Privacy Policy
Last updated: August 25, 2026
What this covers
This policy covers rashaadrandall.com. I run the site myself — there is no company behind it, no analytics team, and nobody else with access to what it records. Below is what the site actually collects, who else ends up holding it, and how long it stays. It is written to match the code rather than to cover every eventuality.
If you find a sentence here that the site does not live up to, treat the sentence as the bug and tell me.
What the site collects
Contact and lead forms
The contact page and the shorter lead forms on the service pages send four things you type: your name, your email address, a subject, and your message. Alongside them the server records two things you did not type — the IP address the request came from and your browser's user-agent string. Both are kept for spam forensics. All six are written to a database I run, and all six also appear in the notification email that reaches my inbox.
Newsletter
Subscribing stores the email address you enter, together with the IP address and user agent the request arrived with. Nothing else: no name, no profile of what you read, no list rented or shared with anyone. The address is used to email you when I publish, and for nothing else.
Spam protection
The forms are protected by Google reCAPTCHA v3, which runs invisibly on the pages that carry one. It has no puzzle and nothing to click: it watches how the page was used and gives the server a score for how likely the submission came from a person. Doing that means your browser contacts Google and discloses your IP address, your browser and device characteristics, and your mouse and keyboard activity on that page. What you typed into the form is not sent to Google.
This is treated as strictly necessary rather than as analytics, so switching analytics off in the cookie settings does not stop it. That is a deliberate call and worth stating plainly: without it the contact form is an open, unauthenticated endpoint that anyone can script. If you would rather not be scored, block the script — the form still submits, and the server accepts an unscored submission rather than refusing it.
Analytics
The site runs Google Analytics 4. On each page it records a page view — the path, the page title, and the full URL including any query string — and a handful of named events: clicking a call to action, submitting a lead form, downloading the resume PDF, and opening an FAQ answer. The event payloads are deliberately built to carry no names, no email addresses, and nothing you typed. The tag is configured with IP anonymisation switched on.
The machine-learning demos
Two pages talk to a model server I run: the custom language model demo and the ad preview validator. Text you type into the chat demo is sent to that server and held in its memory so the model can follow the conversation. Images you upload to the validator are decoded in memory, classified, and dropped once the response is sent. Neither is written to a database, and neither is forwarded to an outside AI provider — the models run on the same machine as the site.
That memory is not permanent storage, but it is not a guarantee of privacy either. Please treat the demos as public and do not paste anything confidential into them.
Server logs
Every request to the site is written to the server log with its timestamp, status, path, and the client IP address — that happens for ordinary page loads, not only for forms. If a contact submission fails both to save and to send, the address it came from is written to the same log so the message can be recovered by hand. These logs live inside the running container and are destroyed whenever it restarts or redeploys; there is no long-term log archive.
Cookies and browser storage
Google Analytics sets its own cookies in your browser — the ones whose names begin with _ga — so that repeat visits can be recognised. On pages with a form, reCAPTCHA sets one more, _GRECAPTCHA, which is how it scores the submission. Those are the only cookies involved.
The site itself sets no cookies. The one thing it keeps in your browser is your light-or-dark theme preference, saved in local storage under the key theme. That value never leaves your browser and is never sent to the server.
There are no advertising tags, no cross-site tracking pixels, and no third-party marketing scripts anywhere on the site. The only third-party scripts that run at all are the analytics tag and, on the pages with a form, reCAPTCHA.
Cookie settings
Analytics start as soon as a page loads. They are not held back waiting for you to agree — the cookie settings control is an opt-out, not an opt-in. You can switch analytics off at any time and the choice is remembered. Three categories are offered:
- Strictly necessary — the little the site needs to work at all, such as remembering your theme, and the reCAPTCHA check that keeps the forms usable. Always on.
- Analytics — governs Google Analytics. Turning it off stops the tag from running.
- Marketing — advertising and remarketing signals. Like analytics, it is on unless you turn it off.
How the information is used
- To read and reply to what you send me
- To email the newsletter to people who asked for it
- To trace spam and abuse back to a source
- To see which pages and services people actually use
Nothing collected here is sold, rented, traded, or used to build an advertising profile.
Who else receives it
- SendGrid (Twilio)
- Delivers the contact-form notification to my inbox. The whole submission travels in that email, including the IP address and the user agent — not just what you typed.
- Google Analytics
- Receives the page views and events described above, and sets the _ga cookies described above.
- Google Fonts
- Typefaces are loaded from fonts.googleapis.com and fonts.gstatic.com, so your browser contacts Google on every page load. That request discloses your IP address to them whether or not analytics are switched off.
- Google reCAPTCHA
- Runs on the pages that carry a form, to tell a person apart from a script. Google receives your IP address, your browser and device characteristics, and how you moved and typed on the page, and returns a score. It sets a _GRECAPTCHA cookie to do it. It never receives what you typed into the form.
- My email inbox
- Contact notifications land in a hosted mailbox that I read. Its provider can see those messages the same way any mail provider can.
- Hugging Face
- The demo model server downloads model files from Hugging Face when it starts. Nothing about you is sent there — the traffic goes one way, and the models run on my own hardware.
Everything else runs on a single server I administer. No other party is given access to the database or the inbox.
How long it is kept
Contact submissions and newsletter addresses are kept until I delete them by hand. There is no scheduled purge and no expiry date. A message you sent two years ago is still in the database, with the IP address and user agent that came with it.
Server logs and the model server's logs are the opposite: they sit in ephemeral container storage and are wiped every time the service restarts or is redeployed. Chat sessions held in the model server's memory go the same way.
Analytics data is held by Google on its own retention schedule, under its terms rather than mine.
Your choices
There is no account page and no unsubscribe link, because there is no system behind either. Every request below is one I handle by hand — send it through the contact form and I will act on it:
- Ask what I hold about you
- Ask me to correct something that is wrong
- Ask me to delete it
- Ask to be taken off the newsletter list
Coming off the newsletter means me removing the row myself, so allow a couple of days rather than the instant effect an unsubscribe link would give you. To stop analytics instead, use the cookie settings control; blocking cookies or third-party scripts in your browser works too.
Security
The site is served over HTTPS. The database connection requires TLS, and its credentials come from a secrets manager rather than from the source code. The contact form is rate limited to five submissions per address per ten minutes. That is a reasonable setup for a personal site, and it is not the same thing as a promise that nothing can go wrong — I am not going to make that promise.
Children
This site is aimed at people hiring a technology consultant, not at children, and I do not knowingly collect anything from anyone under 13. If you believe a child has sent me something, tell me and I will delete it.
Changes to this policy
When what the site does changes, this page changes with it and the date at the top moves. The policy lives in the same public repository as the site, so its full history is there to read.
Questions
Anything about this policy, or about what I hold on you, goes through the contact page. It reaches me directly.