Privacy Policy

This is a tutorial site. You can read every post here without giving me anything — no account, no signup, no email.

The parts below cover the few places where data does change hands: comments, cookies, embedded content, and the third-party services the site runs on.

Last updated: 26 August 2026.

Who Runs This Site

This site is mkyong.com, run by Yong Mook Kim (Mkyong). See the About page for who that is, or email me with anything on this page.

Comments

When you leave a comment, the site stores what you typed in the form — your name, your email, your website if you filled it in, and the comment itself.

It also stores your IP address and your browser's user agent string. Those two are for spam detection, not for tracking you around the site.

Comments are checked by an automated spam service before they appear. Your comment and its details are sent to that service so it can score them.

Gravatar

If you comment, a scrambled version of your email address (a hash) may be sent to Gravatar to check whether you have a profile picture there. If you do, it is shown next to your comment.

Gravatar is run by Automattic. Their privacy policy covers what they do with it.

Cookies

If you leave a comment, you can tick a box to save your name, email, and website in a cookie. That is only so you do not have to type them again next time. Those cookies last a year.

If you have an account here and log in, a few more cookies get set:

  • A temporary one on the login page, to check whether your browser accepts cookies at all. No personal data, gone when you close the browser.
  • Login cookies, which last two days — or two weeks if you tick "Remember Me". Logging out removes them.
  • A screen-options cookie, which remembers how you like the admin laid out. Lasts a year.
  • If you edit or publish a post, one more cookie holding the post ID. No personal data, expires after a day.

Almost nobody reading this has an account. Those last ones apply to me and to anyone else who writes here.

Google Analytics, AdSense, and Cloudflare set cookies of their own. Those are covered further down.

Embedded Content

Some posts embed things from other sites — videos, code sandboxes, images.

Embedded content behaves as if you had visited that other site directly. It can set its own cookies, run its own tracking, and see how you interact with it. If you are logged in to that service, it can tie that back to your account there. Their privacy policies apply, not this one.

Analytics

Two tools count visits here.

Google Analytics measures which posts get read and where readers come from. It sets its own cookies and sends that data to Google. Google's privacy policy and its page on how it uses data from sites that use its services cover what happens to it.

Umami does the same counting in a lighter way. It sets no cookies and does not follow you to other sites. It records the page you opened, where you arrived from, and rough details like browser and country. There is no profile of you in it.

I use the hosted version, Umami Cloud, so those counts sit on Umami's servers rather than mine. Their privacy policy covers what they do with them.

Advertising

The ads here are Google AdSense. Google and its partners use cookies to pick which ads you see and to count clicks. Depending on your settings, those ads may be personalised using data Google already holds about you.

You can turn personalised ads off at My Ad Center. You will still see ads, just generic ones.

I do not see who you are from the ads. I see totals — impressions and earnings — and nothing that identifies a reader.

If you are in a region where consent is required, a message appears the first time you visit, asking what you allow. That message is Google's consent tool, and your answer controls whether Google Analytics and AdSense may set their cookies and personalise what you see.

Say no and the site still works. You get the same posts, the same code, and generic ads instead of targeted ones.

Your answer is remembered so you are not asked on every visit.

Cloudflare

The site is served through Cloudflare, which sits between your browser and my server. It caches pages so they load faster and blocks attacks before they reach the site.

That means Cloudflare sees your requests, including your IP address, and sets its own security cookies to tell people apart from bots. Their privacy policy applies to that.

Nothing Else

No newsletter, no tracking pixels from social networks, no data brokers, no selling anything to anyone. The list above is the whole list.

How Long Things Are Kept

Comments and their details are kept indefinitely. That is so follow-up comments from the same person get approved automatically instead of sitting in a moderation queue.

If you have an account, the profile information you entered is kept until you delete it. You can see and edit it any time, apart from your username. Site administrators can see and edit it too.

What You Can Ask For

The only personal data this site holds about a reader is their comments — the name, email, and website you typed in the form, plus the IP address and browser string saved alongside them.

You can ask for a copy. WordPress builds a file listing every comment tied to your email address and sends you a download link. You can also ask me to delete the lot.

The one exception is anything I have to keep for legal, security, or administrative reasons — for example, records tied to a spam or abuse investigation.

Email me from the address you commented with, and I will sort it out.

One Thing Worth Knowing

If you request a password reset, your IP address is included in the reset email. That is how WordPress works, and it is there so you can spot a reset you did not ask for.