Legal

Privacy Policy

This policy explains how information is handled when you visit anilbhimani.com, read or contribute to the public blog, or use account and social-login features.

Last Updated: September 1, 2026

Introduction

This Privacy Policy applies to the website operated under the Anil Bhimani name at anilbhimani.com and to related requests made to api.anilbhimani.com. It describes the types of information that may be processed, why that information is used, and the choices available to you.

Information We Collect

The information processed depends on how you use the website:

  • Information you provide: profile or account details, blog posts, comments, and other information you choose to submit through available forms or community features.
  • Social-login profile information: details supplied by an OAuth provider, which may include your name, email address, provider account identifier, username, and profile image.
  • Technical and security information: IP address, browser or device information, user-agent data, request timestamps, authentication/session metadata, and security events needed to operate and protect the website.
  • Public content: information you intentionally publish, such as an approved blog article, author display name, or approved comment, may be visible to other visitors.

Social Login / OAuth Information

The blog may let you authenticate through Google, GitHub, Facebook, X/Twitter, or another OAuth provider made available on the sign-in screen. When you choose a provider, that provider authenticates you and returns only the account information permitted by you and made available under the requested scope.

Your provider password stays with your provider.

This website does not collect or receive your Google, GitHub, Facebook, or other OAuth-provider password or login credentials. Authentication is performed by the respective provider. The application uses the resulting provider identity and a local session token to recognize your blog account.

The exact information received can vary according to the provider, its policies, your provider settings, and the permissions you grant. You may revoke the website's access from your provider account settings, although revocation does not automatically erase information already received and retained by this website.

Facebook Login

If you choose Facebook Login, Meta authenticates your account. Depending on the permissions you approve and the information Facebook makes available, this website may receive your public profile information, such as your name, Facebook account ID, profile image, and email address when email permission is granted and an email is available.

This information is used to create or connect your local blog account, display appropriate author information, maintain your authenticated session, and protect the community. The website does not receive your Facebook password and does not post to Facebook on your behalf unless a separate feature and permission are clearly presented to you.

How Information Is Used

Information may be used to:

  • provide public blog content and community features;
  • create, connect, and administer authenticated accounts;
  • display author names, profile images, posts, and approved comments;
  • maintain sessions and remember authentication state;
  • moderate submissions and respond to account or support requests;
  • detect abuse, investigate security events, and protect users and services;
  • debug, maintain, and improve the reliability of the website and API; and
  • comply with applicable legal obligations and enforce website rules.

Cookies and Authentication

The website and API may use essential cookies, session storage, local storage, and server-side session records to complete OAuth flows, maintain authentication, preserve authorized access, and prevent fraud or misuse. For example, a temporary OAuth state value may be maintained during provider authentication, while a local blog session token may be stored in your browser's session storage.

These mechanisms are functional and security-related. Blocking or clearing them may sign you out or prevent authentication and protected features from working correctly. This policy does not represent that analytics or advertising cookies are in use where such systems have not been implemented.

Data Sharing

Information may be shared only as reasonably necessary with:

  • OAuth providers when you initiate or manage social login;
  • hosting, infrastructure, security, and technical service providers that help operate the website and API;
  • authorities or other parties when required by law, to protect rights and safety, or to investigate fraud or security threats; and
  • other visitors when you intentionally publish content through public blog features.

Personal information is not offered for sale. Service providers may process information only for operational purposes connected with the services they supply.

Data Retention

Information is retained for as long as reasonably necessary to provide the relevant account or blog feature, maintain security, resolve disputes, enforce agreements, and meet applicable legal obligations. Retention periods vary by data type. Session records may expire automatically, while published content, moderation records, security logs, and records needed to document requests may be kept for longer where there is a legitimate operational, safety, or legal need.

When information is no longer needed, reasonable steps are taken to delete, anonymize, or securely isolate it, subject to backup cycles and legal requirements.

Data Security

Reasonable administrative and technical safeguards are used to protect information, including limited API access, session-token controls, expiration, and security logging. No internet service or storage system can guarantee absolute security, so users should also protect their provider accounts and sign out on shared devices.

User Rights and Choices

Depending on your location, you may have rights to request access to, correction of, deletion of, restriction of, or a copy of certain personal information, and to object to particular processing. You may also:

  • sign out and clear website data stored by your browser;
  • revoke social-login access in your OAuth provider settings;
  • choose not to publish blog content or comments; and
  • request account or data deletion as described below.

A request may require reasonable identity verification. Some information may be retained where required for security, legal compliance, fraud prevention, or the protection of others' rights.

Account and Data Deletion

You may request deletion of your account and information associated with a Google, GitHub, Facebook, X/Twitter, or other supported social-login identity. Use the current contact method available on this website and state that you are requesting social-login account deletion. Include the provider you used and enough information to locate and verify the account; do not send your provider password.

After verification, the request will be reviewed and eligible profile, provider-association, and session information will be deleted or de-identified. You may be asked whether public posts or comments should also be removed or anonymized. Limited records may be retained when necessary for legal compliance, security, abuse prevention, dispute resolution, or to document completion of the request.

Facebook data deletion

Facebook users may follow the same process to request deletion of information received through Facebook Login. You can also remove this website from the Apps and Websites section of your Facebook settings to revoke future access. Removing the app from Facebook does not by itself delete data previously received by this website, so submit a deletion request through the website's contact method if you also want locally held account information removed.

Third-Party Services

OAuth providers and infrastructure providers operate under their own terms and privacy policies. This website may also link to independent third-party websites. Their handling of information is controlled by their policies, not this one. Review the privacy settings and policies of Google, GitHub, Meta/Facebook, X/Twitter, or any other provider you choose before authorizing access.

Children's Privacy

This website and its account features are not directed to children under 13, and personal information is not knowingly collected from children under 13. If you believe a child has provided personal information, use the contact method below so the matter can be reviewed and appropriate action taken.

Changes to This Privacy Policy

This policy may be updated as the website, its providers, or applicable requirements change. The revised version will be posted on this page with an updated “Last Updated” date. Material changes may also be highlighted through an appropriate website notice.

Contact

For privacy questions, rights requests, or account/data deletion, use the current contact method provided on the Anil Bhimani website. Please describe your request clearly and identify the social-login provider involved, if applicable. Never send an OAuth-provider password or other private login credentials.

Go to the website contact section