Privacy Policy
Last updated: August 31, 2026
This Privacy Policy describes how Nkengbeza Blog ("we", "us", or "our") collects, uses, and protects information when you visit or interact with this blog. By using the site — including creating an account, leaving a comment, or using the contact form — you acknowledge the practices described here.
1. Information We Collect
1.1 Account Registration
When you create an account, we collect:
- Name — displayed publicly on comments and your profile.
- Email address — used to identify your account and send password-reset emails. Never displayed publicly.
- Password — stored as a one-way cryptographic hash (bcrypt). We cannot read your password.
- Theme preference — stored to remember your chosen display theme across visits.
- Registration timestamp — recorded for account security purposes.
You may optionally add a bio, website URL, and social media usernames (GitHub, LinkedIn, Twitter) to your public profile. These are entirely optional and displayed only if you provide them.
1.2 Social Login
If you sign in via a third-party OAuth provider (GitHub, Google, Facebook, GitLab), we receive:
- Your name and email address as supplied by that provider.
- A provider-specific user ID to link your account.
- Your provider profile avatar (used only as a display fallback).
- A temporary access token, stored securely and used only to authenticate the session.
We do not request access to your contacts, posts, files, or any permissions beyond basic profile information. The OAuth provider's own privacy policy governs how they handle your data.
1.3 Comments
When you post a comment, we store:
- The comment text you submit.
- A reference to your account (name displayed publicly).
- The date and time of submission.
Comments are held for moderator review before they appear publicly. We reserve the right to decline or remove comments that violate our Terms of Use.
1.4 Contact Form
Messages sent via the contact form include the name, email address, and message body you provide. This information is used solely to respond to your inquiry.
1.5 Usage Data
We automatically collect standard server-log data when you visit pages: IP address, browser type, operating system, referring URL, pages viewed, and timestamps. This data is used in aggregate to understand site traffic and is not linked to individual identities.
2. How We Use Your Information
- Account management — to create and secure your account, send password-reset emails, and let you manage your profile.
- Comments — to moderate, display, and associate comments with the correct author.
- Contact responses — to reply to messages you send us.
- Site improvement — to understand which content is useful and how to improve the reading experience.
- Security — to detect and prevent abuse, spam, and unauthorised access.
We do not sell, rent, or share your personal data with third parties for marketing purposes.
3. Cookies & Local Storage
We use a small number of strictly necessary cookies and browser storage mechanisms:
- Session cookie — a secure, HTTP-only cookie that keeps you logged in during your browser session. It expires when you close your browser or log out.
- CSRF token — a short-lived cookie used to protect form submissions from cross-site request forgery attacks.
- Remember-me cookie — set only if you tick "Remember me" at login. Allows your session to persist for up to two weeks.
- Theme preference — stored in
localStorage(not a cookie) so your chosen theme is applied immediately on page load, even before a server response. - Sidebar state (admin users only) — whether the admin sidebar is expanded or collapsed, stored in
localStorage.
We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies that identify you personally.
4. Third-Party Services
- Gravatar — if you have no uploaded avatar, a default image is requested from Gravatar using a hash of your email address. Gravatar's privacy policy applies to that request.
- OAuth providers — GitHub, Google, Facebook, and GitLab if you use social login (see §1.2).
- Google Fonts — font files are loaded from Google's CDN. Google may log the request; see Google's privacy policy for details.
5. Data Retention
- Account data — retained for as long as your account is active. You may request permanent deletion at any time (see §6).
- Comments — retained indefinitely as part of the public record of a post. If your account is deleted, comments may be anonymised rather than removed, preserving discussion context.
- Contact form messages — retained only as long as necessary to resolve your inquiry, then deleted.
- Server logs — retained for up to 90 days for security monitoring, then purged.
6. Your Rights
Depending on your jurisdiction (including GDPR in the EU/UK and similar legislation elsewhere), you may have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — update inaccurate or incomplete information via your profile settings.
- Deletion — request that your account and associated personal data be permanently deleted.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing in certain circumstances.
To exercise any of these rights, please contact us via the contact page. We will respond within 30 days.
7. Security
We apply reasonable technical safeguards including password hashing (bcrypt), HTTPS-only transport, CSRF protection on all forms, and rate limiting on authentication endpoints. However, no system is completely secure. Please use a strong, unique password and do not share your credentials.
8. Children's Privacy
This blog is not directed at children under 13. We do not knowingly collect personal data from anyone under 13. If you believe a child has submitted information to us, please contact us and we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. The "last updated" date at the top of this page reflects when material changes were last made. Continued use of the site after an update constitutes acceptance of the revised policy.
10. Contact
If you have questions or concerns about this Privacy Policy, please reach out via the contact page.