Privacy Policy
Last Updated: December 26, 2025
1. Introduction
Welcome to iscovici.com. This privacy policy explains how I, Ori Iscovici ("I", "me", or "my"), collect, use, and protect your personal data when you visit this website. This is a personal portfolio and creative coding showcase, not a commercial service.
I am committed to protecting your privacy and ensuring transparency about data processing. This policy complies with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Data Controller
The data controller responsible for your personal data is:
Name: Ori Iscovici
Email:
Website: https://iscovici.com
If you have any questions about this privacy policy or wish to exercise your data protection rights, please contact me at the email address above.
3. What Data We Collect
3.1 Analytics Data (with your consent)
When you consent to analytics cookies, we collect the following data via Google Analytics 4:
- Anonymized IP addresses: Your IP address is anonymized before processing
- Browser and device information: Browser type, version, operating system, screen resolution
- Usage data: Pages visited, time spent on pages, navigation patterns
- Referral source: Where you came from to reach this site
- Geographic location: Country and city-level location (approximate)
3.2 Local Storage Data (strictly necessary)
We store the following data locally in your browser using localStorage. This data is used to remember your preferences between visits and enhance your experience:
- Cookie consent preferences: Your choices regarding analytics and marketing cookies (stored with timestamp)
- Experiment settings: Configuration values for interactive experiments (e.g., NeoMorphic Design Playground colors, shadow settings, light direction)
- UI state: Drawer positions, expanded/collapsed states, and other interface preferences
Important: This data never leaves your device and is not transmitted to any server. You can clear this data at any time by:
- Using the "Reset to Defaults" buttons in each experiment
- Clearing your browser's localStorage for this site
- Using your browser's privacy/incognito mode
3.3 Camera Access (with explicit permission)
Some interactive experiments (Kaleidoscope and Game of Life) request access to your camera. Important facts:
- Camera access requires your explicit browser permission each time
- All camera processing happens locally in your browser using client-side JavaScript
- No camera images or video are ever stored, recorded, or transmitted to any server
- You can revoke camera access at any time in your browser settings
3.4 Server Logs (legitimate interest)
Our hosting providers (Vercel and Cloudflare) automatically collect standard server log data:
- IP addresses (for security and performance monitoring)
- Request timestamps
- HTTP headers (User-Agent, Referer)
- Resource paths accessed
This data is collected automatically for security, performance optimization, and technical troubleshooting. It is retained according to the hosting providers' data retention policies.
4. Legal Basis for Processing
Under GDPR Article 6, we process your personal data based on the following legal grounds:
- Consent (Article 6(1)(a)): Analytics cookies and tracking via Google Analytics - you can withdraw consent at any time
- Legitimate interests (Article 6(1)(f)): Server logs for security, fraud prevention, and technical operations
- Technical necessity: localStorage for essential site functionality and user experience preferences
5. How We Use Your Data
We use collected data for:
- Analytics and improvement: Understanding how visitors use the site to improve content and user experience
- Technical functionality: Maintaining your preferences across sessions
- Security: Detecting and preventing abuse, unauthorized access, and technical issues
- Performance optimization: Improving site loading speed and reliability
We do not use your data for marketing, advertising, or profiling purposes.
6. Third-Party Data Processors
6.1 Google Analytics & Google Tag Manager
- Purpose: Website analytics and tag management
- Data collected: Anonymized usage data, device information, anonymized IP addresses
- Legal basis: Consent (you can opt out via cookie settings)
- Data location: United States (Google LLC) with Standard Contractual Clauses
- Privacy policy: https://policies.google.com/privacy
- Configuration: IP anonymization enabled, advertising features disabled
6.2 Vercel (Hosting)
- Purpose: Website hosting and delivery
- Data collected: Server logs, IP addresses, technical request data
- Legal basis: Legitimate interest (technical necessity)
- Data location: United States (Vercel Inc.) with appropriate safeguards
- Privacy policy: https://vercel.com/legal/privacy-policy
6.3 Cloudflare R2 (CDN for Images)
- Purpose: Content delivery network for images (images.iscovici.com)
- Data collected: IP addresses, access logs for image resources
- Legal basis: Legitimate interest (performance and security)
- Data location: Global network with data centers worldwide
- Privacy policy: https://www.cloudflare.com/privacypolicy/
7. International Data Transfers
Some of our third-party processors (Google Analytics, Vercel) are located in the United States. Data transfers to the US are protected by:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- The EU-U.S. Data Privacy Framework for qualifying organizations
- Additional technical and organizational security measures
Cloudflare operates a global network and processes data in various locations, always maintaining GDPR compliance.
8. Data Retention
- Google Analytics data: Automatically deleted after 14 months
- Server logs (Vercel/Cloudflare): Retained for 30-90 days for technical operations
- LocalStorage data: Persists until you clear your browser data or uninstall your browser
- Cookie data: See our Cookie Policy for specific retention periods
9. Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
9.1 Right of Access (Article 15)
You have the right to request confirmation of whether we process your personal data and, if so, to access that data and receive information about the processing.
9.2 Right to Rectification (Article 16)
You have the right to request correction of inaccurate personal data and to have incomplete data completed.
9.3 Right to Erasure / "Right to be Forgotten" (Article 17)
You have the right to request deletion of your personal data when:
- The data is no longer necessary for its original purpose
- You withdraw consent and there is no other legal basis
- You object and there are no overriding legitimate grounds
- The data was unlawfully processed
9.4 Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
9.5 Right to Object (Article 21)
You have the right to object to processing based on legitimate interests. We will stop processing unless we demonstrate compelling legitimate grounds that override your interests.
9.6 Right to Withdraw Consent (Article 7)
Where processing is based on consent, you have the right to withdraw that consent at any time. You can manage cookie consent through the cookie banner or browser settings.
9.7 Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your habitual residence, place of work, or place of the alleged infringement.
10. Data Security
I implement appropriate technical and organizational measures to protect your personal data:
- Encryption: All data transmission uses HTTPS/TLS encryption
- IP Anonymization: Google Analytics anonymizes IP addresses before processing
- Access Controls: Limited access to server infrastructure and analytics
- Regular Updates: Dependencies and security patches kept current
- Minimal Data Collection: We only collect what is necessary
- Trusted Processors: Only reputable, GDPR-compliant service providers
11. Children's Privacy
This website is not directed at children under 16 years of age. I do not knowingly collect personal data from children. If you believe a child has provided personal data, please contact me, and I will promptly delete such information.
12. Links to Third-Party Websites
This website may contain links to external websites (such as GitHub, LinkedIn, Instagram). I am not responsible for the privacy practices or content of these third-party sites. Please review their privacy policies before providing any personal data.
13. Changes to This Privacy Policy
I may update this privacy policy from time to time to reflect changes in my practices or for legal, operational, or regulatory reasons. The "Last Updated" date at the top of this page indicates when the policy was last revised.
Material changes will be communicated through a notice on the website or via email if I have your contact information.
14. Contact Information
If you have any questions, concerns, or requests regarding this privacy policy or the processing of your personal data, please contact me:
Email:
Website: https://iscovici.com
Response time: I will respond to your inquiry within 30 days as required by GDPR
15. Additional Resources
- Cookie Policy - Detailed information about cookies used on this site
- GDPR Official Resource - Learn more about your data protection rights
- Google Analytics Opt-out Browser Add-on - Opt out of Google Analytics across all websites
Summary: This website collects minimal personal data, primarily for analytics (with your consent) and technical operations. You have full control over your data and can exercise your GDPR rights at any time by contacting . Camera access is optional, client-side only, and never stored or transmitted.