Privacy Policy
Updated September 17, 2026
Scope and contact
This notice covers Michael Chan's personal website, chan.dev, and its private account, connection, and media tools at auth.chan.dev, social.chan.dev, and devices.chan.dev. These tools are for personal use and authorized testing. Contact hi@chan.dev with privacy questions or requests.
Website visits
Cloudflare hosts the website and provides traffic and performance analytics. Hosting services process technical request information, such as IP addresses, browser information, requested pages, and errors. Some pages load Google Fonts, external images, or embedded content such as YouTube videos. Those providers receive browser requests and may use their own cookies or storage.
Private accounts and connections
Sign-in uses WorkOS. Account information includes an identifier, email address, name when provided, verification status, session information, and workspace membership. Cookies maintain sign-in across chan.dev subdomains; blocking or clearing them can prevent access or sign you out.
When an authorized user connects a provider, WorkOS manages the connection, permissions, and OAuth tokens or API keys. The tools process the profile details allowed by that connection, such as an account identifier, display name, username, avatar, or profile link. A profile link entered manually may also be stored. TikTok Login Kit uses the basic-profile permission to identify the connected account; video access requires a separate permission and an enabled upload feature.
Media and other input
The private tools process files, captions, audio, and other input supplied for their features, along with status and activity records. Original media and publication records may be stored. Content is sent to a connected provider when an authorized user requests a supported action, such as an upload, post, or transcription.
Use and service providers
Information is used to operate the website and private tools, maintain connections, perform requested actions, diagnose failures, and protect access. WorkOS handles identity and connections; Cloudflare provides hosting and storage. The providers selected for a feature receive the information needed for that feature. Their own privacy policies apply to their services. Information may also be disclosed where required by law.
Provider notices: WorkOS, Cloudflare, and Google.
Control and retention
Connections can be removed at auth.chan.dev/connections. Access can also be revoked in the provider's settings. Disconnecting or signing out does not automatically delete an account, stored files, past activity, or content already sent to another service.
Records are kept to maintain accounts and connections, operate the tools, investigate issues, and preserve completed actions. To request access, correction, or deletion, contact hi@chan.dev. Requests may require account verification. Some records may remain for security, legal requirements, backups, or the history of completed actions. Data held by other providers is subject to their controls.
Updates to this notice appear here with the date shown above.