Privacy Policy
This personal portfolio is operated by Aidan Connaughton. I determine why and how information submitted through aidanconnaughton.com is processed. The site does not offer user accounts or maintain visitor profiles, and I do not sell personal information, use it for targeted advertising, or use it to make decisions that have legal or similarly significant effects.
Questions and privacy requests can be sent to aidan@aidanconnaughton.com.
What I collect / process
- Contact form: When you submit the contact form, the information you enter (such as name, email address, subject, and message), along with a submission timestamp and request identifier, is delivered to me through a private Discord webhook so I can respond.
- AI chat: If you use the on-site AI chat, your message is sent to OpenAI for automated moderation and response generation. Recent conversation history, generated replies, and a response identifier may also be processed to keep the conversation working.
- Security, hosting, and delivery: The active deployment uses Cloudflare Workers for hosting and server execution, along with Cloudflare's DNS/proxy, network delivery, security, and Turnstile services. Cloudflare may process technical information such as network address, user agent, requested URL, response status, TLS or browser signals, site key and origin, timestamps, location or network metadata, and challenge results to deliver the site, limit requests, and prevent abuse. Depending on its configuration, Cloudflare may set a strictly necessary security cookie such as
cf_clearance. - Restricted previews: Cloudflare Access protects private Worker preview deployments. If you are authorized to open one, Cloudflare may process your login identity, authorization result, session information, requested preview hostname, and related security records. Public visitors do not need a Cloudflare Access account to use the production site on aidanconnaughton.com.
- Browser storage: Theme preference and portfolio achievement progress are stored in local storage. A bounded chat transcript, response identifier, and verification state are stored in session storage for the current tab session. This storage supports site features and is not used for cross-site advertising.
- Cloudflare operational records: Workers Logs may store invocation and application records such as request method and URL, response status, timestamps, request identifiers, Cloudflare request metadata, application status events, console messages, errors, and uncaught exceptions. Contact-form text and AI chat text are not intentionally written to Workers Logs. If the site encounters an application error, a limited report containing the page path, error digest, user agent, and shortened error message may also be delivered to Discord.
- VPS-compatible chat records: When the preserved VPS deployment is used, its local server-side chat logger stores limited metadata by default, including timestamps, model name, response status, message lengths, a hashed conversation identifier, and a keyed hash of the network address used for abuse prevention. Chat text is not stored in those local logs by default.
Please avoid submitting sensitive information (passwords, financial details, government IDs, etc.) through the contact form or AI chat.
How it’s used
- To respond to messages you send via the contact form.
- To moderate messages and provide contextual AI chat responses.
- To remember your display preference, achievement progress, and current-tab chat state.
- To protect the website from abuse and keep it reliable.
- To diagnose errors and review aggregate delivery, traffic, and security information.
Sharing / third parties
This site relies on third-party providers to operate. Depending on what you use, your data may be processed by:
- Cloudflare provides Workers hosting and execution, DNS/proxy and network delivery, security, operational logging, Turnstile verification, and Access for restricted previews. See Cloudflare's Privacy Policy and Cloudflare's Turnstile Privacy Addendum.
- OpenAI provides message moderation and AI response generation. See OpenAI's Privacy Policy.
- Discord receives contact-form submissions and limited application error reports through private webhooks. See Discord's Privacy Policy.
- Other hosting and network providers may process requests and technical records needed to serve and secure the site when the VPS-compatible deployment or upstream services are used.
I do not sell personal information to these providers. They process information to deliver the services described above and under their own privacy terms.
AI data handling
Under OpenAI's default API data controls, API content is not used to train OpenAI models unless the API account opts in to data sharing. OpenAI may retain abuse-monitoring records for up to 30 days. The Responses API used by this site also retains response application state for at least 30 days by default so conversational continuity can work. OpenAI may retain information longer when legally required or necessary to protect its services or others from harm. See OpenAI's API data-controls documentation.
Retention
- Current-tab chat history and its response identifier remain in session storage until you clear the chat, close the tab or browser session, or clear site data.
- Theme preference and achievement progress remain in local storage until you clear site data.
- Cloudflare Workers Logs are retained according to the active Workers plan and logging configuration. At the time of this policy, Cloudflare lists three-day retention for Workers Free and seven-day retention for Workers Paid, with seven days as the maximum Workers Logs retention period. See Cloudflare's Workers Logs documentation.
- When the VPS-compatible deployment is used, local operational chat logs use a 90-day retention window: expired records are pruned when logging runs, and the files are also limited by size-based rotation. Conversation content logging is disabled by default. If temporarily enabled for troubleshooting, stored chat content is encrypted at rest and follows the same retention window.
- Cloudflare Access authentication and session records for restricted previews are retained according to the applicable Access configuration and Cloudflare's policies. Preview access is currently limited to authorized Cloudflare account members.
- Contact submissions and application error reports remain in private Discord channels until I manually delete them or Discord removes them under its policies. You may request deletion by email.
- Cloudflare, OpenAI, Discord, and infrastructure providers retain their own records according to their respective policies and legal obligations.
Cookies, tracking, and privacy signals
The site does not use advertising cookies, sell or share personal information for targeted advertising, or perform cross-site behavioral tracking. Because those activities are not performed, browser Do Not Track and Global Privacy Control signals do not change the site's behavior. Functional browser storage and any Cloudflare security cookie are used only to provide preferences, session features, and abuse prevention.
Your choices
- Don’t use the contact form or AI chat if you don’t want to share information.
- Use the chat's clear control, close the tab, or clear site data to remove browser-stored chat data.
- Clear this site's browser data to remove theme and achievement storage.
- Email me to request access to, correction of, or deletion of information you submitted. I may need enough information to verify and locate the record. Some hashed or aggregate technical records cannot reasonably be linked back to an individual.
International processing
This site is operated from the United States. Providers such as Cloudflare, OpenAI, Discord, and hosting services may process information in the United States and other countries, where privacy protections may differ from those in your location.
Children
This site is not directed to children under 13, and I do not knowingly collect personal information from children under 13. If you believe a child has submitted personal information, contact me so I can review and delete it where possible.
Changes to this policy
I may update this policy as the site or its providers change. Material changes will be posted on this page, and the “Last updated” date reflects the latest revision.