Privacy Policy
Last updated: August 8, 2026
This site is run by Reza Mousavi and accessible at mrez.dev. This policy explains what data is collected, why, and the choices you have. It is written to match what the site actually does — nothing more, nothing less.
Data we collect
- Account data. When you create an account (email and password, or Google/GitHub sign-in), we store your name, email address, and avatar. This powers your dashboard, favorites, and API keys.
- Usage data.Every page view and tracked event is sent to a first-party beacon on this site and stored in the site's own database. This includes the page path, the referring site, and a random visitor id kept in your browser's localStorage — it is not your name or IP address, and no cookie is used for it.
- Optional analytics.Google Analytics 4 is loaded only in production, configured via the site's environment. When enabled, Google's privacy policy applies to that collection.
- Technical data. Your IP address is used transiently by the API rate limiter to prevent abuse and is not retained beyond the rate-limit window. Standard server logs may record request metadata.
How we use data
- Provide and secure accounts, favorites, and API keys.
- Understand which pages and tools are useful (the analytics dashboard).
- Protect the site and its API from abuse and downtime.
Cookies and local storage
Signing in sets a session cookie, which is strictly necessary for the account features to work. The theme preference and visitor id are kept in localStorage. We do not set third-party tracking cookies.
Third-party services
- Google and GitHub OAuth — used only to verify your identity when you choose social sign-in.
- GitHub API — fetches your public profile and repositories for the GitHub showcase page.
- Upstash Redis — caches GitHub data (expires after 30 minutes) and backs the rate limiter.
- Google Analytics — only when enabled in production as described above.
Data retention
Accounts and API keys remain until you delete them or request deletion. Analytics events are kept to power the admin dashboard. Cached data in Redis expires automatically.
Your rights
You can request a copy of your personal data, correct it, or ask for it to be deleted. Email mrez321@gmail.com and we will respond promptly.
Changes to this policy
If this policy changes, the “last updated” date above will be revised. Material changes will be called out here.
Contact
Questions about privacy? Email mrez321@gmail.com.