Effective date:
ririum (https://riri.my/) is a personal website and personal project. It is not operated as a commercial service, online store, or customer platform. Nothing on this website should be understood as creating a business relationship, customer account, advice, or ongoing service obligation between me and visitors. This website is provided on an as-is and as-available basis to the extent permitted by applicable law.
I care about privacy and keep data collection to a minimum. This Privacy Policy explains what information may be processed when you use this website.
What I collect
I do not use analytics services, advertising trackers, profiling tools, or third-party tracking cookies on this website.
When you visit the website, the server may automatically create access logs. These logs may include technical data such as your IP address, date and time of access, requested URL, referrer, browser or user-agent information, response status, and similar server-level metadata.
If you submit a comment or guestbook message, I may process the name you enter and the content of your submission so it can be reviewed, displayed, moderated, administered, and deleted where applicable.
For comments submitted on or after July 26, 2026, the website creates a unique deletion credential associated with the submission. A corresponding self-service deletion link is displayed immediately after successful submission. The deletion credential is used only to authorize deletion of the associated comment and is not used for analytics, advertising, profiling, or visitor tracking.
If captcha verification fails during comment submission, I may create a temporary PHP session token, stored as a session cookie, so your comment text can be preserved and you do not have to retype it. This session is used only for that functional purpose and not for analytics, advertising, or profiling.
If you choose to contact me by sending an email directly to the address published on this website, I will receive whatever information you include in that email and any associated email metadata needed to receive and respond to it.
What I do not use
- Analytics cookies.
- Advertising cookies.
- Third-party tracking cookies.
- Behavioral profiling tools.
- Newsletter signup forms.
Why I process data
I process limited data only where necessary to operate the website and its basic features. This includes:
- Serving pages and media.
- Maintaining security and stability.
- Detecting abuse, spam, and malicious activity.
- Troubleshooting technical issues.
- Displaying, moderating, managing, and enabling the deletion of comments and guestbook messages.
- Generating and validating deletion credentials for comments submitted on or after July 26, 2026.
- Preserving comment text temporarily if captcha verification fails.
- Reading and replying to emails sent directly to me.
Grounds for processing
Privacy laws differ between jurisdictions. Where applicable law requires a grounds for processing for processing personal data, the applicable basis may include:
- Your voluntary submission of a comment or guestbook message for review and public display.
- Your voluntary decision to contact me and the need to receive and respond to that correspondence.
- My legitimate interests in operating, securing, maintaining, moderating, and protecting the basic functionality of this personal website.
Submitting a comment, guestbook message, or email is optional.
Cookies and session data
This website does not use analytics cookies, advertising cookies, or third-party tracking cookies. A temporary essential session token may be used during comment submission to support captcha retry and comment recovery. This session mechanism is functional and short-lived, not a tracking system.
Retention
By default, access logs are kept for up to 5 (five) days and are then automatically deleted. Logs may be purged manually earlier at my discretion.
PLEASE BE AWARE: While access logs on my server instances are short-lived, Oracle Cloud and your internet service provider may independently process technical connection data under their own policies and legal obligations. I do not control their independent logging or retention practices.
A log entry looks something like this on my end:
87.xxx.xxx.xxx - - - [1778014230.477 (05/May/2026:22:50:30 +0200)]
"GET / HTTP/3.0" 200 3934 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)
AppleWebKit/537.36 (KHTML, like Gecko)
Chrome/147.0.0.0 Safari/537.36 Edg/147.0.0.0" host="-" sni="riri.my"
scheme=https request_time=0.000 cache=- ssl=TLSv1.3upstream_time=-
upstream_addr=- upstream_status=- bytes_in=463 pipe=.conn=5 conn_requests=1
Temporary session data used during comment submission is kept only for as long as necessary for that purpose. It may consist of a short-lived session cookie stored in your browser together with corresponding server-side session data.
Comment form data is retained only as necessary to process the current submission or captcha retry. The associated session expires automatically or is deleted after successful submission.
If a submission is successful, the comment is stored for moderation and, once approved, displayed publicly on the relevant page. For comments submitted on or after July 26, 2026, the associated deletion credential remains valid for as long as the comment remains available and is permanently invalidated when the comment is deleted.
Comments may remain stored and publicly visible for as long as the relevant post, guestbook, or website remains available. They may be removed earlier by a person holding a valid deletion link or by me for moderation, privacy, legal, security, technical, or administrative reasons.
When deletion is confirmed through a valid deletion link, the comment is removed from the live website and active comment database. A residual copy may remain temporarily in an existing backup until that backup is replaced or deleted.
If you email me directly, I may retain the email for as long as reasonably necessary to handle the correspondence, keep records of the exchange, or protect against abuse.
Comments
In this policy, “comments” include both comments submitted underneath individual blog posts, referred to on this website as “diary” posts, and messages submitted through the guestbook page.
Comments are public and may display the name you provide together with the comment text. Please do not submit sensitive, confidential, or unnecessary personal information.
The comment system does not require an account or email address. The active comment database does not store an IP address, email address, user account, or another persistent identity marker alongside a comment. Server access logs are stored separately, are short-lived, and are maintained for technical and security purposes rather than to identify commenters or establish ownership of comments.
For comments submitted on or after July 26, 2026, a unique self-service deletion link is displayed immediately after successful submission. The link is displayed only once, and the website does not provide a way to display or recover it later.
Opening a valid deletion link displays the associated comment and asks for confirmation before deletion. Possession of the link is treated as sufficient authorization to delete the corresponding comment, and no additional identity verification is required.
Anyone who obtains a valid deletion link may be able to delete the associated comment. You should therefore keep the link private and store it securely if you may wish to delete the comment later. After deletion is confirmed, the comment is removed and the link is permanently invalidated.
Comments submitted before July 26, 2026, do not have deletion links. If your request concerns an older comment, or if you have lost a deletion link, you may contact me using the address below.
I will review the request and may ask for information reasonably necessary to identify the relevant comment and assess whether the request is genuine. Because comments are not connected to accounts, email addresses, or persistent identity markers, I may be unable to fulfill a request where the relevant comment or authorship cannot reasonably be identified or verified.
I do not collect or retain additional identifiers solely to make future verification of comment ownership possible.
Data storage
Website content, submitted comments, deletion credentials, temporary comment-session data, and server access logs are hosted on servers in Italy using Oracle Cloud, a United States-based hosting and infrastructure provider.
Oracle Cloud may process limited technical and hosting data as necessary to provide infrastructure, storage, networking, security, and related services.
To operate, moderate, maintain, and back up the website, limited website data may also be accessed or temporarily stored on my local devices outside Italy and, depending on my location, in a country different from the country in which you are located.
Because this website may be accessed internationally, data may be processed in a country different from the country in which you are located. I use reasonable technical and organizational measures to protect the limited data involved.
If the website’s primary hosting location changes, this policy will be updated accordingly.
Sharing and service providers
I do not sell personal data or use it for advertising, behavioral profiling, or third-party marketing.
I use Oracle Cloud as the website’s hosting and infrastructure provider. Oracle Cloud may process limited data where necessary to provide hosting, networking, storage, security, and related technical services.
If you contact me by email, the email providers (both your and mine) and network services involved in delivering and storing the message may process its contents and associated metadata as necessary to provide those services.
Information may be disclosed where reasonably necessary to comply with an applicable and valid legal obligation, respond to abuse, fraud, spam, or malicious activity, investigate or address a security incident, protect the website, its operator, visitors, or other persons, or establish, exercise, or defend a legal claim.
Your rights
Depending on your location and the laws that apply, you may have rights concerning personal data that relates to you. These may include rights to request access, correction, deletion, restriction, objection, or a copy of certain data. These rights may be subject to applicable legal, technical, and verification requirements.
For comments submitted on or after July 26, 2026, you can independently delete the comment by using the unique deletion link displayed immediately after successful submission. Opening the link allows you to review the associated comment before confirming deletion. Possession of a valid link is treated as sufficient authorization, and no additional identity verification is required.
The link is displayed only once, and the website does not provide a way to display or recover it later. If you lose the link, or if your request concerns a comment submitted before July 26, 2026, you may contact me using the address below.
Because comments do not require an account, email address, or persistent identity marker, I may not always be able to identify particular data as belonging to you or verify that a request comes from the original commenter. I may ask you to provide information reasonably necessary to identify the relevant comment, data, or correspondence and to protect other visitors against unauthorized access, alteration, or deletion.
I do not collect or retain additional personal information solely to make future identity verification possible. If you provide sufficient information to allow the relevant data and request to be reasonably identified, I will review the request in accordance with applicable law. If the relevant data or authorship cannot reasonably be identified or verified, I may be unable to fulfill it.
Depending on your jurisdiction, you may also have the right to contact or lodge a complaint with the data protection or privacy authority responsible for your location.
Security
I take reasonable technical and organizational measures to protect this website and the limited data processed through it.
Deletion links function as private authorization credentials. Anyone who obtains a valid deletion link may be able to delete the associated comment. Deletion credentials are used only for that purpose and are permanently invalidated when the corresponding comment is deleted.
Connections to this website are encrypted in transit where supported by the visitor’s browser, device, and network. Specific transport technologies or protocol versions may change over time as part of normal operation and maintenance, so they are not guaranteed as a permanent feature. HTTP/3, QUIC, and TLS 1.3 are transport and security technologies, but they are operational details disclosed for transparency.
Contact
This website is owned and operated by one individual under the public identity used on this website.
For privacy-related questions or requests, you can email me at: ri [@] riri [.] my
Please include enough information for me to understand your request and, where relevant, identify the affected comment, message, or other data.
Changes
I may update this Privacy Policy from time to time by publishing a revised version on this page. Changes become effective when the revised version is published, unless otherwise stated.
Last updated:




