Page

Privacy Policy.

This Privacy Policy applies to blog.analogarray.org and explains what information may be collected when you visit the blog, how that information is used, who may process it, and the choices available to you.

The blog is a personal publication operated by Anjelo Fernando. It does not provide user accounts, comments, advertising, newsletter signup, checkout, or public contact forms. Most information handled through the blog is limited to normal technical data created when a website is delivered, protected, and maintained.

Summary

  • The main blog has no user accounts, comments, newsletter signup, contact form, checkout, or advertising.
  • The main blog does not run behavioral analytics, advertising pixels, remarketing tags, or profiling tools.
  • The blog does not sell, rent, or trade visitor personal information.
  • The blog may generate normal technical logs through hosting, web server, CDN, DNS, and security systems.
  • The blog includes static lab/demo pages. Some demos may use browser storage, mock API calls, third-party scripts, or third-party fonts.
  • Hosting, CDN, or security services may use strictly necessary cookies or similar technologies to deliver the site, prevent abuse, or complete a security challenge.

Who runs this blog

blog.analogarray.org is the personal blog of Anjelo Fernando, based in Auckland, New Zealand.

The portfolio site at analogarray.org has its own privacy policy. This policy covers blog.analogarray.org and static pages served from this blog domain, including article pages, section pages, tag pages, RSS feeds, and lab/demo pages.

Questions, correction requests, or privacy concerns can be sent through the contact options on the portfolio site or by emailing [email protected].

Information this blog may collect

Information you send directly

If you contact me about the blog by email, social message, or another channel, I receive the information you choose to send. That may include your name, email address, profile details, message content, attachments, and normal message metadata.

Please do not send sensitive personal information unless it is necessary for the reason you are contacting me.

Technical information

When you visit the blog, technical systems used to deliver and protect the site may process log data such as:

  • IP address
  • requested URL
  • browser and device information
  • referrer
  • timestamps
  • error events
  • bot, abuse, firewall, or security events

This information is used to serve the blog, troubleshoot faults, understand security issues, block abuse, and keep the site available.

RSS feeds

The blog provides RSS feeds. If you subscribe through an RSS reader, the reader may request feed URLs from this site. The blog may see normal technical log information for those feed requests. Your RSS reader may also have its own privacy practices.

Static lab and demo pages

Some blog pages link to or host static lab demos. These are project demonstrations, not production services.

The current spend tracker mock under /labs/spend-tracker-mock/ uses browser session storage for demo state such as mock login/session flags, a mock CSRF token, and a mock username. It also contains mock transaction and budget data. Do not enter real passwords, real bank data, real financial records, or other sensitive information into static demos.

Static demos may make local mock API calls within the page, use third-party scripts such as Chart.js from cdnjs, and load Google Fonts. Those third-party requests may expose technical request information, such as IP address and browser details, to the relevant provider.

Published posts, photos, and comments about events

This blog includes posts, travel notes, technical notes, images, and observations. Some posts may mention places, dates, projects, or people in a personal or professional context.

If a post or image includes you and you want to request a correction, removal, or reduced detail, contact me. I will review requests case by case, balancing privacy, accuracy, authorship, security, and record-keeping.

How information is used

Information is used only for limited purposes:

  • to operate and deliver the blog
  • to maintain security and prevent abuse
  • to troubleshoot errors and availability issues
  • to reply when you contact me
  • to maintain RSS feeds and public content
  • to run static demos in your browser
  • to handle correction, removal, legal, or security requests

I do not use visitor information for targeted advertising, automated profiling, credit decisions, employment screening, or resale.

Where a privacy law requires a legal basis, the limited handling described in this policy is based on these grounds:

  • Technical logs and security events: legitimate interests in operating, debugging, securing, and protecting the blog, and any legal obligation that may require security records or abuse handling.
  • Contact messages: your choice to contact me, my legitimate interest in replying, and steps connected with a possible project, correction request, collaboration, or professional conversation.
  • Static demo browser storage: your interaction with the demo and my legitimate interest in demonstrating project behavior without collecting real production data.
  • RSS feed requests: my legitimate interest in making blog content available through standard feed readers.
  • Published posts and images: legitimate interests in publishing personal writing, technical notes, project records, travel notes, and site content, balanced against privacy and removal requests where appropriate.
  • Third-party script and font requests: legitimate interests in presenting demos and pages consistently, with the provider’s own privacy terms applying to the provider’s processing.
  • Legal requests or disputes: compliance with legal obligations, protection of rights, or legitimate interests in preventing misuse and resolving claims.

Cookies and browser storage

The main blog pages do not currently set advertising, analytics, tracking, account, comment, checkout, or newsletter cookies.

Hosting, CDN, or security providers may set strictly necessary cookies or use similar technologies if needed to deliver the blog, prevent abuse, route traffic, or complete a security challenge. Those are operational controls rather than advertising or behavioral analytics tracking.

Static lab/demo pages may use browser storage. For example, the spend tracker mock uses session storage for demo-only state. Session storage is normally cleared when the browser tab or session ends, although exact behavior depends on your browser.

You can clear cookies, local storage, and session storage through your browser settings.

If analytics, advertising pixels, embedded media, comments, a contact form, newsletter signup, or other tracking technology is added later, this policy and any required consent controls should be updated before those features go live.

The blog does not sell or share personal information for targeted advertising, so Global Privacy Control and Do Not Track signals do not change how the blog behaves.

The blog may use or link to third-party services, including:

  • Cloudflare or similar DNS, CDN, tunnel, hosting, routing, and security services
  • GitHub or other code hosting and deployment services
  • Google Fonts on some static demo pages
  • cdnjs or similar script CDN services on some static demo pages
  • LinkedIn, GitHub, the portfolio site, and other external websites

When your browser requests resources from a third party, or when you follow an external link, that third party’s own privacy policy applies. I do not control how external websites handle your information.

Who information may be shared with

I do not sell visitor personal information.

Information may be processed by service providers that help operate, secure, host, route, monitor, or publish the blog. Information may also be disclosed if required by law, to respond to valid legal process, to protect the blog from abuse, to investigate security issues, or to protect rights and safety.

Retention

  • Contact messages are kept for as long as needed to handle the conversation, request, project, record, or follow-up, unless deletion is requested and there is no practical or legal reason to keep them.
  • Technical logs are kept according to the retention settings of the hosting, CDN, security, tunnel, or server systems used for the blog.
  • Static demo session storage remains in your browser according to browser behavior and can be cleared by you.
  • Published blog posts and images remain online unless edited, unpublished, or removed.

Security and data location

The blog is served over HTTPS. The current main blog has no public account database, comment system, contact form, checkout, or newsletter database.

No website, server, email system, or CDN can be guaranteed perfectly secure. Reasonable technical and operational safeguards are used for the limited information involved.

Because the blog is public and uses internet infrastructure providers, information may be processed in New Zealand or other countries where those providers operate.

Your choices and rights

You can ask what personal information I hold about you, ask for correction, ask for deletion where practical, or raise a concern about how your information has been handled.

Contact: [email protected]

If you are in New Zealand and are not satisfied with the response, you can contact the Office of the Privacy Commissioner. If you are elsewhere, you may also have rights under your local privacy law.

Children’s privacy

This blog is a personal and technical publication. It is not directed at children. I do not knowingly collect personal information from children through the blog.

Changes to this policy

This policy may be updated when the blog changes or when legal requirements change. The latest version will be posted on this page.

Last updated: June 2, 2026.