Skip to content

Privacy Policy

Last updated 9 September 2026. This replaces the version from 2015.

dipinkrishna.com is a personal blog and portfolio run by me, Dipin Krishna, an individual in Kerala, India, not a company. For the GDPR I am the data controller; under India’s Digital Personal Data Protection Act, 2023 I am the data fiduciary. Use the contact form to reach me about anything on this page.

The short version

  • There are no visitor accounts, no newsletter and no login. Nothing here asks you to register.
  • The only personal information you actively give me is what you type into the contact form or a comment.
  • Passively, the server logs requests. That is the only measurement here.
  • I don’t sell, rent or trade your data, and I don’t run retargeting pixels, session recording or heatmaps.
  • Fonts are served from this server, so loading a page doesn’t announce you to a font CDN.

What gets collected, and why

Server logs

The site runs on a DigitalOcean server behind Cloudflare. Both keep request logs: your IP address, the time, the URL you asked for, the referring page and your browser’s user-agent string. This is how anyone runs a web server: it’s what makes it possible to fix a broken page or block whatever is hammering the login form. Logs rotate automatically and aren’t used to build a profile of you.

Analytics

There is no analytics service on this site. No measurement script runs in your browser, nothing is stored on your device for counting purposes, and no third party is sent a record of your visit.

What I have instead is the request logs described above, plus the aggregate traffic figures Cloudflare produces from routing the traffic it is already routing. I read those occasionally to see which articles are worth updating. Neither gives me a profile of a reader, and I don’t build one.

Google Analytics used to run here. It was removed in September 2026 and nothing replaced it.

The contact form

The form on the contact page collects your name, email address, an optional company name and your message. It is emailed straight to me. Submissions are not stored in the site’s database. The email also carries the IP address the message came from and the page it was sent from, which is how I tell a real enquiry from a spam run. A one-way hash of that IP address is held for up to an hour, purely to limit how many messages one connection can send.

Enquiries stay in my mailbox for as long as the conversation is useful, and are deleted after that. If you’d like a message deleted sooner, ask.

Comments

Comments are open on most posts. Leaving one stores your name, email address, optional website, the comment text, your IP address and your user-agent string. This is WordPress’s standard behaviour. The name, website and comment text are published; your email address and IP address are not. If the comment form offers to remember you and you accept, WordPress sets comment_author_* cookies so you don’t have to retype your details; if you don’t, no comment cookies are set.

Comments are kept with the post they belong to, indefinitely, because a fifteen-year-old thread is often more useful than the article above it. Ask and I’ll delete or anonymise yours.

Comment avatars come from Gravatar, so a hashed copy of your email address and your IP address reach Automattic when an avatar loads.

Cookies

This site sets very little by itself:

  • bp_user-role and bp_user-registered: set on every response to record whether the visitor is signed in, so cached pages are served correctly. They contain no personal data.
  • comment_author_*: only if you leave a comment and choose to be remembered on the form.
  • Cloudflare may set __cf_bm or cf_clearance when its bot protection is involved in serving you a page.

There is no cookie banner. None of these cookies carry your name, your email address or anything you typed.

Embedded content from other sites

Some older posts embed a YouTube video, a GitHub gist or an X/Twitter post. Embedded content behaves exactly as if you had visited that site directly: the other site can see your IP address, set its own cookies and track your interaction with it. Their privacy policies apply, not mine.

Advertising

No ads are being served as of the date at the top of this page. The site is built so that ad code can only ever appear on single blog posts, never on the portfolio, the contact page or any listing page. If Google AdSense is switched back on, Google and its partners may use cookies or device identifiers to select and measure ads. You control that at Google My Ad Center and optout.aboutads.info, independently of this site.

What I don’t do

  • I don’t sell, rent or share your personal information with data brokers or advertisers. There is no “sale” or “sharing” of personal information in the CCPA sense.
  • I don’t run a mailing list, so nothing you send me is added to one.
  • I don’t fingerprint browsers, record sessions or replay your clicks.
  • I don’t use comments or enquiries to train AI models. The site does welcome AI crawlers, but only to the published articles, never to comment metadata, enquiries or anything else in this policy.

Who else touches the data

  • DigitalOcean: hosting.
  • Cloudflare: DNS, CDN and bot protection; all traffic passes through it, which is also where the aggregate traffic figures come from.
  • Google: only if AdSense is ever re-enabled.
  • Automattic: Gravatar avatars on comments.
  • An email delivery provider: carries contact-form messages to my mailbox.

These providers operate outside India, including in the United States, so using this site involves an international transfer of the limited data above. Each has its own safeguards and privacy terms.

Legal basis (EU/UK readers)

Server logs, spam prevention and site security rest on my legitimate interest in keeping a site online and working. Reading aggregate traffic figures rests on the same legitimate interest: knowing which articles people read. It stores nothing on your device and singles nobody out. Contact-form messages and comments are processed on the basis of your own request to send them.

Your rights

Wherever you live, you can ask me to show you what I hold about you, correct it, delete it, or stop using it. If you’re in the EU or UK, that’s your GDPR right of access, rectification, erasure, restriction, objection and portability, and you may complain to your data protection authority. If you’re in India, the DPDP Act gives you access, correction, erasure, grievance redressal and nomination rights. If you’re in California, you may request disclosure and deletion, and you will never be treated differently for asking.

Send the request through the contact form and say it’s a privacy request. I answer within 30 days, usually much sooner. For comments, WordPress’s built-in export and erasure tools mean I can hand you a file or wipe the record cleanly. I may need to confirm you control the email address on the comment or enquiry before acting.

How long things are kept

  • Server and Cloudflare logs: a short rolling window, then rotated away automatically.
  • Contact-form emails: as long as the conversation is live, then deleted.
  • Rate-limit hashes: one hour.
  • Comments: indefinitely, alongside the post, until you ask otherwise.
  • Traffic figures: aggregate only, held by Cloudflare for a limited period. There is no per-visitor record to keep or delete.

Children

This site is written for working developers and isn’t directed at children. I don’t knowingly collect personal data from anyone under 18. If a child has left a comment or sent a message, tell me and I’ll remove it.

Security

The whole site is served over HTTPS. It takes no payments and stores no card details, passwords or visitor accounts, so there is simply very little here to lose. Should something in my control be breached in a way that affects you, I’ll say so publicly on this site and notify the relevant authority where the law requires it.

Changes

I’ll edit this page when the site changes, and update the date at the top. Anything that materially changes what is collected will be called out here rather than slipped in quietly.

Contact

Questions, requests or complaints about privacy go through the contact form. Leave a reply address in the message and I’ll come back to you there; a postal address is available on request.