not on them. Your choice is shared across the whole site, so changing it on any other page applies there too.

For the cookieless, aggregate Cloudflare analytics, the basis is legitimate interest under Article 6(1)(f) GDPR: understanding which pages are useful, using data that does not identify you and is not stored in your browser. No consent is required for it, which is why it runs whatever you choose.

For Google Analytics, the basis is consent under Article 6(1)(a), given by pressing Accept and withdrawable at any time from the footer.

For server logs, the basis is legitimate interest, specifically keeping the site available and secure.

Where your data goes

The site is served from Italy, and the cookieless analytics are processed by Cloudflare.

If you accept Google Analytics, the data it collects is transferred to Google LLC in the United States, which is outside the European Economic Area. That transfer relies on the EU-US Data Privacy Framework, an adequacy decision adopted by the European Commission in July 2023, under which Google LLC is certified. Google also offers the European Commission’s standard contractual clauses as an additional safeguard. Measurement traffic from this site is sent to Google’s European endpoint, and Google Analytics does not store your IP address.

If you decline, no data of yours leaves the site for Google at all, because nothing of theirs is ever loaded.

Third parties

WhoWhat forWhere
CloudflareDNS, and serving the site as a reverse proxy, so it handles every request. Also the cookieless web analyticsPrivacy policy
GoogleAnalytics, only after you accept. Never contacted otherwisePrivacy policy
The hosting providerThe origin server and its standard access logsItaly

The documentation links out to places like GitHub, Packagist, YouTube, Discord and Ko-fi. Those are ordinary links: nothing is requested from them until you click, and once you do, their own privacy policies apply, not this one.

The live demo and the theme builder run entirely in your browser from files served by this site. They embed nothing from anyone else.

The video referenced on In the wild is not embedded either. It is an ordinary link, so nothing is requested from YouTube, and therefore from Google, unless you follow it.

What this site publishes about other people

In the wild quotes people who have written publicly about Laravel Truss. This section is about them rather than about you, because the page would otherwise be the only part of the site making claims nothing here covers.

What appears: a name, a short excerpt of something that person published in public, a link to the original, and the date they published it. Nothing else. No photographs, no job titles, no follower counts, and no measure of how any post performed.

Where it comes from: public posts, public articles and public issue reports, quoted with attribution and linked so the excerpt can be checked against the whole. Quotes are reproduced exactly, including their own punctuation and spelling; they are never edited, tidied or shortened without saying so. Where an excerpt is not in English, the original is shown alongside a translation that is labelled as ours.

Why no permission is asked: quoting a short, attributed passage of something somebody chose to publish, with a link to the source, is ordinary practice. Nothing private is ever used. Material shared in a direct message or a closed channel is not published without explicit agreement.

How to have it removed: write to hello@albertoarena.it and the entry comes down. No reason is needed and nothing is asked in return.

Your rights

Under GDPR you have the right to access the personal data held about you, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable form, and to complain to a supervisory authority.

In practice there is very little to exercise these against here: the analytics described above are aggregate and do not identify you, so there is normally no personal data attached to you to retrieve or delete. Server logs are the exception. Write to hello@albertoarena.it and any request will be answered.

Changes

If this site starts collecting anything beyond what is described above, this page will be updated before that happens, not afterwards, and the date at the top will change.