Privacy Policy

Last updated: 2026-07-29

This Privacy Policy explains how this website (“the Site”) handles information when you visit rcruz.dev. It covers the Site itself; my apps have their own privacy policies, linked from each app’s page.

Information I collect

  • Technical request data. Like any website, visiting the Site sends technical information (your IP address, browser type and version, the page requested, referring page, and access time) to the providers that serve it. This is logged by those providers for security, abuse prevention, and reliability. I do not have access to these logs and do not receive this data.
  • Network error reports. The content delivery network sets a standard Report-To / NEL header, which asks your browser to report failed connections (the URL, error type, and your IP address) back to it. This helps detect delivery problems and is handled entirely by that provider.
  • Messages you send me. If you email me (for example via the Contact page), I receive your email address and whatever you choose to write to me.

The Site runs no analytics, no tracking scripts, and no advertising. Fonts and all other assets are served from rcruz.dev itself rather than from third-party CDNs, so simply loading a page does not contact any outside service. The Site does not ask you to create an account.

Cookies

The Site sets no cookies of its own and uses no tracking or advertising cookies.

The content delivery network in front of the Site may set strictly necessary security cookies (such as __cf_bm, cf_clearance, or _cfuvid) if its bot protection or rate limiting is triggered by a request. These exist only to distinguish automated traffic from real visitors, carry no advertising or cross-site tracking function, and are not used to profile you.

How your information is used

Technical request data is used only to deliver the Site, keep it available, and protect it from abuse, which is my legitimate interest in running a secure, functioning website (Article 6(1)(f) GDPR). Messages you send me are used only to reply to you and to handle whatever you contacted me about (Article 6(1)(b) and (f)).

I never sell your personal data, and I do not use it for profiling, automated decision-making, or marketing.

Service providers

Delivering the Site involves two providers, each acting as a processor or independent controller for the technical data described above:

  • GitHub Pages (GitHub, Inc., a Microsoft company, United States) hosts the Site’s files. See the GitHub Privacy Statement.
  • Cloudflare (Cloudflare, Inc., United States) sits in front of the Site as a content delivery network and security layer. Every request passes through Cloudflare, which terminates the HTTPS connection at its edge. See the Cloudflare Privacy Policy.

Email you send to [email protected] is handled by Apple iCloud+ (for users in the European Economic Area, provided by Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland). See the Apple Privacy Policy.

Beyond these, I don’t share your data with third parties, except where required by law. The Site also links out to external sites, app stores, and app pages; those have their own privacy practices, which I do not control.

International transfers

Both providers are based in the United States, so technical request data is processed outside the European Economic Area. Both are certified under the EU–U.S. Data Privacy Framework and rely on Standard Contractual Clauses for transfers, which are the safeguards recognised under Chapter V of the GDPR.

Email you send me is delivered to an iCloud+ mailbox provided by an Irish Apple entity, so that contractual relationship sits inside the EEA. Apple may still process message data on infrastructure outside the EEA, under the safeguards set out in its own privacy policy.

Data retention

I don’t control the retention of provider logs; GitHub and Cloudflare each apply their own retention periods, described in the policies linked above. GitHub states that it retains GitHub Pages visitor logs for a limited period for security and legal-compliance purposes.

Email correspondence is kept for as long as needed to deal with your enquiry and for any period I’m legally required to keep it, then deleted.

Security

The Site is served exclusively over HTTPS, so traffic between your browser and the Site is encrypted in transit. For technical accuracy: that connection is decrypted at Cloudflare’s edge and re-encrypted onward to GitHub, which means Cloudflare can see request contents in the clear, the standard arrangement for any CDN-fronted site. As the Site is static and asks for no personal data, there is no form submission or account data travelling over that connection.

Your rights

If the GDPR applies to you, you have the right to request access to, correction of, or deletion of any personal data I hold about you (in practice, the contents of an email you sent me). You may also object to or request restriction of processing, and request a copy of your data in a portable format.

Because I have no access to the providers’ server logs and those records aren’t tied to an identity I hold, I can’t retrieve or delete them on your behalf; requests about that data need to go to GitHub or Cloudflare directly.

To exercise any of these rights, contact me. You also have the right to lodge a complaint with a supervisory authority: in Spain, the Agencia Española de Protección de Datos (aepd.es).

Changes to this policy

If this policy changes, the revised version will be posted on this page with an updated date above.

Contact

For any privacy request or question, contact me.

Operator

Ricardo Cruz, Canary Islands, Spain.