Transparency, not boilerplate

What this site actually does.

A specific, accurate account of how this site handles data — every claim below reflects the real, current code, not a generic privacy-policy template.

There's no database.

This site doesn't operate a database or any long-term storage of visitor data. The contact form relays your name, email, and message directly to Resend, which sends it as a real email — it isn't saved anywhere by this site afterward.

Rate limits, and what they track.

Each interactive feature is rate-limited per visitor to keep it usable for everyone: the AI assistant (30 requests/10 min), Consult mode (15/10 min), site search (30/10 min), the prompt playground (20/10 min), and the contact form (5/15 min). This is tracked by IP address in memory only — never written to disk, never shared, and it resets automatically whenever this app redeploys.

AI answers are cached briefly.

Assistant, Consult, and search responses are cached in memory for 15 minutes so identical questions don't trigger a fresh model call. The cache holds the question and answer text only, lives in the same ephemeral memory as the rate limits above, and is never persisted.

What's sent to the AI model.

Your message (plus, for the assistant, the last few turns of that conversation) is sent to OpenRouter to generate a response. No visitor-identifying information — name, email, IP — is included in that request. The system prompts instruct the model to answer only from this site's own published facts, never to invent claims about Gopalakrishna.

What stays in your browser.

A few preferences live in your browser's local/session storage and never reach any server: your 3D-effects intensity, sound on/off, whether you've seen the intro animation, and the AI assistant's chat history for your current tab session. This site also keeps a short rolling log (last 50) of which links/buttons you click, held in session storage — used for nothing beyond this browser tab, cleared when you close it, and never transmitted anywhere.

Analytics.

Vercel Analytics and Speed Insights are used for aggregated, cookie-free traffic and performance metrics. Neither sets tracking cookies or builds an individual visitor profile.

Security headers, for real.

Every response carries a strict Content-Security-Policy, HSTS, X-Frame-Options: DENY, Cross-Origin-Opener-Policy: same-origin, a Permissions-Policy blocking camera/microphone/geolocation/payment/USB access by default, X-Content-Type-Options: nosniff, and a same-origin CSRF check on every API route. You can verify all of this yourself — it's just HTTP response headers, visible in your browser's network tab on any request to this site.

Questions about any of this? Reach out via the contact section — or read the code yourself at github.com/gopalgk53/portfolio.