Privacy Policy

Last updated: 27 July 2026

This site is my personal portfolio. This page explains what it collects, why, and what you can do about it. Short version: a little analytics so I can see what is working, and whatever you type into the contact or resume forms so I can reply.

What I collect

Analytics: which pages you view, and a few specific actions like opening a project, requesting my resume, or clicking through to my LinkedIn or GitHub. Choose Accept all and a random ID is stored in your browser so a repeat visit is not counted as a brand new person. Choose Essential only and it stays session based, with no analytics cookie.

Forms: if you use the contact form or ask for my resume, I receive the name and email you type, and your message. That is all.

Server logs: my host keeps standard technical logs, such as IP address and browser type, for security and reliability.

Who processes it

PostHog, in its EU region, runs the analytics. Resend delivers the resume email. Messages sent through the contact form are logged to a private Google Sheet so I can read and reply to them. Vercel hosts the site, keeps standard server logs, and runs its firewall and BotID bot protection to block automated abuse. Sanity stores the site content, not visitor data. Some pages also load embedded content from providers like YouTube, Vimeo, and LinkedIn, which act as their own processors. I do not sell your data, run ads, or track you across other sites.

Security and bot protection

To keep the contact and resume forms from being flooded by automated scripts, Vercel runs its firewall and an invisible bot check called BotID, powered by Kasada. It looks at technical signals such as your IP address, browser characteristics, and how the page is used to tell a real visitor from a bot. There is no visible CAPTCHA and nothing for you to click. These signals are used only to block abuse, not to profile you or track you across other sites.

Cookies

My own analytics cookie is set only if you choose Accept all. Separately, project pages can embed third-party content, and those providers may set their own cookies when the embed loads. I run no advertising cookies and do no cross site tracking of my own.

Embedded content

Some project pages embed third-party content such as videos or posts from YouTube, Vimeo, Loom, and LinkedIn. When a page with an embed loads, that provider can set its own cookies and receive technical data like your IP address, under its own privacy policy rather than mine. This is separate from the analytics choice above. To limit it, use your browser cookie controls or avoid embed-heavy pages.

Keeping and deleting data

I keep form emails for as long as it takes to have the conversation and follow up. Analytics data follows PostHog's retention. If you want me to delete anything you sent, just ask.

Your choices

You can pick Accept all or Essential only from the banner, and change your mind later by clearing this site's storage. To see or delete data you have sent me, reach out through the contact page. Third-party embed cookies are controlled through your browser settings.

Contact

Questions about this policy can go through the contact page.