privacy policy
Privacy policy
Last updated: July 2026
This website is operated by Opes (“I”, “me”) at opes.dev. This policy explains what personal data is collected, why it is used, and your rights. It applies to visitors from the United States, the United Kingdom, the European Economic Area, and elsewhere.
For questions or requests, email [email protected]. See also the cookie policy, terms of use, and donation policy.
Data I collect
- Contact form — name, email address, and message when you use the contact form.
- Server logs — standard web server data such as IP address, browser type, and pages requested. Used for security and troubleshooting.
- Rate-limit cache — a hashed record of recent contact form attempts to prevent abuse. Stored on the server, not in a visitor-facing database.
- GitHub cache — public repository names, descriptions, and metadata from the GitHub API, cached briefly on the server for the home page.
I do not run analytics, advertising trackers, or user accounts on this site. I do not sell personal data.
How data is used
Contact form data is sent to me by email via SMTP so I can read and reply. Server logs and rate-limit data are used to keep the site secure and available. GitHub data is used to display recent public repositories.
Legal bases (UK & EU)
Where UK GDPR or EU GDPR applies, I rely on:
- Legitimate interests — operating and securing the website, responding to enquiries, and displaying public project information.
- Contract / pre-contractual steps — handling messages about work or services you request.
- Consent — where required for non-essential cookies or similar technologies (see the cookie policy).
United States visitors
I do not sell or share personal data for cross-context behavioural advertising. Depending on your US state, you may have rights to access, delete, or correct personal data I hold about you, and to opt out of certain processing. To exercise these rights, email [email protected] with enough detail for me to locate your message.
UK & EU rights
If UK or EU data protection law applies, you may have the right to access, rectify, erase, restrict, or object to processing, and to data portability where applicable. You may also lodge a complaint with your local supervisory authority (for example the ICO in the UK or your EU member state authority).
To exercise your rights, email [email protected]. I may need to verify your identity before responding.
Retention
Contact messages are kept in my email inbox for as long as needed to respond and for reasonable business records. GitHub cache files expire after about one hour. Rate-limit records roll off automatically within 24 hours. Server logs are retained according to my hosting provider’s normal retention period.
Third parties
- SMTP / email provider — delivers contact form messages (processes addresses and message content).
- Cloudflare Turnstile — optional bot verification on the contact form when configured.
- GitHub — public API for repository metadata displayed on the home page.
- PayPal — voluntary donations via the donate page are handled entirely by PayPal; see the donation policy.
- Hosting provider — serves the website and may process server logs.
International transfers
Email, hosting, or other providers may process data in countries outside your own. Where required, I rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms offered by those providers.
Children
This site is not directed at children under 16. If you believe a child has sent personal data through the contact form, email [email protected] and I will delete it.
Changes
I may update this policy from time to time. The “Last updated” date at the top will change when it does.