PRIVACY / SOURCE BEFORE POLICY

Privacy starts with the data flow, not a policy template

This page describes what can be verified in the current source candidate and separates it from production choices that have not been made. It is a development-state disclosure—not a privacy notice for a service that does not yet exist.

Development preview · information as of 2026-09-09 · production notice pending

What the source candidate does not collect

The landing source includes no analytics, advertising, third-party fonts, cookies, account system, or contact form. It exposes no source upload, hosted-analysis API, signup, billing, or customer project state.

Theme and animation preferences are stored in this browser after you choose a setting. They are not sent to the site or used for tracking. You can remove them by clearing this site's browser data; if storage is unavailable, the controls still work for the current page.

Telegram and LinkedIn are ordinary outgoing links on the author page. Clicking one leaves this site; the source candidate does not proxy the destination or collect a message first.

No analytics or advertising

No tracking SDK, ad network, behavioral profile, conversion pixel, or remote font dependency is included in the published source.

No accounts or forms

There is no login, contact submission, newsletter, comment, payment, or browser-side customer record.

No source uploads

The current site publishes static guidance. It does not receive manifests, compiler artifacts, Swift source, findings, or analysis output.

What a public host may still process

Serving a static page can still create infrastructure data. Depending on the selected host and configuration, requests may expose IP addresses, request headers, timestamps, requested URLs, and referrers to delivery infrastructure.

No production provider, region, log schema, security layer, purpose, access policy, retention window, or deletion process is selected. This page therefore describes possible categories without claiming that a specific production flow is active.

Request metadata

A web server or edge service may record enough request context to deliver content, diagnose failures, or protect availability.

Delivery providers

DNS, TLS, CDN, hosting, and deployment services can create separate processing boundaries that must be named once selected.

Security and abuse records

Rate limiting, firewall, or incident tooling may retain event data if enabled; no such production configuration is claimed here.

Why this is not yet a production notice

A real privacy notice must follow the deployed system. It needs the operator identity and contact, applicable purpose and basis, actual processors and regions, data categories, retention and deletion, request rights, and an effective date tied to the live configuration.

Those inputs remain unresolved. Copying generic legal language into this candidate would hide the missing decisions instead of informing a visitor.

Crawling, training, and access are different

Allowing a search crawler to discover a public page does not by itself grant or deny use for model training. Search indexing, training preference, licensing, and access control are separate owner and delivery decisions.

For this candidate, the owner has chosen to allow search crawling and not restrict training crawlers through robots.txt. This crawler preference does not change the content license.

A robots.txt instruction communicates crawl preferences to cooperating agents; robots.txt is not access control and does not remove already disclosed information. Private material requires actual authentication and authorization.

Search indexing

Controls whether discoverable public routes are invited into search systems; it does not define every later use of the content.

Training preference

Requires an explicit publication and licensing decision rather than being inferred from ordinary search visibility.

Access control

Protects non-public material with enforced identity and authorization, not a crawler preference file.

What must be decided before launch

The production privacy work starts after the hosting and operating model are concrete. The published notice must then match those facts and remain versioned when the data flow changes.

Name the accountable operator

Identify who operates the public site, where privacy questions go, and which jurisdiction and request process actually apply.

Map every processor

Record hosting, delivery, logging, monitoring, region, access, purpose, and transfers from the real deployment configuration.

Publish lifecycle and rights

State effective retention, deletion, security, user-request, and change-notification behavior without borrowing terms from a future SaaS product.