Privacy_node
Minimal data by design.
Portfolio data
LucyOS is a portfolio experience. The contact and bug-report forms validate information in your browser, then transmits the submitted name, email, and message through the configured email provider to the fixed owner recipient. The requester email is used only as reply-to. LucyOS does not persist message content in its application database. Optional bug-report evidence is sent as an attachment through Resend to the fixed owner mailbox. LucyOS does not keep an application database or object-storage copy; Resend and the recipient mailbox process and retain their copies under their respective policies and settings. Pseudonymous, non-reversible network and email quota buckets are used only to prevent abuse.
Accessibility preferences are stored only in your browser. The boot sequence uses session storage to avoid replaying during the same browsing session.
Field performance metrics
LucyOS samples at most 10% of eligible page loads after the page has loaded to measure LCP, INP, CLS, FCP, and TTFB. It honors Do Not Track and Global Privacy Control. The browser converts each measurement into a coarse histogram bucket and sends only the metric name, bucket number, coarse route group, and compact, medium, or wide viewport group to a first-party LucyOS endpoint.
LucyOS does not set an analytics cookie or store a visitor, account, session, or fingerprint identifier. Precise metric values, URLs, query strings, full user agents, location, and raw network addresses are not stored. A keyed network quota derived by the server limits abuse without retaining the source address; that quota bucket expires within 24 hours. Private daily histograms remain for up to 90 days, after which scheduled cleanup removes them. Supabase stores only those private aggregate counters and short-lived quota records.
Interactive portfolio tools
Ask Anything processes your question and request context only to return that response to you. A network address is observed from trusted request metadata. Approximate network city, country, coordinates, and timezone are returned only to the requester; they are IP-derived estimates, never GPS or precise location. Device class and browser family are broad inferences from a bounded user-agent request header; the full user agent and versions are not returned. This automatic request metadata needs no browser geolocation or permission prompt. Because the host provides no supported ISP or telecom name, Ask sends the observed public IP to IPWho solely to resolve the network owner for that response. LucyOS does not cache or persist the lookup. IPWho receives and may process the queried address under its own Privacy Policy and Terms. If that bounded lookup fails, the provider is reported as unavailable rather than invented. LucyOS does not use these facts to claim your identity or exact GPS location. These requester details are not persisted by LucyOS in application logs, analytics, browser storage, or a database. Hosting and security providers may process operational request telemetry under their own controls. The raw IP address is not published to Community Chat or shared with other visitors.
The typing test runs in your browser. Its prompt, keystrokes, score, and local mini-game state are not sent to Community Chat. Interface sound and accessibility preferences remain in local browser storage and can be reset from System Preferences.
Community Chat
When Community Chat is available, Supabase stores your write-once display name, message content, approximate city and country, broad device class, moderation reports, and pseudonymous abuse-control records required to operate the basic chat.
The approximate city and country come from trusted hosting request metadata, not GPS or a browser geolocation permission. The displayed device is a broad class inferred from a bounded user-agent header. LucyOS publishes those three coarse details beside the message for its 24-hour lifetime, but does not store or publish coordinates, GPS, region, browser, full user agent, account UUID, raw network address, or browser fingerprint. LucyOS derives a keyed abuse-control bucket from trusted network metadata and discards the source address; the raw IP address is never stored in the LucyOS application database. Hosting infrastructure may still process request logs under its own operational controls.
Community messages remain active for up to 24 hours before scheduled deletion. Managed backups may persist temporarily under the infrastructure provider's recovery schedule. Deleting the active chat identity removes its messages and revokes that exact capability through its original lifetime. Local mute affects only your browser.
Message content, its city/country/device projection, ownership, idempotency, and report records are retained for no more than 24 hours. Write-once display-name continuity and keyed revocation or abuse-control records may persist for up to 30 days. Logical reads exclude expired content immediately; bounded scheduled cleanup removes the corresponding database records.
An opaque capability may stay for up to 30 days in an HttpOnly, SameSite=Strict cookie scoped to the Community API and is Secure in production. Browser JavaScript receives no Supabase Auth token and the raw capability is never stored in the database.
Supabase receives chat data only for database storage, moderation, quotas, and retention cleanup. Use the requests and contact path below for access or deletion questions.
Network Pulse
Network Pulse is voluntary and starts only after you choose Start. It sends your public-facing IP and Internet measurement data to an external test service. That service may publish the IP with the measurement data.
LucyOS keeps the result only in the open utility's memory and adds no persona, route, referrer, account, device, or other custom metadata. LucyOS returns the initiating requester's validated public IP to that same open utility after Start. A snapshot or PDF you choose to create includes that public IP in the file assembled locally by your browser. Outside a file you deliberately save, LucyOS holds it only in component memory and clears it on rerun or close. It is not an ISP lookup. LucyOS does not persist, cache, log, enrich, or share that displayed requester IP with another visitor. LucyOS cannot delete or control an external public dataset after a test starts. Use LucyOS's requests and contact path below for LucyOS-controlled data.
Tetris leaderboard
Tetris works locally without Community Chat or an account. When ranking is available, a scoped anonymous capability stays in a Secure, HttpOnly, SameSite=Strict cookie. The database measures elapsed time and the server replays a bounded action trace to derive score, lines, and level. The trace is discarded after validation and is not stored.
The public top ten shows a visitor-chosen normalized printable name and game metrics. Duplicate names and repeated verified runs are allowed. The private leaderboard retains the deterministic best 100 verified attempts; displaced results are deleted. The expiring run keeps a bounded canonical request and response receipt only for exact safe retries. Replay verifies the game rules, not a human identity, and raw capabilities, network addresses, seeds, and traces are never public.
Typing leaderboard
Typing works locally without Community Chat or an account. When ranking is available, the server issues one of eight fixed prompts and a single-use run capability. A scoped anonymous capability remains in a Secure, HttpOnly, SameSite=Strict cookie for up to 30 days; raw cookie and run values are never stored or exposed publicly.
PostgreSQL measures the run time and the server replays at most 512 accepted lowercase, space, or Backspace events. The key trace is discarded after validation. The public top ten exposes only a visitor-chosen normalized printable name, WPM, accuracy, and elapsed time. Duplicate names and repeated verified runs are allowed, while the private leaderboard keeps only the deterministic best 100 verified attempts. The expiring run keeps a bounded canonical request and response receipt only for exact safe retries. Replay rejects direct score injection but does not prove that a human typed the public prompt, so rankings are a casual challenge rather than identity proof.
Diploma verification previews
Opening a preview sets a five-minute HttpOnly cookie containing stateless signed authorization bound to this site and the selected diploma. The cookie is scoped to the diploma API; it is Secure and SameSite=Strict in production. LucyOS keeps no viewer session database and does not use viewer analytics.
The viewer serves only reduced, metadata-stripped, watermarked derivatives. Archival diploma originals remain separate from the site and are not served by the viewer.
These controls reduce casual scraping; they are not DRM. Any preview visible in a browser can still be captured with screenshots or browser network tools. Redaction and watermarking protect sensitive details and identify the preview as verification material, but cannot prevent copying.
Research purchase data
Research checkout asks for first and last name, fulfillment email, email confirmation, gateway and product selection, and required consent. The email is verified before payment. LucyOS does not collect card, bank, wallet, or other payment-instrument details.
The research purchase flow has no buyer account or hosted purchase library. Hosted PayPal and QRPH checkout keeps no first-party durable buyer database. Manual GCash checkout validates the uploaded proof in memory, sends it directly to the fixed owner mailbox as an email attachment, and retains no first-party payment record or proof object. Encrypted browser cookies also hold first-party session state; they are short-lived and essential to verification, checkout state, device binding, and signed redelivery. Production cookies are HttpOnly, Secure, SameSite=Lax, and bound to this site and the browser device secret.
Email challenges expire after 10 minutes, verified-email state after 15 minutes, hosted checkout state after two hours, the encrypted GCash owner-review link after 14 calendar days, owner review sessions after 30 minutes, and a signed hosted redelivery cookie may last up to 24 hours.
LucyOS discards the transient GCash upload after the owner email is accepted. The attachment copy remains subject to Resend and owner-mailbox retention; LucyOS has no database or object-storage copy to clean up. The research purchase flow does not use IP addresses, user agents, or browser fingerprints as device identity; those signals may still be processed by hosting security controls to limit abuse.
Service providers
PayMongo (shown as QRPH) and PayPal host payment steps and process payment data under their own notices. LucyOS sends them product, amount, currency, reference, and a keyed email binding; merchant metadata does not contain the buyer's plaintext name or email.
Resend processes the verified email address, display name, and transactional message content to send verification, fulfillment, receipt, and document redelivery messages. A provider's acceptance of a message does not guarantee inbox placement. PayMongo, PayPal, GCash, and Resend retain their provider records under their own policies. Supabase supports unrelated LucyOS community and operational features, but no research payment method reads from or writes to it.
After an initial verified purchase, LucyOS also sends a separate notification to the owner Gmail mailbox. It contains the buyer name and email, product and purchase metadata, and a PII-free purchase receipt for support and reconciliation. A pending GCash message also attaches the normalized buyer-supplied receipt for manual review. The owner mailbox retains that message according to its mailbox retention settings and applicable support or legal requirements.
Requests and contact
You may ask about access, correction, objection, deletion or blocking, and other rights available under applicable privacy law. Some payment records remain with PayMongo, PayPal, GCash, Resend, or the owner mailbox under their own legal and retention duties; LucyOS cannot delete records it does not control.
Rodstark Global Solutions, Inc.research@njmlabios.spaceExternal services
External channels open third-party services, which apply their own privacy policies.