Skip to content
Rahman FakhruDiscuss a project
07

PRIVACY POLICY.

How rahmanef.com and personal projects that link to this policy handle data, including Google integrations.

Updated 26 September 2026

Scope

This policy applies to rahmanef.com and to personal projects or applications operated by Rahman Fakhru when that project links to this policy or identifies it as its privacy notice. Collaborative projects, third-party services, or sites that do not link to this policy are not automatically covered. Features and data handling can differ by project, and an in-product notice may provide additional details.

Data you provide

Contact forms may request your name, email, topic, and optional context. If you submit a booking request, the preferred time, browser time zone, and planned session duration may also be stored so the time can be confirmed correctly. This information is used to respond to your request and operate features you choose. Do not submit passwords, API keys, or sensitive documents through general-purpose forms.

Google integrations and Google user data

Some projects may use Google Sign-In or Google OAuth for features you choose. The data requested depends on the feature and the scopes shown during authorization, such as basic identity information including name/email, or Calendar, Drive, Gmail, or other Google-service data only when the project actually provides a related feature and asks for that permission. Projects should request the narrowest scopes necessary. Google user data is used only to provide, secure, or improve the user-requested feature; it is not sold, used for advertising or retargeting, used for credit or lending decisions, or used to train general-purpose AI/ML models. Human access to Google user data is limited to cases where you affirmatively request support or review, access is necessary for security or abuse investigation, or access is required by law. Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Tokens, storage, and sharing of Google data

When an integration requires continuing access, a project may store OAuth tokens or connection metadata in the project's backend or credential store for as long as needed to run the integration. Google user data is not shared with other parties except infrastructure providers or processors needed to operate the feature you requested, for security purposes, or where required by law. Technical practices can differ between projects, so this policy does not claim a specific encryption method, certification, or security control that has not been verified across all covered projects.

Revoking access and deletion requests

You can disconnect an integration inside the project when that control is available and can revoke an application's access from the third-party connections area of your Google Account. After access is revoked, the project can no longer request new Google data using a token that is no longer valid. You may also contact the email below to request access to, correction of, or deletion of data under a project's control. Your identity and the context of the request may need to be verified.

Retention and security

Data is retained only while reasonably needed to provide the feature you chose, maintain an active account or connection, investigate security or abuse, comply with legal obligations, or resolve a legitimate request. This policy does not promise automatic deletion or a fixed retention deadline that has not been implemented and verified for each project. Reasonable access and security measures are used according to the project's capabilities, but no system can be guaranteed completely secure.

rahmanef.com analytics

Public rahmanef.com pages use first-party analytics without advertising cookies. Data may include the page path without its query, viewport category, referring domain, campaign parameters, CTA clicks, coarse browser and operating-system labels, browser language and local time zone/hour, and a temporary sessionStorage identifier. Approximate country, region, and city are resolved from IP using a DB-IP database running locally on the VPS. Raw IP and raw User-Agent are not stored in the analytics database; IP is processed transiently for location lookup and a rate-limit hash. The site may also load Google Analytics 4 as secondary measurement with analytics/ad storage set to denied and Google Signals/ad personalization disabled, so Google receives cookieless measurement pings rather than Analytics cookies. Brief contents are not sent to Google Analytics. Do Not Track or Global Privacy Control prevents both the first-party beacon and GA4 tag from running.

Language, browser storage, and logs

The homepage may suggest a language using an IP-country lookup performed locally on the VPS without sending the IP to an external geolocation service. A cookie can retain a manual language preference for up to one year. Other features may use browser storage for preferences or sessions you choose. Infrastructure logs are a separate system and may be processed for security, reliability, and troubleshooting.

External services and processors

rahmanef.com runs as a Next.js application on a VPS; forms and analytics may connect to Convex. Other personal projects may use different hosting, database, email, payment, authentication, or API providers. Links to WhatsApp, social platforms, Google, and other external services are subject to their own policies. Processors receive data only as needed to operate the relevant service or as required by law.

Rights, questions, and changes

You may request access to, correction of, or deletion of data under a project's control and ask questions about data use through the contact below. This policy may be updated as features, integrations, or legal requirements change; the update date above identifies the latest published version.

[email protected] · Contact · Terms