Privacy
This policy covers trussphp.com, the documentation site for Laravel Truss.
It does not cover the Laravel Truss package itself. Truss runs inside your own application, reads only your database structure, and sends nothing anywhere. See the Authorization guide for how access to it is controlled.
Last updated: 12 August 2026.
Who is responsible
This site is maintained by Alberto Arena, who is the data controller for it.
For anything in this policy, including a request to exercise the rights below, the contact address is hello@albertoarena.it.
What this site collects
Analytics, in aggregate and without cookies. The site uses Cloudflare Web Analytics, which is privacy-first by design: it does not use cookies, does not store any identifier in your browser, and does not build a profile of you or follow you across sites.
It records the page visited, the referring page, approximate country, browser and operating system, screen size, and page performance timings. This is used for one thing: knowing which documentation is actually read, so it can be improved.
Google Analytics, only if you accept it. Nothing belonging to Google is loaded until you press Accept. Not the script, not a cookieless ping, nothing. If you decline, or simply ignore the banner, no request is ever made to Google and no cookie is set.
This is stricter than the usual arrangement. Most sites load the Google tag immediately in a “denied” mode that still contacts Google with your IP address before you have agreed to anything. This site does not do that, which is why the sentence above can be written without a caveat.
If you do accept, Google Analytics records the pages you visit, the referring page, approximate location, device and browser, and clicks on links leading away from this site (for example to GitHub). It is configured with every advertising feature switched off: no ad personalisation, no ad storage, no Google Signals, no cross-site profiling. Data is retained for 14 months. Google acts as a processor and its own privacy policy applies.
Server logs. Like any web server, the host records standard access log entries, which include IP addresses, for security and troubleshooting. These are handled by the hosting provider under its own retention schedule and are not used for analytics.
Nothing else. There is no advertising, no profiling, no tracking pixels, no social media widgets, no comment system, and no account to create. Nothing you do here is sold or shared for marketing.
Cookies and browser storage
Unless you accept analytics, this site sets no cookies at all.
It uses your browser’s local storage for three things. Local storage is not a cookie: it is never sent to the server, and it never leaves your device.
| Key | Purpose |
|---|---|
starlight-theme | Remembers whether you chose the light or dark theme |
truss-theme | On the live demo and theme builder, remembers the palette you were previewing |
truss-consent | Remembers whether you accepted or declined analytics, so you are not asked again |
Note that declining is remembered here rather than in a cookie, so refusing leaves nothing on your device that any server can read.
If, and only if, you accept analytics, Google sets its own cookies (_ga and
_ga_<id>) to tell repeat visits apart. Declining means they are never created.
You can clear any of this at any time through your browser’s site data
settings. Clearing truss-consent simply means you will be asked again.
Changing your mind
Use Cookie settings in the site footer. It clears your stored choice and shows the banner again, and the page reloads so that anything previously loaded stops immediately.
The live demo and the theme builder are full-screen pages with no footer, so the control is not on them. Your choice is shared across the whole site, so changing it on any other page applies there too.
Legal basis
For the cookieless, aggregate Cloudflare analytics, the basis is legitimate interest under Article 6(1)(f) GDPR: understanding which pages are useful, using data that does not identify you and is not stored in your browser. No consent is required for it, which is why it runs whatever you choose.
For Google Analytics, the basis is consent under Article 6(1)(a), given by pressing Accept and withdrawable at any time from the footer.
For server logs, the basis is legitimate interest, specifically keeping the site available and secure.
Where your data goes
The site is served from Italy, and the cookieless analytics are processed by Cloudflare.
If you accept Google Analytics, the data it collects is transferred to Google LLC in the United States, which is outside the European Economic Area. That transfer relies on the EU-US Data Privacy Framework, an adequacy decision adopted by the European Commission in July 2023, under which Google LLC is certified. Google also offers the European Commission’s standard contractual clauses as an additional safeguard. Measurement traffic from this site is sent to Google’s European endpoint, and Google Analytics does not store your IP address.
If you decline, no data of yours leaves the site for Google at all, because nothing of theirs is ever loaded.
Third parties
| Who | What for | Where |
|---|---|---|
| Cloudflare | DNS, and serving the site as a reverse proxy, so it handles every request. Also the cookieless web analytics | Privacy policy |
| Analytics, only after you accept. Never contacted otherwise | Privacy policy | |
| The hosting provider | The origin server and its standard access logs | Italy |
The documentation links out to places like GitHub, Packagist, YouTube, Discord and Ko-fi. Those are ordinary links: nothing is requested from them until you click, and once you do, their own privacy policies apply, not this one.
The live demo and the theme builder run entirely in your browser from files served by this site. They embed nothing from anyone else.
The video referenced on In the wild is not embedded either. It is an ordinary link, so nothing is requested from YouTube, and therefore from Google, unless you follow it.
What this site publishes about other people
In the wild quotes people who have written publicly about Laravel Truss. This section is about them rather than about you, because the page would otherwise be the only part of the site making claims nothing here covers.
What appears: a name, a short excerpt of something that person published in public, a link to the original, and the date they published it. Nothing else. No photographs, no job titles, no follower counts, and no measure of how any post performed.
Where it comes from: public posts, public articles and public issue reports, quoted with attribution and linked so the excerpt can be checked against the whole. Quotes are reproduced exactly, including their own punctuation and spelling; they are never edited, tidied or shortened without saying so. Where an excerpt is not in English, the original is shown alongside a translation that is labelled as ours.
Why no permission is asked: quoting a short, attributed passage of something somebody chose to publish, with a link to the source, is ordinary practice. Nothing private is ever used. Material shared in a direct message or a closed channel is not published without explicit agreement.
How to have it removed: write to hello@albertoarena.it and the entry comes down. No reason is needed and nothing is asked in return.
Your rights
Under GDPR you have the right to access the personal data held about you, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable form, and to complain to a supervisory authority.
In practice there is very little to exercise these against here: the analytics described above are aggregate and do not identify you, so there is normally no personal data attached to you to retrieve or delete. Server logs are the exception. Write to hello@albertoarena.it and any request will be answered.
Changes
If this site starts collecting anything beyond what is described above, this page will be updated before that happens, not afterwards, and the date at the top will change.