Skip to main content
Ahmed Salama

Privacy

What this site collects

Short version: almost nothing, and nothing that identifies you unless you choose to write to me.

No cookies, no trackers

This site sets no cookies for visitors and loads nothing from a third party. There is no advertising network, no analytics script, no embedded video, no web font fetched from someone else’s server. That is why there is no cookie banner: there is nothing to ask you to consent to.

What is measured

Requests to the site are counted on the server. For each one the site records the page path, the host of the referring site if there was one, the country derived from the network edge, and a coarse device type.

Your IP address is never stored. It is combined with your browser string, a secret value and the current date, and passed through a one-way hash. Because the date is part of the input, the result changes at midnight UTC, so visits on different days cannot be linked together. It is a way of counting sessions, not a way of recognising a person.

The admin view labels these requests, not visitors, because a rotating hash cannot honestly claim to count people.

These records are deleted after 90 days.

If you use the contact form

The form asks for your name, your email address, an optional subject and your message. All four are stored so that I can read and answer you. Alongside them the site stores the same hashed session value described above, your browser string and the host you arrived from, which is what makes filtering automated submissions possible.

The legal basis is legitimate interest: you contacted me in order to get a reply, and a reply requires keeping what you wrote. Messages are deleted after 24 months.

The form is never used to add you to a mailing list, and there is no mailing list. Nothing you send is shared with anyone.

Where the data is

In a PostgreSQL database hosted by Neon in Frankfurt, Germany, inside the EU. Nothing is transferred outside the EU. The database is not reachable from the public internet without credentials, and the site’s own pages read from it on the server rather than in your browser.

Errors

Server-side errors are reported to Sentry so that a broken page can be found and fixed. That reporting runs only on the server: no error-tracking code runs in your browser, and no report contains the contents of a contact message.

Removing your data

Email [email protected] and ask, and I will delete your message and confirm that I have. You can also ask for a copy of anything held about you. There is no form and no process to go through; it is one person reading email.

Analytics records cannot be traced back to an individual by design, so there is nothing there to find or remove on request.

Changes

If what the site does changes, this page changes first. It describes the current behaviour of the code, not an intention.

Back to contact