Claude is having a major outage. Status board · Discuss Claude

Privacy Policy

KEH-TECH (keh-tech.net) is a knowledge base, news site and community forum for IT people. It is a personal project run by Karl E. Henry (“we”, “us”). This page explains what information the site collects, why, and what you can do about it. The short version: we collect what is needed to run a forum and keep it free of spam, we do not run ads, the only analytics we keep counts page views and identifies nobody, and we do not sell anyone’s data.

What we collect

When you just read the site

You can read the knowledge base, news and forum without an account. Like every web server, ours keeps short-lived logs of requests: IP address, browser type, the page requested and the time. Our security software also looks at this information to block attacks. We do not use it to build profiles of readers.

When you create an account

We store the username and email address you give us and a scrambled (hashed) version of your password, which we cannot read. Your email address is never shown publicly. Anything you add to your profile, such as a display name, avatar, signature or links, is optional and is public.

When you sign in with Google

Signing in with Google is optional. You can always create an account with an email address and password instead, and nothing on the site requires a Google account.

If you do use it, we ask Google for two basic permissions, email and profile, and Google sends us four things: your Google account ID, your name, your email address, and the web address of your Google profile picture. That is the whole of it.

We keep the account ID so we can recognise you next time, together with your name, email address and profile picture, and the dates you first connected and last signed in. We do not show your Google name: you are given a generated display name, which you can change on your forum account page.

We never see your Google password. We do not ask for, and cannot read, your Gmail, contacts, calendar, Drive or anything else in your Google account. We do not keep an access token after you sign in, so this site cannot do anything on your behalf at Google.

You can disconnect Google from your account on your profile page, or ask us to do it, and you will still be able to sign in with your email address and password. Deleting your account removes the connection along with everything else.

When you post

Forum topics, replies and comments are public and can be found by search engines. We store the content, the time, and the IP address it was posted from. IP addresses are visible only to the site’s administrators and moderators and are used to fight spam and abuse. Please do not post passwords, license keys, or private details about yourself, your employer or anyone else. Remove them from logs and screenshots before you share them.

When you contact us

The contact form sends us your name, email address, message and IP address by email. We use them only to deal with your message. The form does not save messages in the website’s database.

When you use the Shell Lab

The Shell Lab runs entirely in your browser. The commands you type, the files you create in it and the scripts you write stay in your browser tab and are never sent to us. So that your progress follows you between devices, we store which exercises you have completed with your account, and when you last completed one. Your Shell Lab progress, and the mascots that grow with it, are shown on your forum profile, beside your forum posts and on the Top of the Stack leaderboard, where other members can see them. You can keep yourself off Top of the Stack from your forum account page. Your browser also keeps a copy of your progress and any script you are writing in its local storage, so the lab opens where you left off.

When you practise or follow a learning path

If you answer practice exam questions while signed in, we store with your account which questions you answered, whether your latest answer to each was right, how many times you have tried it, and when. If you tick off steps on a learning path, we store which steps you ticked. Lab exercises and practice questions on a path tick themselves from the progress described above. Your practice scores and how many learning paths you have finished are shown on your forum profile, where other members can see them, and you can clear your answers for any exam from its practice page. If you are not signed in, your answers are checked but not stored.

When you use the tools

The admin utility belt and the subnet calculator run entirely in your browser: nothing you type into them is sent to us. The DNS and email check, the certificate checker and the IP owner lookup run on our server, which looks up only the domain, hostname or address you enter. Results are cached for a few minutes so a repeat lookup is quick, and are not linked to you. The IP owner lookup asks Team Cymru’s public IP-to-ASN service, over DNS, which network an address belongs to; it only runs when you press the button. “What’s my IP” shows you the address your request came from and does not store it. To stop the tools being overused, we count lookups per visitor for a few minutes using a one-way hash of your address, never the address itself.

Certificate reminders. If you are signed in and choose “Watch this certificate”, we store the hostname and port with your account, with the date you added it, when we last checked it, the certificate’s expiry date, whether it was trusted, and whether we have emailed you about it. Our server checks each watched certificate once a day and emails you at 30, 14 and 7 days before it expires, when it expires, and if it stops being trusted. You can watch up to ten. Remove one on the certificate checker page, or with the “Stop watching” link in any reminder, and it is deleted; deleting your account deletes them all. They are included when you ask for a copy of your data or ask us to erase it.

Cookies

We use only the cookies needed to run the site:

  • Login cookies keep you signed in. They last for two days, or one week if you choose “Remember Me” or sign in with Google, and are removed when you log out.
  • Forum cookies remember things like which topics you have read. Opening the forum, signed in or not, also sets wpforo_browser_timezone, which holds only your time zone so post times show in your local time; it lasts a day.
  • Comment cookies, if you tick the box when commenting, remember your name and email for next time. They last one year.
  • Cloudflare Turnstile may set its own cookies on the login, registration, password reset and contact forms and the forum’s post editor.
  • Signing in with Google takes you to Google’s own sign-in page, where Google sets its own cookies. We set one short-lived cookie of our own, SESSnsl, to carry you through the sign-in and back; it lasts only for that browser session.

There are no advertising cookies and nothing that follows you to another site.

How we count visits

We use Umami to count page views, so we can see which articles are read and which are not. It sets no cookie, stores nothing on your device and does not identify you: there is no profile, no cross-site tracking, and nothing is sold. Umami (Umami Software, Inc.) runs the counter for us: each page view reaches it with your IP address, which it uses to work out the country and does not store. Page addresses are sent without their query string, so what you search for here is not recorded. It records the page, the site that linked to it, the country, and the general type of device and browser. Because it cannot recognise you there is nothing to opt out of, but it does stand down if your browser sends a Do Not Track signal.

We also keep our own tally of how many times each article and tool is read, how often each forum board is visited and which links are followed, so we can name an article and a tool of the month and see which subjects readers want more of. It is a count per page per day: it stores no IP address, sets no cookie, keeps nothing on your device and says nothing about you. For links to other websites it keeps only the other site’s domain, never the full address. It ignores visitors whose browser sends a Do Not Track signal, and people who edit the site.

Services that help us run the site

We share information with other companies only where it is needed to operate the site:

  • Bluehost hosts the website and its email on servers in the United States.
  • Cloudflare Turnstile protects our forms from bots. When a form protected by Turnstile loads, Cloudflare receives your IP address and information about your browser. Cloudflare’s privacy policy and terms apply.
  • Google Sign-In handles the “Continue with Google” button. When you use it you are sent to Google to sign in, so Google knows you signed in to this site, and it returns the details listed above. Google’s privacy policy applies to what happens on their side.
  • Akismet (Automattic) checks comments and contact messages for spam. It receives the text, the name and email entered, the IP address and browser details. See the Akismet privacy notice.
  • Wordfence (Defiant) is our security plugin. It examines visitor IP addresses and login attempts to block attacks. See the Wordfence privacy policy.
  • Gravatar (Automattic). We do not use it: members without an uploaded avatar get a neutral picture, and nothing is sent to Gravatar.

We do not sell, rent or trade personal information. We would disclose it only if the law required us to, or if it were necessary to protect the site or its members from harm.

How long we keep it

  • Account details are kept until you ask us to delete your account, or until the account has been inactive for 24 months. Before an inactive account is deleted we email the address on it and give you 30 days to sign in; signing in resets the clock. See section 9 of the Terms.
  • The link between your account and your Google account is kept until you disconnect it, or until the account is deleted.
  • Posts and comments stay published so that discussions remain useful to others. When an account is deleted we can remove its posts or keep them without your name, whichever you prefer.
  • Server and security logs are kept for a limited time, normally no more than a few months. Backups of the site, which include account details, are kept for 14 days, so something deleted can remain in a backup for up to 14 days afterwards.
  • Shell Lab progress is kept until you delete your account or ask us to remove it.
  • Practice answers and learning path progress are kept until you clear them, delete your account, or ask us to remove them.
  • Contact form emails are kept only as long as needed to deal with them.

Your choices and rights

Posts and topics you wrote stay on the site when an account is deleted for inactivity, reassigned to “Former member”, so that discussions remain useful; section 9 of the Terms explains this and how to ask for them to be removed instead.

You can change your email address, password and profile from your account at any time. You can also ask us for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete your account and data. Write to contact@keh-tech.net from the address on your account, or use the contact form, and we will respond within 30 days. We will not erase information we are required to keep for legal or security reasons.

Depending on where you live, laws such as the GDPR or state privacy laws may give you additional rights, including the right to object to certain uses of your data and to complain to your local data protection authority. Where the GDPR applies, we process your data to provide the account and forum you asked for, and on the basis of our legitimate interest in keeping the site secure and free of spam. The site is run from the United States and your information is stored there.

Children

KEH-TECH is written for working IT professionals and students. It is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has created an account, please tell us and we will remove it.

Security

The site is served over HTTPS, passwords are stored hashed, administrator accounts require two-factor authentication, and repeated failed logins are locked out. No website can promise perfect security, so please use a unique password here.

Changes to this policy

If we change how we handle personal information we will update this page and its effective date. Significant changes will also be announced in the forum.

Contact

Questions about this policy or your data: contact@keh-tech.net or the contact form.