Privacy
Summary (read this)
This is a static, read-only personal site. It does not run analytics, advertising, newsletters, accounts, or databases. No personal data is collected or stored by the site itself. The only way you share data is if you click an email link, which opens your own mail app.
What we do not collect
- No cookies, localStorage, or tracking set by us (theme toggle is in-memory only and resets on reload).
- No analytics (no Google Analytics, Plausible, etc.), no pixels, no A/B tests.
- No forms that POST to a server; no server logs we control.
What happens when you click Email
Links labeled Contact me / email use mailto:. Clicking opens your device's email client and pre-fills the recipient and subject. No data is sent to or stored on this site. The address is assembled in your browser via JavaScript at interaction time to reduce automated harvesting; the raw address does not appear in the static HTML.
Once you send an email, that message is handled by your email provider and Gmail (the recipient inbox). That exchange is governed by those providers' policies. We do not log the click on our server.
Third parties you may contact by clicking out
- LinkedIn — only if you click the LinkedIn link.
- Academia.edu / RemissionRoute — only if you click a publication or project link.
- Google Fonts — the site loads fonts from
fonts.googleapis.com / fonts.gstatic.com. Google may log your IP and user-agent when fetching fonts. No other Google services are used. If you prefer not to contact Google, you can block third-party fonts and the site will fall back to system fonts.
Each outbound site has its own privacy policy.
Hosting & security (no backtracing)
- Hosted on Cloudflare Pages (global CDN, HTTPS only, HSTS, TLS 1.2+). Static assets are served from Cloudflare edge nodes (worldwide) with no origin server you can trace back to a personal device.
- Security headers:
Strict-Transport-Security, X-Content-Type-Options: nosniff, X-Frame-Options: DENY, Referrer-Policy: strict-origin-when-cross-origin, Permissions-Policy: camera=(), microphone=(), geolocation=()and a restrictiveContent-Security-Policy(see/_headers). - No
X-Powered-By, no version leaks, no source maps, no.envor keys in the bundle. - Cloudflare may keep minimal, rotated edge access logs for abuse/security (not used for profiling). We do not receive or process those logs.
Legal bases & your rights (US / Canada / EU / Worldwide)
Canada (PIPEDA) & Quebec Law 25: No personal information is collected via the site; consent is obtained when you voluntarily email us (CASL-implied consent for reply). You may withdraw consent by not emailing.
EU/UK GDPR: No personal data is processed by the site. If you email us, processing is on the basis of legitimate interest (Art. 6(1)(f)) to answer your inquiry and, where applicable, consent (Art. 6(1)(a)). You retain rights of access, rectification, erasure, restriction, objection, and portability — exercise via email.
California / US (CCPA/CPRA + other states): We do not sell or share personal information, do not use sensitive personal information, and do not profile. No opt-out is needed because no such processing occurs. If you email us, we use the content only to reply.
Retention: No data retained by the site. Email correspondence you initiate is retained only as long as needed to reply, then per normal inbox retention.
International transfers: Static files are cached on Cloudflare's global network. Email you send may transit Gmail's infrastructure. By using mailto, you acknowledge that technical routing may involve transfers outside your jurisdiction.
Children
No part of this site is directed to children under 16 and no data is knowingly collected.
Changes
If this policy changes, the Effective date above will be updated. No notice banner is needed as no personal data processing changes.
Contact
Questions about privacy: email Noel. Supervisory authorities (e.g., OPC in Canada, your EU DPA, or California AG) remain available if you believe your rights are affected.