01. Philosophy & Scope
realm (available at irvanma.eu.org and associated gRPC microservices) is the personal digital sanctuary and engineering platform operated by Irvan Malik Azantha. We operate under a straightforward tenet: we collect only what is strictly required to provide service features, and nothing more.
We do not sell, rent, monetize, or broker personal information to data aggregators or advertisers. There are zero programmatic marketing trackers, Google Analytics scripts, or cross-site fingerprinting beacons on this platform.
02. Data Collection & Purpose
We process information exclusively across four touchpoints:
- Authentication & User Accounts: When you register directly or authenticate via Google or GitHub OAuth, we store your chosen username, email address, avatar URL, and cryptographic password hash (or provider identity ID). Passwords are salted and hashed using bcrypt/Argon2; plaintext passwords are never logged or stored.
- Interactive Comments & Reactions: When you comment on blog posts or react with emojis, your submitted content and associated user handle are stored in our PostgreSQL database to display alongside the discussion.
- Contact Form Inquiries: When you submit the contact form, your name, email, subject, and message are transmitted over encrypted webhooks to Irvan's private notification channels (Discord, Telegram, or SMTP). A honeypot field is utilized to drop automated spam bots silently.
- Media & Avatar Uploads: Images uploaded for user profiles are converted to modern WebP formats and compressed using Zstandard (zstd) on our private, self-hosted disk storage.
04. Third-Party Integrations & Proxies
To provide specific external features without leaking user identities, we utilize strict server-side proxy gateways:
- GitHub API: Used server-side to query public repository contribution matrices. Your client IP is never exposed to GitHub during site visits.
- Google & GitHub OAuth: Used strictly for voluntary single sign-on when you choose to link an identity provider. We request only minimal public profile scopes.
- Last.fm Scrobbler API: Cached and proxied by our Go backend with stale-while-revalidate and circuit-breaker mechanisms. Visitors do not connect directly to Last.fm.
05. Security Architecture & Sandboxing
Our technological architecture enforces defense-in-depth principles:
Filesystem isolation enforced via Linux kernel security modules.
All transit is encrypted via modern forward-secret ciphers.
Strict private subnet filtering, honeypots, and token-bucket rate limits.
Trace-correlated logs sanitize all PII and tokens before emission.
06. Your Rights & Data Erasure
Regardless of your geographic jurisdiction (GDPR, CCPA, or otherwise), you possess absolute sovereignty over your data:
- Right to Access: You can review your profile information directly in your account settings.
- Right to Rectification: You may edit your username, avatar, and password whenever you choose.
- Right to Erasure (Forget Me): You can delete your account permanently via the settings panel. Deletion is instantaneous and purges your authentication records and session tokens.
07. Contact & Data Requests
If you have inquiries regarding this privacy policy or wish to exercise any data subject rights manually, please contact Irvan via the Contact Form or via email at irvanma@gnuweeb.org.