Privacy Policy Β· Ahsan Mahmood
How data is collected, used and protected across this website and the Android app.
Introduction
This policy explains how information is collected, used, disclosed and safeguarded when you visit this website or use the Android app built from it.
If you do not agree with it, please do not use the site or the app. It may change at any time; changes are signalled by the Last updated date at the top of this page and nowhere else β there is no mailing list and you will not be notified individually.
Information collected
Analytics
Three providers run on this site, each answering a different question:
- Google Analytics 4 β anonymous usage: page views, session duration, device type, browser, and location at country or city level.
- Microsoft Clarity β anonymised session recordings: pointer movement, clicks and scrolling, used to find layouts that do not work.
- Amplitude β interaction and funnel data: which features get used and in what order.
Portfolio interaction
- Which projects are opened, and how long they are read
- Category filters and search queries used on the projects page
- Which payment methods are viewed
- Outbound clicks β GitHub, live demos, store listings
- CV and resume downloads
Errors and notifications
- Sentry β JavaScript errors, performance problems and crash reports.
- OneSignal β only if you opt in to notifications: a device push token and a device identifier, held so the updates you asked for can be delivered.
Collected automatically
IP address (anonymised), browser and version, device and operating system, pages visited and time spent, referring site, country or city, screen resolution, and interactions such as clicks and scrolls.
How the data is used
- Service improvement β understanding how the site is actually used.
- Performance β finding and fixing bugs, crashes and slow pages.
- Content β learning which projects and writing are worth keeping.
- Security β detecting abuse.
- Communication β replying to anything you send through a form.
What is not done with it: it is not sold, not used for advertising, not shared with marketers, and not used to track you across other websites.
Free accounts
Free accounts help pay for themselves. We may use content from free accounts to improve and train the features built here β the writing you put into a question, a feature request or a vote comment. This is separate from everything in the paragraph above and does not change it: nothing is sold, nothing goes to advertisers, and nothing is shared with marketers.
Content in a paid plan is not used this way without your explicit consent. You can object at any time by writing to the address at the end of this document and your account is excluded, and moving to a paid plan stops it outright. The same clause is in the Terms & Conditions under plans and payment.
File storage
Files are stored on FilesHub β profile images, project screenshots, CV and resume documents, and portfolio assets.
- Public files are served over a CDN and need no authentication.
- Files are kept for as long as they are referenced by something on the site.
Android app permissions
The app asks for the minimum needed for the features you choose to use, and nothing is collected without an action you started. It does not request camera, location or media-storage permissions.
Picking an image
Attaching an image to a conversation or setting a profile picture opens the standard Android system file picker. No Android permission is required for this, and it only happens when you tap an upload control.
Notifications
On Android 13 and later the app asks for notification permission the first time you enable a notification, never at launch. Declining it leaves every other feature working.
Sharing and third parties
Data reaches the providers named above and no one else. Most of them are processors acting on instruction; Microsoft Clarity is the one that also acts as a controller of the session recordings it holds, which is why it is named separately in the store data-safety declaration.
Data is disclosed outside that set only where the law requires it.
Security
Traffic is encrypted in transit with TLS. Database access is governed by Postgres row-level security β public content is read-only and every write is scoped to the account that owns it. Administrative access is authenticated and limited to the site owner.
No system is perfectly secure, and this one is not claimed to be. What is claimed is that the amount held is small enough that a breach could not expose much.
Your rights
Under the GDPR and comparable laws you may ask for:
- Access β a copy of what is held about you
- Rectification β correction of anything wrong
- Erasure β deletion, covered in its own document
- Restriction β a pause on processing
- Portability β your data in a machine-readable file
- Objection β to processing based on legitimate interest
Requests go to the contact address at the end of this document and are answered within 30 days. There is no charge.
Cookies and tracking
Cookies, local storage and session storage are used for preferences and for the analytics described above. The full breakdown β every cookie, who sets it, and how to switch it off β is in the Cookie Policy.
Children
This site is not directed at children under 13 and no data is knowingly collected from them. If you believe a child has provided information here, write to the address below and it will be removed.
Retention
- Analytics β retained on each providerβs own schedule, typically 14 months.
- Error reports β 90 days.
- Messages you send β until you ask for them to be deleted.
- Uploaded files β while something on the site still references them.
Changes to this policy
Changes are published on this page with a new Last updated date. Material changes to how data is handled will also be summarised at the top of this document rather than buried in a section.
https://aoneahsan.com/privacy-policy