Privacy Policy
1. Overview
At Technology Blog (operated by Austin Software Services LLC), we believe in software engineering transparency, user control, and data minimization. This Privacy Policy explains what personal information we collect, why we collect it, how it is handled, and how you can exercise your privacy rights.
We do not sell personal information, and we do not engage in behavioral advertising networks.
2. Information Users Provide
Depending on how you interact with the Platform, you may provide us with:
- Identity & Profile Information: Your name, display name, email address, profile picture URL, and professional author biography when creating or updating an author profile.
- User Contributions: Articles, draft submissions, markdown bodies, architecture diagrams, code snippets, tags, categories, and technical comments that you publish or submit for review.
- Preferences & Bookmarks: Saved articles, reading lists, theme preferences (light/dark mode), and text-to-speech audio speed settings.
- Communications: Inquiries, feedback, bug reports, and copyright notices sent to our team.
3. Authentication Provider Information & Scopes
You may sign in using third-party identity providers (Google, GitHub, LinkedIn) or registered email. We strictly follow the principle of least privilege and request only the minimum OAuth scopes necessary to authenticate you:
- Google: OpenID Connect profile and email (
openid,email,profile). - GitHub: Basic public user profile and primary verified email address (
read:user,user:email). - LinkedIn: Standard OpenID profile and email address (
openid,profile,email).
4. Automatically Collected Information
When you browse or interact with Technology Blog, our servers automatically record standard operational telemetry:
- HTTP Logs: IP address, user-agent string (browser and operating system type), request timestamp, HTTP status code, and referring page.
- Security & Audit Logs: Authentication events, failed login attempts, OAuth state validation results, and rate limit triggers to prevent brute-force attacks and abuse.
- Performance Telemetry: Latency metrics, Cloud Run instance health indicators, and error traces.
6. How Information Is Used
We use collected information exclusively to operate and protect the Platform:
- Authenticate your identity and manage role-based authoring permissions.
- Publish, format, index, and serve technical articles, author bylines, and reader comments.
- Enable editorial review workflows between authors, editors, and publishers.
- Protect against automated scraping, spam bots, denial-of-service attacks, and security vulnerabilities.
- Troubleshoot application errors and optimize system response times.
- Communicate vital platform updates, security alerts, or editorial notifications.
7. Data Sharing (No Sale of Personal Information)
We only share necessary operational data with vetted infrastructure sub-processors essential to delivering the Platform:
- Cloud Infrastructure: Google Cloud Platform (Cloud Run, Cloud DNS, Firestore, and Secret Manager) located within secure United States data centers.
- Identity Providers: Google, GitHub, and LinkedIn for processing authentication callbacks that you initiate.
- Monitoring & Reliability: Cloud Logging and Cloud Monitoring for diagnostic tracing and uptime verification.
8. Legal & Security Disclosure
We may disclose personal information only when strictly necessary to:
- Comply with a valid subpoena, court order, or enforceable governmental demand.
- Enforce our Terms of Use or investigate potential malicious violations.
- Detect, prevent, or address fraud, security breaches, or technical platform emergencies.
- Protect the legal rights, safety, or property of Austin Software Services LLC, our users, or the public.
9. Data Retention
We retain personal data according to clear operational timelines:
- User Profiles & Published Content: Retained for the active lifetime of your account or until you request deletion.
- Article Drafts & Bookmarks: Retained while your account is active.
- Audit & Access Logs: Retained in Cloud Logging for up to 30 days for forensic security analysis and performance monitoring, after which they are automatically purged.
- Policy Acceptance Records: Retained to verify compliance with applicable legal agreements.
10. Account Deletion & Data Export
You have full control over your data. You may request account deletion or an export of your published articles and profile data at any time:
- Submit a deletion request to privacy@austinss.com using your registered email address.
- Upon verification, your user profile and private drafts will be permanently removed from active Firestore databases within thirty (30) days.
- Published articles can either be removed or anonymized (author byline replaced with a neutral attribution) upon your written preference, preserving public reference links.
11. Security Measures
We employ robust, modern security safeguards designed to protect your information:
- All web traffic is encrypted in transit using Transport Layer Security (TLS 1.3 / HTTPS).
- Data stored in Google Cloud Firestore is encrypted at rest using industry-standard AES-256 keys.
- Session cookies use strict
HttpOnly,SameSite=Lax, andSecureflags. - OAuth secrets and administrative credentials are stored exclusively in Google Cloud Secret Manager and never committed to source repositories.
- Automated vulnerability scanning, Cosign container signing, and Syft SBOM generation are embedded in our continuous delivery pipelines.
12. Children's Privacy
Technology Blog is a technical and enterprise engineering publication intended for professional developers, architects, and students. The Platform is not directed to individuals under the age of 13 (or 16 in the European Economic Area). We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal data, please contact privacy@austinss.com for prompt deletion.
13. International Visitors
Our services and databases are hosted primarily within the United States. If you access Technology Blog from the European Union, United Kingdom, Canada, or other jurisdictions, your personal information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your home country.
14. Your Privacy Rights (GDPR & State Privacy Laws)
Depending on your location (such as the European Union, United Kingdom, California, Texas, and other jurisdictions), you may have the following statutory privacy rights:
- Right of Access & Portability: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate profile data.
- Right to Erasure ("Right to Be Forgotten"): Request permanent deletion of your personal data.
- Right to Restrict or Object to Processing: Object to specific types of processing.
- Right to Non-Discrimination: We will never discriminate against you, deny services, or alter experience levels for exercising your legal privacy rights.
To exercise any of these rights, please email us directly at privacy@austinss.com. We will respond within thirty (30) days.
15. Changes to This Privacy Policy
We may periodically update this Privacy Policy to reflect technical enhancements, architectural updates, or regulatory developments. When updates are published, we will revise the "Last Updated" date at the top of this document. Material changes will be highlighted with a notice on the Platform or communicated via email to registered authors.
16. Contact Information
For questions, privacy requests, or data protection concerns regarding this Privacy Policy, please contact our Privacy Team:
Company: Austin Software Services LLC
Platform: Technology Blog
Privacy Contact: privacy@austinss.com
Support & Legal: admin@austinss.com
Address: Austin, Texas, United States