Privacy Policy
Last updated: March 2026
1. Introduction
This website is a personal website operated by Ricardo Fernández Gasca.
It contains personal writings, technical articles, projects, and an interactive AI assistant designed to answer questions about the content of the site and facilitate communication.
Respecting visitor privacy is an important design principle of this website. Data collection is intentionally minimized and limited to what is necessary to operate the site and its interactive features securely.
This website does not use advertising networks, does not sell personal data, and does not perform behavioral profiling of visitors.
2. Data Collection
Most of the website can be accessed without providing any personal information.
However, some data may be processed in the following situations.
AI Assistant Interaction
The website includes an AI assistant that allows visitors to interact conversationally.
When interacting with the assistant:
- Messages sent by the visitor
- Responses generated by the assistant
- Session metadata (timestamps, session identifier)
may be temporarily processed to generate responses and maintain conversation context.
To maintain system stability and prevent abuse, limited technical metadata may also be processed, including:
- IP address (for rate limiting)
- Session identifiers
- Request timestamps
This information is used strictly for operational and security purposes.
Contact Form
If you voluntarily submit information through the contact form, the following data may be collected:
- Your name
- Your email address
- The content of your message
This information is provided entirely at your discretion.
3. How Data Is Used
Information collected through this website may be used for the following purposes:
- Responding to messages sent through the contact form
- Operating the AI assistant functionality
- Maintaining system stability and preventing abuse (rate limiting and security controls)
- Improving the reliability of the website
Personal data is never sold, never rented, and never used for advertising purposes.
4. Conversation Logs
Interactions with the AI assistant may be stored for operational purposes.
Stored logs may include:
- Conversation history
- Session identifiers
- Timestamps
- Tool interactions performed by the assistant
These logs are used exclusively for:
- debugging
- improving system reliability
- investigating potential misuse
Conversation logs are stored in a private workspace and are not publicly accessible.
Visitors should avoid sharing sensitive personal or confidential information when interacting with the assistant.
5. Data Storage & Infrastructure
This website relies on several external services required for its operation.
These services may process minimal technical information necessary to deliver the website.
Infrastructure services include:
- Vercel — hosting and serverless infrastructure
- Upstash Redis — temporary storage for rate limiting and session counters
- Google AI services — AI model used by the site assistant
- Cloudflare Turnstile — CAPTCHA used to prevent automated abuse
- Notion — content management and private storage of conversation logs
These services may process technical data such as IP addresses as part of their normal operation.
6. Cookies & Tracking
This website does not use advertising cookies.
It does not run third-party tracking scripts or advertising analytics.
Some technical mechanisms may use short-lived identifiers or session tokens to maintain functionality such as:
- chat sessions
- rate limiting
- abuse prevention
These mechanisms are strictly functional and not used for behavioral tracking.
7. Security Measures
The website implements several security controls to protect both the system and its visitors, including:
- request rate limiting
- CAPTCHA verification for new chat sessions
- automated prompt injection detection
- input validation and sanitization
- session expiration mechanisms
These controls help prevent automated abuse, spam, and malicious interactions.
8. Your Rights (GDPR Notice)
If you are located in the European Union, you have the right to:
- request access to personal data concerning you
- request correction of inaccurate data
- request deletion of your personal data
- withdraw consent at any time
Because the website intentionally collects very limited personal data, most visitors will not have identifiable information stored unless they voluntarily submitted a message through the contact form.
Requests regarding personal data can be made through the contact form on this website.
9. Changes to This Policy
This Privacy Policy may be updated occasionally to reflect improvements to the website or new functionality.
The latest version will always be available on this page with the corresponding update date.
10. Contact
If you have questions about this Privacy Policy or about how data is handled on this website, you can contact me through the website contact form.