Site visitors
Privacy
Plain-language privacy stance for verified member access and public content.
The first rebuild keeps public browsing quiet while adding protected member access for contact and deeper material.
Public pages can be read without an account. Contact messages, newsletter subscription state, member-only depth content, and model testing require a verified account.
Account records include email address, display name, password hash when password sign-in is used, email verification status, encrypted MFA secret material, hashed recovery codes, OAuth identity links when social sign-in is used, group membership, status, timestamps, and audit events.
Protected contact messages are stored in the private site inbox. Discord alerts, when enabled, are minimal: event type, verified user identity, timestamp, and an admin link. They do not include the full message body and they disable mentions.
Newsletter records store local subscription status only. This slice does not add a mass-email sending engine.
There are no public comments, anonymous uploads, or anonymous AI inference features in this version. Private admin access exists only for approved publishing, site maintenance, user review, contact message review, newsletter review, and audit inspection.
AI-assisted drafts are reviewed before publication. Drafts must not contain secrets, private customer details, raw infrastructure values, or unapproved personal activity.
Production privacy details should be reviewed again before public cutover, especially when SMTP, OAuth providers, Cloudflare Turnstile, Discord alerts, analytics, or newsletter delivery tooling are enabled.