This policy explains what this website does with information. It describes the site as it is actually built, not as a template imagines it — where the site does nothing in a given category, it says so plainly rather than reserving the right to do it later.
By using the website, you acknowledge the practices described here.
1. About this website
SHUJA // PROTOCOL is a personal portfolio and professional technology website operated by Shuja Abrar.
It presents professional experience, software development projects, blockchain work, smart-contract security research, technical skills, GitHub activity, certifications, publications and related professional information.
2. Information collected from you
The website has no contact form, no sign-up, no comments and no newsletter. There is no way for a visitor to submit personal information through it.
Contact details are published as direct links. Using them — an email address, a GitHub profile, a LinkedIn profile — takes you to that service or opens your own email client, which happens outside this website and under that provider's policies.
The hosting provider processes ordinary technical request data in the course of serving pages, which typically includes:
- IP address
- Browser type and version
- Operating system and device type
- Referring page
- Pages requested, with date and time
- Basic performance and error diagnostics
This is used for security, reliability and debugging. It is handled by the hosting provider under its own policy, and is not combined into a visitor profile here.
3. Cookies and browser storage
No cookies are set for ordinary visitors. There is no cookie banner because there is nothing to consent to.
A session cookie is set in one case only: when the website owner signs in to the restricted administrative area. It exists to keep that session authenticated and is never set for anyone else.
The website does store two small preferences in your own browser:
- Whether interface sound is switched on — remembered between visits
- Whether the start-up animation has already played — remembered for the current browsing session only
Both stay in your browser, are readable only by this website, and are never transmitted anywhere. Clearing site data removes them.
4. Analytics
The website uses no analytics, no tracking pixels, no advertising technology and no third-party scripts of any kind. Fonts are served from this website's own domain rather than a font provider, so loading a page does not tell anyone else that you visited.
If analytics are ever added, this policy will be updated before they are.
5. GitHub information
The website shows development activity drawn from GitHub. A synchronisation process reads the owner's GitHub account using an authorised access token and stores snapshots in this website's own database. Your browser never contacts GitHub on this website's behalf, and no visitor's GitHub information is read.
Stored and displayed information relates solely to the owner's own repositories and may include:
- Repository names, descriptions and topics
- Programming languages and byte counts
- Commit counts and commit subject lines
- Branch names
- Pull request and release metadata
- Contributor counts and repository statistics
- Daily contribution activity
Because the access token is authorised for the owner's account, synchronisation covers private repositories as well as public ones. Whether private repositories are *displayed* is a separate, deliberate setting.
At the time of writing, private repository information is displayed — including repository names, branch names and commit subject lines — so that the portfolio reflects current work rather than only whatever happens to be public. Individual repositories can be, and are, excluded from public display where their contents should not be named.
If you are a client or collaborator and a repository name or commit subject should not appear here, contact the address below and it will be excluded.
6. LinkedIn information
There is no LinkedIn API integration and no LinkedIn authentication. Nothing on this website reads LinkedIn automatically.
Professional information originating from the owner's LinkedIn profile — experience, education, certifications, publications, honours and languages — was transcribed by hand and stored in this website's own database, where each record is labelled with its origin.
Recommendations written by other people are reproduced as they were written, with the author's name and their stated professional relationship, as they appear on the owner's public LinkedIn profile. If you wrote one of these and would like it removed or amended, contact the address below and it will be actioned.
No LinkedIn credentials are collected, and no visitor's LinkedIn information is processed.
7. How information is used
Information available to this website is used to:
- Operate and serve the website
- Display portfolio, career and development activity content
- Keep GitHub snapshots current
- Maintain security and detect abuse
- Diagnose errors and monitor performance
No automated decisions are made about visitors, and no profiling is carried out.
8. Service providers
The website depends on third-party infrastructure, which may include:
- GitHub — source of the development activity shown here
- A hosting provider, for serving the website
- A managed PostgreSQL provider, for the database
These providers process information under their own privacy policies and terms. No information is sold, rented or shared for advertising.
9. Data security
Reasonable technical measures protect the information this website holds, including HTTPS/TLS, a strict content security policy, authenticated access to the administrative area, server-side secret management, cryptographic verification of incoming webhooks, input validation and rate limiting.
No internet transmission or storage system can be guaranteed completely secure, and no such guarantee is made here.
10. Retention
Technical logs held by the hosting provider are retained for a limited period for security and debugging, under that provider's policy.
Portfolio content, including GitHub snapshots, is retained as long as it remains part of the website, and is updated or removed at the owner's discretion.
11. Disclosure
Information may be disclosed where required by law or legal process, or where necessary to protect the security and rights of the website, its operator or others. It is not sold or rented in any circumstances.
12. External links
The website links to third-party services, including GitHub, LinkedIn and project demonstrations. Those services' privacy practices are their own. Review their policies before providing them with personal information.
13. Children's privacy
This is a professional portfolio and is not directed at children. No personal information is knowingly collected from children. If you believe a child has provided information, contact the address below.
14. Your rights
Depending on where you live, you may have rights to access, correct, delete or restrict the processing of your personal information, to object to processing, and to withdraw consent where processing relies on it.
Because this website collects nothing from visitors, most such requests will have nothing to act on. The exceptions are the named recommendations described in section 6 and any repository naming described in section 5 — both of which will be actioned on request.
15. International transfers
Because the website uses infrastructure providers in other countries, information may be processed or stored outside your country of residence. Reasonable measures are taken to handle such transfers in line with applicable requirements.
16. Changes
This policy may be updated to reflect changes to the website, its integrations or applicable law. The effective date at the top of this page changes whenever the substance does.
17. Contact
For privacy questions or requests:
- Shuja Abrar
- Email: shujaabrar7@gmail.com
- Website: http://3.231.211.68