Privacy Policy
What The Tech Archive collects, why, who we share it with, and how to get it deleted. Plain language, no boilerplate.
Last updated: 6 August 2026
This is the canonical source for the /pages/privacy page. The page itself lives in
the database behind the API; this file exists so the text is version-controlled and
reviewable, and so it can be re-applied if the record is ever lost. Edit here first,
then push it to the CMS.
Every statement below was verified against the running site rather than copied from a template. If you change what the site loads or stores, change this text in the same commit.
The short version
- We publish articles. You can read every one of them without an account, without giving us your name, and without telling us anything about yourself.
- If you subscribe to the newsletter, we store your email address. Nothing else.
- If you sign in, we do it through Google, and we store the profile basics Google returns so your comments and bookmarks belong to you.
- We use Google Analytics to count visits and see which articles are read. We do not sell data, we do not run advertising, and we do not build profiles about you.
- You can ask us to delete anything we hold about you. One email is enough: shamuddin1011@gmail.com.
The rest of this page is the detail behind those five points.
Who we are
The Tech Archive is an independent publication about artificial intelligence, published at shaam.blog by Sham.
For anything to do with privacy — a question, a correction, a deletion request — write to shamuddin1011@gmail.com. That address is read by a person, and it is the same address used for corrections and editorial contact.
What we collect
Things you choose to give us
Your email address, if you subscribe. The newsletter form stores one thing: the
address you typed, plus a short label recording which part of the site you signed up
from (for example footer). No name, no company, no interests, no tracking pixel in
the emails to tell us whether you opened them.
Your Google profile basics, if you sign in. Signing in is optional and only needed to comment, like, or bookmark. We use Google as the only sign-in provider, which means:
- We never see, receive, or store your password.
- Google returns your name, email address, and profile picture URL, and we store those so your activity is attributed to you and so you can be reached about it.
- We do not request access to your Google account beyond that basic profile.
What you write. Comments are content you publish deliberately. They are visible to everyone, attached to your display name and picture, and stored until you or we delete them. Likes and bookmarks are stored against your account so they persist between visits; bookmarks are private to you.
Things collected automatically
Analytics. Every page loads Google Analytics 4 (property G-Q5DX8H69ZY). It
records the page you viewed, roughly where in the world you are, the type of device
and browser, and where you arrived from. It sets cookies to recognise a returning
browser. We use it to see which articles are worth writing more of. We have not
enabled Google Signals, advertising features, or any ad remarketing on this property.
Security and delivery. The site sits behind Cloudflare, which handles caching and blocks automated abuse. Cloudflare processes your IP address and request headers to do that, and sets its own cookies to remember that a visitor has already passed a bot check. This is what keeps the site up; it is not optional, and it is not used to advertise to you.
Server logs. Our API records administrative and sign-in activity — the request path, the time, the response status, the IP address, and the browser's user-agent string. This is a security measure: it is how an unauthorised change would be traced. Ordinary article reading is not logged this way. Request rates are counted per IP address in memory to stop abuse; those counts are not stored.
View counts. Each article carries a view total. It is a number on the article, not a record of who read it.
Things we do not collect
To be explicit, because policies usually are not:
- No advertising or ad-targeting cookies. There are no ads on this site today.
- No Facebook, Meta, TikTok, or LinkedIn tracking pixels.
- No session recording, heatmaps, or mouse-movement capture.
- No fingerprinting library.
- No payment details — we do not sell anything, so we never touch card data.
- No cross-site tracking of you across the wider web.
- No purchase of mailing lists or personal data from third parties.
If any of that changes — introducing advertising is the likeliest reason it would — this page will be updated before the change goes live, not after.
Cookies and similar technologies
| Set by | Purpose | Roughly how long |
|---|---|---|
Google Analytics (_ga, _ga_*) |
Tells returning visits apart from new ones and measures which pages are read | Up to 2 years |
Cloudflare (__cf_bm, cf_clearance) |
Bot and abuse protection; remembers that this browser already passed a check | 30 minutes to 1 year |
| Sign-in session | Keeps you signed in between page loads. Only set if you sign in | Until you sign out or it expires |
| Theme preference | Remembers light or dark mode. Stored in your browser, never sent to us | Until you clear your browser storage |
You can block or delete any of these in your browser settings. Blocking the analytics and theme cookies costs you nothing but the dark-mode preference. Blocking Cloudflare's may mean you are asked to pass a check more often.
Turning analytics off. Any of these works, and we will not try to defeat them:
- Install Google's official Analytics opt-out browser add-on.
- Use a browser that blocks trackers by default, or any reputable content blocker.
- Use your browser's private or incognito mode and clear cookies afterwards.
On consent: analytics currently loads for everyone. If you are in the EU, UK, or another region where prior consent is required for analytics cookies, use one of the opt-outs above until we ship a consent banner. We would rather tell you plainly where we stand than imply a consent flow that does not exist yet.
Why we process any of this
| What we do | Why | Legal basis under GDPR |
|---|---|---|
| Serve pages, images, and feeds | You asked for a page | Legitimate interests |
| Store your newsletter address | You asked to receive the newsletter | Consent |
| Create and run your account | You asked to sign in | Contract |
| Publish your comments | You asked to post them | Contract |
| Analytics | Understanding which articles are worth writing | Consent where required, otherwise legitimate interests |
| Bot protection, rate limits, audit logs | Keeping the site online and detecting tampering | Legitimate interests |
We do not use your data to make automated decisions that have a legal or similarly significant effect on you.
Who else touches your data
We keep the list of third parties as short as we can. Each one is a processor doing a specific job, not a partner we share data with for their own purposes.
| Service | What it does for us | What it can see |
|---|---|---|
| Cloudflare | CDN, TLS, caching, bot protection | IP address, request headers, requested URLs |
| Google Analytics | Traffic measurement | Pages viewed, approximate location, device, referrer |
| Google (Sign in with Google) | Authentication | Your Google account, if you choose to sign in |
| Google Search Console | Shows us search queries that led to the site, in aggregate | Aggregated search data — never individual visitors |
| Our hosting provider | Runs the servers and database | Data at rest on the server |
| Cloudflare R2 | Stores article images, served from cdn.shaam.blog |
Image requests |
We do not sell personal information, and we do not share it for cross-context behavioural advertising. Under the California Consumer Privacy Act, that means there is nothing for you to opt out of on that front — but you still have the access and deletion rights described below.
Where your data goes
The services above operate globally, so your data may be processed outside your own country, including in the United States. Where that involves personal data from the EEA or the UK, we rely on the providers' own transfer mechanisms — Standard Contractual Clauses and, for participating US providers, the EU–US Data Privacy Framework.
How long we keep things
- Newsletter address: until you unsubscribe or ask us to delete it. Every email carries an unsubscribe link, and unsubscribing removes the address.
- Account and profile: until you ask us to delete the account.
- Comments: until you delete them or ask us to. We may keep a comment with the author details removed where deleting it outright would make a conversation unreadable — tell us if you would rather it went entirely.
- Analytics: on Google's retention schedule, currently 14 months, then automatically deleted.
- Security and audit logs: short-lived, kept only as long as they are useful for investigating a problem.
- Aggregate counts such as article view totals are not personal data and are kept indefinitely.
Your rights
Wherever you live, you can ask us to:
- Tell you what we hold about you, and give you a copy.
- Correct anything that is wrong.
- Delete it.
- Stop using it — including withdrawing consent for the newsletter or analytics at any time, which does not affect anything already done lawfully.
- Export it in a portable format.
- Object to processing we base on legitimate interests.
If you are in the EEA or the UK, these are your rights under the GDPR and the UK GDPR. If you are in California, they are your rights under the CCPA as amended by the CPRA, and we will not treat you differently for exercising them. Other regions grant similar rights; we apply the same process to everyone rather than tiering it by geography.
To exercise any of them, email shamuddin1011@gmail.com and say what you want. We aim to reply within 7 days and to complete the request within 30. We may need to confirm you control the email address in question — that is to stop someone else deleting your data, not an obstacle we are putting in your way.
If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to complain to your data protection authority: in the EEA, your national supervisory authority; in the UK, the Information Commissioner's Office.
Security
Traffic to and from the site is encrypted with TLS. Sign-in is delegated to Google, so there are no passwords here to steal. Administrative endpoints require an authenticated admin identity, and changes to them are logged. Access to the server and database is restricted to key-based authentication.
No site can promise perfect security, and we will not pretend otherwise. What we will do is tell you: if a breach affects your personal data, we will notify you and the relevant authority as the law requires.
Children
This site is written for a professional and technical audience and is not directed at children under 16. We do not knowingly collect their personal data. If you believe a child has given us information, email us and we will delete it.
Links and embeds
Articles link out to other sites, and some embed third-party content such as videos. Once you follow a link or interact with an embed, that provider's own privacy policy applies, not this one. We choose what to link to on editorial merit and cannot control what those sites do.
AI-generated content
Some articles are researched and drafted with AI assistance under human editorial review. This matters to privacy for one reason worth stating: we do not feed your personal data, comments, or email address into any AI model, for training or for anything else. How we use AI editorially is described on our AI disclosure page, and how we verify claims on our methodology page.
Changes to this policy
When this policy changes we update the date at the top. For a change that materially affects what we collect or who we share it with — introducing advertising, for instance — we will say so prominently on the site rather than quietly editing this page.
Contact
Email: shamuddin1011@gmail.com
That is the fastest route for a privacy question, a correction, or a deletion request.