Privacy Policy
What this site and the personal Google tool process.
Short version: this static portfolio has no account, contact form, comment system, or first-party visitor database. Cloudflare serves and protects the site, runs cookie-free Web Analytics, and decodes the published email address. The second half of this page covers a separate personal tool that connects to the operator's own Google account.
Last updated:
Who runs this site
This site is run by Joe Poznanski, an individual working as a principal software engineer in Titusville, Florida, USA. It is a personal portfolio. There is no company behind it, no staff, and no third-party marketing operation.
For any privacy question, correction, or deletion request, use thecontact page. It lists the current direct channels, and it is the right route for anything on this page.
What this website and its host process
This site does not ask visitors to create an account or submit personal information through the site itself.
Concretely, as the site is currently built and deployed:
- The Astro pages are pre-rendered static files.
- There is no contact form, login, account, comment system, advertising pixel, or first-party visitor database.
- The site's own code does not write cookies,
localStorage, orsessionStorage. - Contact happens through direct email or the linked social profiles, on the visitor's initiative.
Cloudflare processes request metadata such as IP address, requested URL, and user-agent to deliver and protect the site.
Cloudflare Web Analytics adds a cookie-free performance beacon. Cloudflare says those metrics do not use cookies or localStorage. The service records performance timing and aggregate dimensions such as page path, referrer host, country, device type, browser, and operating system. Cloudflare controls that processing and its retention under Cloudflare's current documentation and privacy terms. Seethe Web Analytics overview,data origin and collection,dimensions, andCore Web Vitals.
Cloudflare's email-obfuscation script decodes published email addresses in the browser.
If you email the address published on the contact page, that message is delivered to an ordinary mailbox where the operator can read it and decide whether to reply.
Separate from the website
Google account access
This section does not describe the website. It describes a separate, private piece of automation that Joe Poznanski runs for himself, and it is published here because Google requires a reachable privacy policy for any application that requests Google account access.
The tool is single-user personal software. Joe Poznanski authorises his own Google account and is the only person who uses it. It is not offered to other users. No other person authorizes their Google account to the tool.
What it asks for and why
The application requests exactly two scopes, and no others:
https://www.googleapis.com/auth/calendar- The granted scope can view, edit, share and permanently delete calendars the account can access. The personal workflow uses it to inspect and manage the operator's own events.
https://www.googleapis.com/auth/gmail.modify- The granted scope can read, compose and send messages; apply and remove labels; archive messages; move messages to Trash; and restore messages from Trash. It does not allow immediate permanent deletion that bypasses Trash.
The broader https://mail.google.com/ scope is deliberatelynot requested. That broader scope is required for immediate permanent deletion.
How that data is handled
- The operator uses retrieved data for his own calendar and mail tasks.
- The operator does not sell it or use it for advertising.
- The specific content needed for a requested task may be transmitted to the AI API that executes the task.
- That provider processes the transmitted content under its current service terms and retention settings.
- Google's verification guidance treats the Calendar scope as sensitive and
gmail.modifyas restricted, even when the personal workflow uses a narrower subset.
Access tokens are stored on hardware the operator controls. They can be revoked through Google Account permissions.
Revoking access
Because the only authorising account is the operator's own, he can withdraw this application's access at any time, without asking anyone, athttps://myaccount.google.com/permissions. Revocation stops future Google API access.
Retention and deletion
Cloudflare controls retention of request and analytics data under its current documentation and privacy terms.
Ordinary direct-email correspondence remains in the mailbox until the operator manages it. The personal Google automation accesses calendar and mail data to perform the requested task; revocation stops future Google API access.
Children
This is a professional portfolio aimed at an adult audience. It does not ask visitors to submit personal information through the site itself.
Changes to this policy
If the site or the personal Google integration changes in a way that affects any of the statements above, this page is updated and the revision date at the top changes with it. This page describes how things actually work today; it does not describe intentions.
Contact
Questions about this policy go through the contact page. The terms of service cover the rest.