This policy explains how personal data is handled on abd3lraouf.dev (the “site”). It is written to be read, not to be survived, and it describes what the software actually does rather than what a template says it might.
1. Who is responsible
The controller of any personal data described here is abd3lraouf, LLC, a limited liability company registered in the United States.
There is no published email address anywhere on this site, deliberately — a plain-text address on every page is the easiest thing on a website to harvest. The contact form is the way to reach the studio, including for every request described in section 9. It is answered by the person who does the work.
2. What the site measures
Reading this site is measured in two ways, and only these two.
- Google Analytics 4, provided by Google: the pages you view (their address, title and the page you arrived from, without any query string); the actions this site reports — downloading a product or a press file, opening a Pro checkout, sending the contact form or joining the mailing list (that it happened, never what you wrote), a search on the writing index (with anything shaped like an email address removed), switching language, copying a coupon, and a page failing to load; and the approximate location, device and browser Google derives from your connection. Google Analytics does not log or store IP addresses. It sets two cookies on this domain,
_gaand_ga_<ID>, holding a random identifier, which expire after 13 months. Google signals and every advertising feature are off: nothing is used for advertising, and no profile is built across other sites. Reports are kept for 14 months. - Cloudflare Web Analytics, provided by Cloudflare: page views and how quickly pages load, counted without cookies, without browser storage and without fingerprinting. It keeps no identifier for you at all.
Where the site asks first. In the European Economic Area, the United Kingdom and Switzerland, Google Analytics does not run until you allow it: a small card asks when you arrive, and until you choose “Allow” Google’s script is not even loaded. Everywhere else it runs unless you turn it off.
Changing your mind. Privacy choices, at the foot of every page, opens the same card; “No thanks” stops Google Analytics and deletes its cookies from your browser. If your browser sends a Global Privacy Control signal, Google Analytics does not run unless you have chosen “Allow” here yourself. A content blocker that stops the script has the same effect, and costs you nothing on this site.
What your browser keeps for the site itself. Your language choice, as site-lang (in localStorage and a one-year cookie, so the address / opens in the language you picked); your answer to the card, as site-consent; and, for the length of one visit, whether that visit has to ask (sessionStorage). None of it identifies you, and none of it leaves your device except the language cookie, which only this site reads. The offline copies of pages are described in section 7.
No advertising, trackers, pixels or fingerprinting, of any kind. Every font, image and script is served from this domain except three: Google’s analytics script, Cloudflare’s Web Analytics beacon, and the Cloudflare Turnstile check on the two forms. The site’s Content Security Policy allows those and forbids everything else, so no other third-party request can be added by accident.
Legal basis: your consent (Article 6(1)(a) GDPR, and the ePrivacy rules on storing data in your browser) where the site asks for it; elsewhere, legitimate interests (Article 6(1)(f)) in knowing which pages and products are useful — which you can object to at any time under Privacy choices. For Cloudflare Web Analytics, legitimate interests; it stores nothing on your device.
3. Hosting and server logs
The site is hosted on Cloudflare Pages. Like every web server, Cloudflare’s network processes the technical details of each request — your IP address, the page requested, your browser’s user-agent string and the referring page — in order to deliver the page and to protect the service from attack and abuse. This is Cloudflare’s own infrastructure logging, retained under Cloudflare’s terms and privacy policy rather than the studio’s, and it is not combined with anything else, not used to build a profile, and not used to identify you.
Legal basis: legitimate interests (Article 6(1)(f) GDPR) in serving the site securely and keeping it available.
4. The contact form and the mailing list
These are the only parts of the site that store personal data you give it. When you submit the contact form, the following is written to a database (Cloudflare D1) operated for the studio:
- Your name, email address and message — as you typed them.
- A salted SHA-256 hash of your IP address — never the address itself. The hash exists only to be compared against other hashes so that the form can be rate-limited; the plaintext address is not stored because it would buy nothing and is personal data the studio has no reason to hold.
- A two-letter country code, derived by Cloudflare from your connection, and the first 500 characters of your user-agent string — both used to triage messages and to recognise abuse.
- The time of submission.
The form is protected by limits on how many messages can be sent in a minute, an hour and a day, and identical messages sent twice within ten minutes are discarded. There is a hidden field that real people never fill in; if it is filled in, the message is dropped.
Your message is held unconfirmed until you open the one-time link emailed to the address you gave, which works for 24 hours; only then is the studio notified. A message that is never confirmed is deleted after 7 days.
Legal basis: taking steps at your request before entering into a contract (Article 6(1)(b) GDPR) where you are enquiring about work, and legitimate interests (Article 6(1)(f)) in replying to correspondence and in preventing abuse of the form.
Please do not send confidential or sensitive information through the form. It is an ordinary enquiry channel, not a secure one, and no confidentiality obligation arises from your using it — see section 8 of the terms.
The mailing list. Signing up for new writing stores your email address, a salted hash of your IP address (for rate limiting, as above), a hash of a one-time confirmation link that expires after 24 hours, and the times you signed up and confirmed. Nothing is sent to you until you open that link. Once you confirm, your address is added to the mailing list held with Resend, which sends each email, and every email carries a one-click unsubscribe. The studio also records whether delivery to your address bounced or was marked as spam, so it can stop sending. An address that is never confirmed is deleted after 7 days.
Legal basis: your consent (Article 6(1)(a) GDPR), given by confirming and withdrawn by unsubscribing.
5. Who else sees it
The studio does not sell personal data, does not share it for advertising, and does not disclose it to anyone except the service providers below, each of which processes it only to provide its service:
- Cloudflare, Inc. — hosting, the content delivery network, the database the messages and sign-ups are stored in, and Web Analytics (section 2).
- Resend — sends the confirmation emails; when email notification is enabled, emails the studio a copy of your name, email address and message so it can be read and answered (the IP hash, country and user-agent are not included); and holds the mailing list and sends each issue to confirmed subscribers.
- Google — Google Analytics (section 2), for the visitors it measures. Google processes that data on the studio’s behalf under its data processing terms, with data sharing and every advertising feature switched off.
- Cloudflare Turnstile — both forms carry Cloudflare’s anti-bot check; to verify it, your IP address and signals from your browser are sent to Cloudflare, under Cloudflare’s privacy terms for Turnstile.
Personal data may also be disclosed where the law requires it, or to establish or defend a legal claim.
6. Downloads and version numbers
No download URL is stored in this site. When you click a download button, the site asks GitHub where the current release file is and redirects your browser to it. That redirect means your browser then connects to GitHub directly, so GitHub — not the studio — receives your IP address and user-agent for the download itself, under GitHub’s privacy policy. The studio stores nothing about downloads itself; if Google Analytics is measuring your visit (section 2), the click is counted there — which product, which platform — with nothing that identifies you to the studio.
Product pages also ask this site for the current version number so the page can correct itself. That request goes to this domain only and carries no identifier.
7. Offline support
The site installs a service worker so that pages you have already visited keep working without a connection. It stores copies of those pages in your own browser’s cache, on your own device. Nothing about what you cached is transmitted anywhere, and clearing your browser’s site data removes it.
8. How long it is kept
Contact messages and the request details stored with them are kept for 24 months from the date they are sent, and are then deleted. Where a message leads to an ongoing engagement, the correspondence may be kept for as long as that relationship lasts and for any period afterwards that tax or limitation law requires.
You can ask for a message to be deleted sooner at any time — see below.
Contact messages and mailing-list sign-ups that are never confirmed are deleted after 7 days. A confirmed subscription is kept until you unsubscribe; unsubscribing stops every email at once, and the record behind it is deleted on request (section 9).
Google Analytics reports are kept for 14 months, and its cookies expire after 13. Cloudflare Web Analytics keeps no identifier, so there is nothing of yours in it to retain.
9. Your rights
If you are in the European Economic Area or the United Kingdom, the GDPR gives you the right to access the personal data held about you, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable format. Where processing rests on legitimate interests, you may object to it at any time.
Where processing rests on your consent, you may withdraw it at any time — for analytics under Privacy choices, for the mailing list by unsubscribing — without affecting what was done before.
If you are a California resident, the CCPA/CPRA gives you the right to know what personal information is collected and disclosed, to have it deleted, to have it corrected, and not to be discriminated against for exercising those rights. The studio does not sell or share personal information, in any sense those words carry under that Act — analytics runs with every advertising feature off — and so shows no “Do Not Sell or Share” link; Google Analytics itself can be turned off under Privacy choices.
To exercise any of these rights, use the contact form. Requests are answered within one month. You may be asked for enough information to be sure the request is genuinely yours — usually just the email address the message was sent from.
You also have the right to complain to a data protection authority, normally the one where you live or work.
10. Where the data is
The studio operates from the United States, and the service providers named in section 5 are based in the United States and run globally distributed networks. Personal data may therefore be processed outside the country you are in, including outside the EEA and UK. Where that involves a transfer from the EEA, the UK or Switzerland, it takes place under the EU–U.S. Data Privacy Framework (and its UK and Swiss extensions) where the provider is certified to it, and otherwise under the European Commission’s Standard Contractual Clauses (with the UK Addendum where applicable), which those providers incorporate into their terms.
11. The apps are separate
This policy covers this website. It does not describe what the studio’s applications do once they are installed on your own machine, because each one is different and each one already says so on its own page.
Where an app processes data, the privacy section of its product page states what leaves the device and what does not, and the app itself carries the controls. Start from the app list. Four of the seven are open source under the MIT licence, so their behaviour can also be read directly from the source rather than taken on trust.
One tool has a policy of its own rather than a section, because it is the only one that touches a third party’s account on your behalf: mcp-studio posts videos to your TikTok account, so what it takes from TikTok and where that goes is written out in full, alongside its own terms.
Apps obtained from the Mac App Store are also subject to Apple’s own privacy terms for the store transaction, and support given through a funding platform named on the donate page is subject to that platform’s privacy policy. The studio never receives your payment details from any of them.
12. Children
The site is not directed at children and the studio does not knowingly collect personal data from anyone under 16. If you believe a child has sent a message through the form, say so through the form and it will be deleted.
13. Changes to this policy
This policy is revised when the site’s behaviour changes, and the date at the top is the date of the last review. Material changes will be reflected there; the mailing list is for the writing, not for notices like this one, so the date is the honest signal.