This policy explains how personal data is handled on abd3lraouf.dev (the “site”). It is written to be read, not to be survived, and it describes what the software actually does rather than what a template says it might.
1. Who is responsible
The controller of any personal data described here is Abdelraouf Sabri, an individual trading as abd3lraouf studios in Egypt.
There is no published email address anywhere on this site, deliberately — a plain-text address on every page is the easiest thing on a website to harvest. The contact form is the way to reach the studio, including for every request described in section 9. It is answered by the person who does the work.
2. What the site collects on its own: nothing
Simply reading this site stores nothing about you and sends nothing about you anywhere. Specifically, and verifiably:
- No cookies. The site sets none at all, which is why there is no cookie banner. There is nothing to consent to.
- No analytics. There is no Google Analytics, Plausible, PostHog, Fathom, Umami or any other measurement script. Page views are not counted.
- No trackers, pixels or fingerprinting, and no advertising of any kind.
- No browser storage. Nothing is written to
localStorage,sessionStorageor IndexedDB. - No third-party fonts or CDNs. Every font, image, script and 3D asset is served from this domain. The site’s Content Security Policy forbids off-origin scripts and connections, so a third-party request cannot be added by accident.
Your browser also sends a “Do Not Track” or Global Privacy Control signal to some sites. There is nothing here for it to switch off.
3. Hosting and server logs
The site is hosted on Cloudflare Pages. Like every web server, Cloudflare’s network processes the technical details of each request — your IP address, the page requested, your browser’s user-agent string and the referring page — in order to deliver the page and to protect the service from attack and abuse. This is Cloudflare’s own infrastructure logging, retained under Cloudflare’s terms and privacy policy rather than the studio’s, and it is not combined with anything else, not used to build a profile, and not used to identify you.
Legal basis: legitimate interests (Article 6(1)(f) GDPR) in serving the site securely and keeping it available.
4. The contact form
This is the only part of the site that stores personal data. When you submit the form, the following is written to a database (Cloudflare D1) operated for the studio:
- Your name, email address and message — as you typed them.
- A salted SHA-256 hash of your IP address — never the address itself. The hash exists only to be compared against other hashes so that the form can be rate-limited; the plaintext address is not stored because it would buy nothing and is personal data the studio has no reason to hold.
- A two-letter country code, derived by Cloudflare from your connection, and the first 500 characters of your user-agent string — both used to triage messages and to recognise abuse.
- The time of submission.
The form is protected by limits on how many messages can be sent in a minute, an hour and a day, and identical messages sent twice within ten minutes are discarded. There is a hidden field that real people never fill in; if it is filled in, the message is dropped.
Legal basis: taking steps at your request before entering into a contract (Article 6(1)(b) GDPR) where you are enquiring about work, and legitimate interests (Article 6(1)(f)) in replying to correspondence and in preventing abuse of the form.
Please do not send confidential or sensitive information through the form. It is an ordinary enquiry channel, not a secure one, and no confidentiality obligation arises from your using it — see section 8 of the terms.
5. Who else sees it
The studio does not sell personal data, does not share it for advertising, and does not disclose it to anyone except the service providers below, each of which processes it only to provide its service:
- Cloudflare, Inc. — hosting, the content delivery network, and the database the messages are stored in.
- Resend — when email notification is enabled, a copy of your name, email address and message is emailed to the studio so it can be read and answered. The IP hash, country and user-agent are not included.
- Cloudflare Turnstile — if the form’s anti-bot check is active, your IP address is sent to Cloudflare to verify that check. Turnstile is not enabled on the form at the time of this review; this clause is here so that switching it on does not make the policy wrong.
Personal data may also be disclosed where the law requires it, or to establish or defend a legal claim.
6. Downloads and version numbers
No download URL is stored in this site. When you click a download button, the site asks GitHub where the current release file is and redirects your browser to it. That redirect means your browser then connects to GitHub directly, so GitHub — not the studio — receives your IP address and user-agent for the download itself, under GitHub’s privacy policy. The studio logs nothing about downloads and cannot tell who downloaded what.
Product pages also ask this site for the current version number so the page can correct itself. That request goes to this domain only and carries no identifier.
7. Offline support
The site installs a service worker so that pages you have already visited keep working without a connection. It stores copies of those pages in your own browser’s cache, on your own device. Nothing about what you cached is transmitted anywhere, and clearing your browser’s site data removes it.
8. How long it is kept
Contact messages and the request details stored with them are kept for 24 months from the date they are sent, and are then deleted. Where a message leads to an ongoing engagement, the correspondence may be kept for as long as that relationship lasts and for any period afterwards that tax or limitation law requires.
You can ask for a message to be deleted sooner at any time — see below.
9. Your rights
If you are in the European Economic Area or the United Kingdom, the GDPR gives you the right to access the personal data held about you, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable format. Where processing rests on legitimate interests, you may object to it at any time.
If you are a California resident, the CCPA/CPRA gives you the right to know what personal information is collected and disclosed, to have it deleted, to have it corrected, and not to be discriminated against for exercising those rights. The studio does not sell or share personal information, in any sense those words carry under that Act, and has no “Do Not Sell or Share” link because there is nothing to opt out of.
To exercise any of these rights, use the contact form. Requests are answered within one month. You may be asked for enough information to be sure the request is genuinely yours — usually just the email address the message was sent from.
You also have the right to complain to a data protection authority, normally the one where you live or work.
10. Where the data is
The studio operates from Egypt, and the service providers named in section 5 are based in the United States and run globally distributed networks. Personal data may therefore be processed outside the country you are in, including outside the EEA and UK. Where that involves a transfer from the EEA or UK, it takes place under the European Commission’s Standard Contractual Clauses (with the UK Addendum where applicable), which those providers incorporate into their terms.
11. The apps are separate
This policy covers this website. It does not describe what the studio’s applications do once they are installed on your own machine, because each one is different and each one already says so on its own page.
Where an app processes data, the privacy section of its product page states what leaves the device and what does not, and the app itself carries the controls. Start from the app list. Four of the seven are open source under the MIT licence, so their behaviour can also be read directly from the source rather than taken on trust.
Apps obtained from the Mac App Store are also subject to Apple’s own privacy terms for the store transaction, and support given through a funding platform named on the support page is subject to that platform’s privacy policy. The studio never receives your payment details from any of them.
12. Children
The site is not directed at children and the studio does not knowingly collect personal data from anyone under 16. If you believe a child has sent a message through the form, say so through the form and it will be deleted.
13. Changes to this policy
This policy is revised when the site’s behaviour changes, and the date at the top is the date of the last review. Material changes will be reflected there; the page has no mailing list, so the date is the honest signal.