Privacy Policy
Last reviewed: 8 October 2026.
This policy covers https://www.raphcrimson.com, the portfolio operated by Raph Crimson Mushailov under the name Raph Crimson. For privacy questions or requests, contact RaphCrimson@gmail.com.
The contact form sends enquiries through the owner-authorized Gmail connection described below. You may also contact RaphCrimson@gmail.com directly.
Contact enquiries
The contact form asks for your name, email address, project subject and message. These details are used to consider and respond to your enquiry. Enquiries are addressed to RaphCrimson@gmail.com. Your email address is used as Reply-To, so a reply can reach you; it is not used as the website’s sender identity. The form does not offer file uploads or automatically subscribe you to a mailing list.
Providing information through the contact form is voluntary. Without a working reply address and sufficient information about your enquiry, we may not be able to respond.
Only include information needed to discuss your project. Please do not send passwords or other information that is unnecessary for an initial enquiry. If you use the direct email link, your email provider and Google’s Gmail service process that correspondence separately from the website form.
Website email and the owner’s Google authorization
FluentSMTP is a WordPress plugin running on the website’s server. It sends website-generated email through Google’s Gmail API using the owner’s RaphCrimson@gmail.com account, with the sender name Raph Crimson. Google will process the recipients, subject, message content, email headers and delivery information needed for that service.
The Google OAuth application is named ‘Raph Crimson Website Mail’ and is used only for the owner-authorized email-sending connection described in this policy.
This is an owner-authorized sending integration, not a service that connects to visitors’ Gmail accounts. Its actual authorization request asks only for the Gmail sending permission, gmail.send. It does not request permission to read or delete mail, or to access Google Drive or Contacts. Visitors do not need to authorize a Google account to send an enquiry.
During the owner’s authorization, the browser passes through FluentSMTP’s authorization callback, which handles authorization data. The installed plugin then communicates with Google to exchange the authorization code and send email. Google’s and FluentSMTP’s own privacy policies also apply to their services.
With credential encryption enabled, the plugin stores the client secret and access and refresh tokens encrypted in the website database. These tokens allow the connection to continue operating without storing the owner’s Google password. This credential protection does not encrypt the separate email-log contents.
Information received through the owner’s Google authorization is used only to operate and maintain this website’s email-sending connection. The use and transfer of information received through the owner’s Google authorization follow the Google API Services User Data Policy, including its Limited Use requirements.
Email records and retention
FluentSMTP email logging is enabled with a retention setting of 14 days. Logs can contain the sender and recipient addresses, subject, full message body, headers such as Reply-To, delivery status, provider response and supplementary delivery information. This means an enquiry may be stored in the website database as well as in Gmail. Failed delivery attempts can also be logged.
The plugin schedules daily cleanup of older email logs. Fourteen days is the configured cleanup threshold, not a guarantee that every copy disappears at an exact time. Copies in Gmail and backups are managed separately; deleting a website log does not delete those copies.
A fixed retention period for enquiries held in the owner’s Gmail mailbox has not been specified as part of this website setup. Please contact the privacy address about retention or deletion of your correspondence.
Hosting, security logs and spam prevention
The website is hosted on an OVHcloud server documented as located in Germany. This does not mean that Google or every other service processes data only in Germany.
The server records technical access and error information for operating and protecting the website. Access records include IP address, request time, requested address and method, response status and size, referring page and browser information. The relevant server logs rotate according to file size rather than a fixed number of days.
The contact form uses validation, a hidden spam-trap field, an anti-forgery check and a submission limit. For that limit, it stores a keyed hash derived from the requesting network address and an attempt counter. The counter has a one-hour expiry; expiry does not guarantee physical removal of every record at precisely that time. These controls do not require a third-party CAPTCHA service.
Backups and service providers
Daily website backups include website files and a database copy, which can include email logs. The separate backup process encrypts these backups before transferring them to the owner’s Google Drive storage. This backup process is separate from the Gmail sending integration and does not add Drive access to that integration’s permission request.
Automatic pruning of these backups is not currently enabled, so they do not have a fixed automatic expiry. Older copies can remain after information is changed or removed from the live website. Hosting-provider backups and snapshots may also retain copies; no fixed retention period for those copies is stated here.
OVHcloud provides hosting, Google provides Gmail and separate backup storage, and FluentSMTP supplies the mail plugin and authorization callback. YouTube provides video playback. Each provider processes relevant information under its own service and privacy terms. This policy does not promise that all provider processing or storage remains in one country.
Videos, cookies and other website features
Portfolio images are currently served from this website. A YouTube player is loaded when you choose a video, using YouTube’s privacy-enhanced mode. That mode is not a promise of no data collection: loading and using the player sends technical information, such as your IP address, browser or device details and referring origin, to Google. YouTube may use cookies or similar technologies under Google’s privacy policy. Opening a Watch on YouTube link takes you to YouTube’s own service.
If a local video thumbnail fails to load, the site can request a replacement thumbnail from YouTube’s image service. Ordinary links to other websites also lead to services with their own privacy practices.
No separate analytics or advertising integration is currently configured for the portfolio. Portfolio search and filters operate in your browser. The public portfolio does not set its own analytics or advertising cookies. WordPress uses login and administration cookies for authorized site users; YouTube’s behavior is separate from those cookies.
Security and privacy requests
The website uses HTTPS. Mail authorization and Gmail API traffic use encrypted connections with certificate verification, and access to administration and stored data is restricted. These measures reduce risk but do not guarantee absolute security.
You may contact RaphCrimson@gmail.com to ask what personal information is held about you, request a copy or correction, request deletion, or raise a privacy concern. Enough information may be needed to identify your enquiry and verify that the request concerns your data. Any applicable legal rights continue to apply.
Deletion from the live website does not automatically remove Gmail correspondence, provider records or historical backups. The scope and any limitations of a request will need to be considered across those systems.
Relevant provider information: Google Privacy Policy (https://policies.google.com/privacy), FluentSMTP Privacy Policy (https://fluentsmtp.com/privacy-policy/), and Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy).