← Back to Portfolio

Privacy Policy

Last Updated: August 2026

1. Information Collection

This portfolio acts as a live security environment and actively collects structured telemetry to analyze security operations, visitor engagement, and site performance. The following information is collected:

  • Visitor Analytics: Page views, scrolling milestones, session duration, and active/idle time.
  • Network & Device Metadata: IP addresses, estimated geographic location (Country, Region, City), browser type, operating system, and screen resolution.
  • Interaction Data: Terminal commands executed, sections viewed, certificates expanded, and files downloaded.
  • Session Tracking: Cryptographically generated UUIDs stored in secure cookies (`pf_vid`, `pf_sid`) to track session continuity.
  • Contact Information: Data explicitly provided via the Contact form (Name, Email, Message, Intent).

2. How Information is Used

Telemetry data is utilized exclusively for internal analytics, active threat monitoring, and maintaining the operational health of this portfolio. Contact information is used strictly to respond to your inquiries.

Your data is never sold, rented, or shared with third-party marketing entities. Aggregate analytical data may be displayed inside the restricted Portfolio Admin dashboard.

3. Data Storage & Security Measures

All analytical and contact data is stored securely in an isolated Supabase PostgreSQL database. Access to this database is protected by stringent Row Level Security (RLS) policies and requires Authenticator Assurance Level 2 (AAL2) multi-factor authentication for administrative access.

Network traffic is encrypted in transit via TLS 1.3, enforced by Vercel edge routing.

4. Cookies & Local Storage

We deploy minimal cookies strictly necessary for maintaining anonymized session state and security throttling. These are functional analytics cookies that do not track you across external domains. See the Cookie Policy for detailed mechanics.

5. Third-Party Services

This portfolio leverages the following third-party infrastructure providers, which act as data processors:

  • Vercel: Hosting, edge routing, and IP geographic resolution.
  • Supabase: PostgreSQL database hosting and real-time socket delivery.
  • Resend / Custom SMTP: Delivery of outbound contact form notifications.

6. Retention Period

General telemetry events and session records are retained for analytical purposes. Contact messages are retained indefinitely within the secure inbox database unless explicitly deleted by the administrator. IP addresses associated with malicious activity (e.g., rate-limit abuse, payload injection) are retained indefinitely on the permanent blocklist.

7. User Rights & Contact

You have the right to request the deletion of any personal information (e.g., contact form submissions) associated with your email address. To exercise this right or ask questions regarding this policy, please contact me directly.

Security Contact: gandhamjothish1@gmail.com