Privacy Policy
Last updated: September 23, 2026
This policy covers allsrc.dev and its sign-in hub, accounts.allsrc.dev, both operated by Shashi Kanth G S (“I”, “me”). It explains what data is collected, why, and how you can control it.
Reading the blog itself requires no account and collects no personal data beyond aggregate, anonymous analytics (see Analytics below). The rest of this page applies if you create an account to comment, save preferences, or use any account-gated feature.
What I collect
If you just read the site: nothing identifying — see Analytics.
If you sign in or sign up (via accounts.allsrc.dev), I collect:
- Email address — always, whether you sign up with email/password or via Google/GitHub.
- Password — only for email/password sign-up. It’s hashed by the authentication provider (Supabase Auth) before storage; I never see or store it in plain text.
- Name and profile picture — only if you sign in with Google or GitHub, pulled from the profile info those providers share with the login.
That’s the complete list. I don’t collect phone numbers, addresses, payment details, or anything beyond what’s needed to keep you signed in and show your name/avatar back to you.
Cookies
allsrc.dev sets exactly one cookie, and only after you actively sign in:
sb-*-auth-token— set by Supabase Auth when you sign in, on the.allsrc.devdomain (shared across allsrc.dev and accounts.allsrc.dev). Purpose: keeps you signed in across the site. Lasts until you sign out or the session expires.
This cookie is strictly necessary — it only exists because you asked to be signed in, and it does nothing else (no tracking, no advertising, no cross-site profiling). Under EU ePrivacy rules, that’s why signing in doesn’t prompt you for cookie consent: consent is only required for cookies that aren’t essential to a feature you explicitly requested.
I don’t use advertising cookies, tracking pixels, or third-party marketing cookies anywhere on the site.
Analytics
allsrc.dev uses Vercel Web Analytics to see aggregate traffic patterns (which pages get read, roughly where visitors come from). It’s cookieless by design — it doesn’t set a cookie or store any identifier tied to you, and I can’t see who you are from it, signed in or not.
Who processes this data
I don’t run my own servers for this. Your data is held by:
- Supabase — hosts the account database and handles authentication (including any Google/GitHub sign-in).
- Vercel — hosts the site and runs the cookieless analytics above.
Both are contracted only to provide their respective service to allsrc.dev — neither is authorized to use your data for their own purposes, and I don’t sell or share your data with anyone else.
How long I keep it
Account data is kept for as long as your account exists. If you’d like your account and associated data deleted, email me (below) and I’ll remove it — there’s currently no self-service delete button, so this is handled by request.
Your rights
If you’re in the EU/EEA or UK, GDPR gives you the right to:
- Ask what data I hold about you
- Correct inaccurate data
- Request deletion of your account and data
- Object to or restrict how your data is used
- Receive a copy of your data in a portable format
To exercise any of these, email me at the address below — I’ll respond within a reasonable time and in any case within 30 days.
Changes to this policy
If what’s collected or how it’s used changes, I’ll update this page and the date at the top.
Contact
Questions about this policy or your data: [email protected]