Privacy Policy
Last updated: 27 September 2026
cntr.ppj.lt is a free visitor counter for websites. This policy explains what data the service handles, why, and for how long. In short: no ads, no trackers, no IP addresses stored, and cookies only when you are logged in.
1. Who is responsible
The service is run by a private individual, Darius Rapalis (Lithuania), who is the data controller. Contact: info@rdarius.lt.
2. Visitors of websites that use a cntr counter
When you open a web page with a cntr counter, your browser loads the counter image from cntr.ppj.lt. Like any web request, this sends your IP address and browser details (the "user agent") to our server. We use them only to count visits:
- We calculate a one-way code (a keyed HMAC-SHA256 hash) from your IP address, your user agent and the counter's number, using a random key that changes every day. Only this code is kept, and only in the server's memory (never written to disk), to recognise a repeat visit on the same day, so it's counted as one unique visitor.
- Your IP address and user agent are not stored. The browser details also tell us whether the visit is from a mobile device; only the resulting number is counted.
- The codes and the daily key are deleted once that date is over in every time zone, at most about 36 hours later. Without the key, the codes can't be linked to you or to your visits on other days or sites.
- What we keep are totals only: views and unique visitors per counter and day, split into mobile and desktop.
- The counter sets no cookies, stores nothing in your browser and builds no profiles.
Legal basis: our legitimate interest, and that of the website owner, in counting a website's visitors (GDPR art. 6(1)(f)). The owner of the website decided to put the counter there and is responsible for telling their visitors about it.
3. Visitors of cntr.ppj.lt
This website uses no analytics, advertising or third-party services: all scripts, styles and images come from our own server. Your IP address is used only to deliver the pages; our web server and proxy keep no access logs, and error logs contain no IP addresses. Your browser's language setting is used to show the site in Lithuanian or English, and is not stored.
4. Registered users
When you register and use the service, we store:
- your username and your password as a one-way hash (bcrypt; we can't see your password);
- the date you last used your account;
- your counters: name, website address, category, time zone, appearance and whether it's hidden from the public list, plus their statistics (totals as described above);
- if the account is suspended for breaking the Terms of Service: when, and the reason.
We don't ask for your email address or real name. Legal basis: providing the service you signed up for (GDPR art. 6(1)(b)).
Counter names, website addresses and statistics are public: they appear in the website list and on each counter's statistics page, unless you tick "Don't show in the public list" for that counter.
5. Cookies
Only one cookie, PHPSESSID, and only when you log in: it keeps you logged in. It
is deleted when you log out or close your browser. It's strictly necessary for logging in, so
it needs no consent. Visitors who aren't logged in, and visitors of websites with a counter,
get no cookies at all.
6. Who else gets the data
The site runs on a server rented from OVHcloud in the European Union, which processes the data only on our behalf as a hosting provider. Copies of the backups are stored with Backblaze (B2 Cloud Storage, data center in the European Union); they are encrypted on our server before upload, so Backblaze can't read them. We don't sell or share data with anyone else, except where the law requires it (e.g. a court order). Data is not stored outside the European Economic Area.
7. How long data is kept
| Unique-visitor codes and daily keys | until the date is over in every time zone (at most about 36 hours) |
| Account and counters | until you delete them; accounts unused for 2 years (no login, and no hits on their counters) are deleted automatically |
| Counter statistics | until the counter or account is deleted |
| Login session | until you log out or close the browser; the data on the server is removed after a period of inactivity |
| Backups (on the server, and an encrypted copy with Backblaze) | 14 days |
8. Security
Connections are encrypted (HTTPS), passwords are stored only as bcrypt hashes, the database is not reachable from the internet, and the site runs in an isolated, read-only container.
9. Your rights
You have the right to access your data, to have it corrected or deleted, to restrict or object to its processing and to receive it in a portable format. You can change your password and delete your account with all its counters and statistics yourself, on the Account page. For anything else, write to info@rdarius.lt; we reply within one month.
Visitors of websites with a counter: we can't tell which data is yours (see section 2), and nothing that could identify you is kept for more than about 36 hours.
You may also complain to the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), L. Sapiegos g. 17, 10312 Vilnius, vdai.lrv.lt, or to the data protection authority of your own country.
10. Children
You must be at least 14 years old to register.
11. Changes
If this policy changes, the date at the top is updated. Significant changes are announced on the website before they take effect.
See also: Terms of Service.