Privacy
This site is a personal portfolio. There are no accounts, no sign-ups, and nothing to buy, so there is very little to collect. What follows describes only what the code actually does, not what a template says it might.
First-party event tracking
The site has a single tracking endpoint, /api/track. It accepts two allowlisted event names, hire_opened and command_run, and rejects everything else with a 400. There is no general-purpose logging channel behind it.
An event can carry: the resolved id of a terminal command (drawn from a fixed set, never the free text you typed), a reference slug that I assign when I share a tagged link, the referring URL, the coarse country and city that Vercel's edge attaches to the request, and the browser's user-agent string.
Your IP address is never stored. The server runs it through a one-way SHA-256 hash, truncates the result, and keeps only that opaque value so repeat visits can be counted without identifying anyone. The raw address is discarded.
Those events go to Axiom, which is where I look at how the site gets used. The endpoint also applies a coarse per-instance rate limit so a loop can't flood the dataset.
Third-party analytics
Google Analytics 4 runs when a measurement ID is configured, and records page views plus a small number of interaction events. Google's own privacy policy governs that data.
Vercel Analytics and Vercel Speed Insights are also loaded. They record aggregate page-view counts and performance measurements (Core Web Vitals). Vercel's privacy policy governs that data.
Stored in your browser
A few preferences are kept in localStorage and sessionStorage on your own device: the theme, the interface mode, the sound setting, your terminal command history, and a flag marking that you've visited before so the boot sequence only plays once a session. None of it is sent anywhere. Clearing site data removes all of it.
What this site does not do
No advertising, no ad-network pixels, no cross-site or third-party ad tracking, and no profiling. Nothing is sold, rented, or shared for marketing. There is no account, no password, and no mailing list.
There is also no cookie-consent banner and no self-service data-deletion flow, and I'd rather say so than imply mechanisms that aren't in the code. The honest position is that there is no account and no stored identifier tied to you to delete. The visitor value is a truncated hash, and nothing links it back to a person.
Your controls, and getting in touch
Blocking scripts in your browser, or using an extension that blocks analytics, stops the third-party parts above. Clearing site data removes the preferences stored locally. Neither breaks the site.
Questions about any of this, or a request about data you think relates to you: email me@dannykeane.co.uk and I'll answer. If this page ever stops matching the code, that's a bug. A test in the repo checks the two against each other.