Skip to content
Aditya More

Transparency & data

Privacy Policy

This policy explains the information I currently process through this portfolio, why I need it, where it is stored, and the choices available to visitors.

Effective and last updated: August 20, 2026

Privacy summary

Mandatory anonymous visitor/session identity and country/region measurement apply to every public visit. Raw IP addresses, city, county, postal code, coordinates, and fingerprints are never written to my application databases. Page/device analytics, BB-8 telemetry, and returning-browser journeys are optional. There is no advertising, cross-site tracking, or third-party analytics SDK, and every public feature remains available when optional analytics is declined.

What is processed

Mandatory anonymous reach

For every public visit, I assign random, opaque visitor and session identifiers and record a server timestamp plus IP-derived country, country code, region/state, and region code when available. These identifiers contain no personal information and are unrelated to an IP address, email, name, device fingerprint, or location. City and more precise location are ignored and never persisted.

Optional Basic Analytics

Only after you select Basic or Enhanced Analytics, I record page views, measured engagement duration, controlled feature events, and coarse device, operating-system, browser, and viewport categories. Basic Analytics does not recognize your browser across separate sessions.

Optional Enhanced Analytics

Only after you explicitly select Enhanced Analytics, a random persistent browser identifier supports return-visit counts and page journeys. I also record a controlled traffic-source category and sanitized referring hostname. I may manually classify a pseudonymous journey; location and behavior never assign a category automatically.

Contact submissions

If you submit the contact form, I store the name, email, message, submission time, read state, and an optional category in a separate AWS DynamoDB table. Only when Enhanced Analytics is active may the message include a one-way hashed analytics reference. I do not put an analytics identifier in the message or use it to create an expanded personal profile.

BB-8 conversations and telemetry

When you use BB-8, a short conversation window and relevant portfolio context are sent through my server to OpenAI to generate a response. Requests use store: false, and I do not persist prompts or responses as analytics. With Basic or Enhanced consent, purpose-limited telemetry records anonymous opens, sessions, request outcome, latency, model, token totals, retrieval status, and coarse device/region context. Detailed agent actions require Enhanced consent.

Standard service processing

AWS Amplify and ordinary internet infrastructure may temporarily process an IP address to deliver and secure the site and derive country/region headers. Request handlers convert it to a short-lived one-way key for in-memory rate limiting. My application never writes the raw address or rate-limit key to its databases and never uses either as visitor identity.

Storage & retention

Retention: mandatory telemetry targets 90 days, Basic and Enhanced Analytics 180 days, BB-8 telemetry 90 days, and contact submissions 365 days. These periods are configurable. DynamoDB TTL deletes eligible records asynchronously, so removal may occur after the eligibility time.

Server-side separation: analytics events, Enhanced visitor journeys, BB-8 telemetry, and contact messages use separate record families; contacts use a separate table. My server is the authoritative analytics store.

Browser storage: localStorage remembers your consent choice and version. Only Enhanced Analytics stores a random persistent visitor identifier. sessionStorage holds the current anonymous visitor/session identity, optional Enhanced visit ID, BB-8 session state/transcript, and temporary contact drafts—not analytics histories.

Cookies: public analytics does not use cookies. A signed, essential admin-session cookie is used only when I sign into the private Command Center.

Service providers & use

Mandatory geography measures reach. Optional analytics measures content usefulness and UX. Enhanced Analytics supports return-visit and journey analysis. Optional BB-8 telemetry measures adoption and reliability. I do not use this data for advertising, automated decisions, or identity discovery.

  • AWS provides hosting, request processing, IP-derived country/region headers, DynamoDB storage, and vector retrieval.
  • OpenAI processes BB-8 prompts and portfolio context when chat or embedding features are used and provides aggregate organization usage/cost reporting to my private Command Center.
  • GitHub provides public profile and repository information requested by my server-side GitHub proxy.

I never store raw IP addresses, city, county, postal code, coordinates, hardware models, advertising identifiers, fingerprints, keystrokes, form values, or chat prompt/response text as analytics. Data is not sold, rented, or shared for unrelated commercial purposes.

Your choices

Use Analytics choices in the footer at any time to select Enhanced, Basic, or mandatory-only measurement. Mandatory visitor/session identity and country/region measurement cannot be disabled within the site. Moving away from Enhanced removes its persistent identifier and stops future optional collection; prior records expire under the applicable retention policy. Do Not Track and Global Privacy Control disable both optional tiers automatically.

You may ask what contact information I hold about you and request correction or deletion by emailing aditya.more@outlook.in. Analytics identifiers are random and pseudonymous; only an Enhanced-consented contact submission can contain the separate one-way hashed linkage.