Legal
Privacy policy.
What this site collects, what the admin tools connect to, and what is never done with any of it.
Last updated 7 October 2026
In short
ravikishan.me is the personal portfolio and writing site of Ravi Kishan. It sets no advertising cookies, runs no third-party tracker, and sells nothing to anyone.
The site has a private admin area which can connect to third-party accounts — Google Tasks, Microsoft To Do, GitHub, LinkedIn and others. Only the site owner can connect an account. Those connections exist so that one person can manage their own data from one place. If you are reading this as a visitor, none of that section applies to you.
What the site collects from visitors
Page analytics
Visits are counted first-party, in aggregate, and without cookies. What is stored is a daily tally — a date and a counter. No IP address, no device fingerprint, no identifier of any kind is written, so one visit cannot be told from another or traced back to a person. The numbers are indicative, not exact.
The contact form
If you send a message through the contact page, what you typed is stored: name, email address, optional phone number, message and the time it arrived. It is used to reply to you and nothing else. It is never added to a mailing list, never sold, and never shared. Ask at the address below and it will be deleted.
Hosting
The site runs on Vercel and stores data in Google Firebase. Both keep standard server logs of requests, as any web host does.
Connected accounts — Google user data
The admin area can connect the owner's own Google account so that tasks can be read and written from one console rather than several apps. This section describes that, in the detail Google's API Services User Data Policy asks for.
What is requested, and why
https://www.googleapis.com/auth/tasks— to list, create, update, move and complete the owner's own Google Tasks from the admin task board.openidandemail— to confirm which account was connected, so a different account cannot be attached by mistake.
No other Google scope is requested. No Gmail, Drive, Calendar or Contacts access is asked for or held.
How it is stored
The refresh token is encrypted with AES-256-GCM before it is written anywhere. The encryption key lives only in the deployment environment and is never stored alongside the data, so the stored record is ciphertext on its own. Tasks themselves are not copied or cached — they are read from Google when a page is opened and written straight back.
What is never done with it
- It is never sold, rented or transferred to anyone.
- It is never used for advertising, profiling or market research.
- It is never used to train, fine-tune or improve any AI or machine-learning model.
- No human other than the account owner reads it.
Limited Use. This application's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking it
Disconnecting the account in the admin area deletes the stored record. Access can also be withdrawn at any time from your Google account permissions, which takes effect immediately and independently of this site.
Other connected services
Microsoft To Do, GitHub, LinkedIn and the other optional connections are handled the same way: the owner's own account, the narrowest scope that does the job, the credential encrypted at rest, nothing copied that does not need to be, and disconnection available both here and in the provider's own settings.
Children
This site is not directed at children and does not knowingly collect data from anyone under 13.
Changes
If this policy changes, the date at the top of the page changes with it. There is no archive of earlier versions — the page above is the policy in force.
Contact
Questions, corrections, or a request to delete something you sent: ravikishan63392@gmail.com.
