Deep Dey's Portfolio

A website by Deep

Data Sovereignty

Privacy Policy.

Effective Date: May 9, 2026

1. Local-First Philosophy

The Deep Dey Digital Infrastructure operates on a "Local-First" data protocol. Applications such as "Transparent Clock" store configuration data exclusively on your local machine. We do not maintain a cloud-synchronized shadow of your personal productivity logs.

2. Google Sign-In Data We Process

When you sign in with Google, we may process your Google account display name, profile image URL, unique Google user ID (`sub`), and email address. This data is used only for identity, account continuity, moderation, and support verification inside this platform.

3. Email Collection and Re-Login Behavior

For new users, email can be stored when account data is first persisted through Google-authenticated profile/comment/feedback flows. For existing users, email is refreshed when they authenticate again through Google and trigger those identity-sync flows. This allows support-side identity verification and keeps profile identity records updated over time.

4. Private Service Key

Each non-owner community account may be assigned a private 16-digit service key. This key is shown masked by default, can be revealed/hidden, copied, and rotated. It is used for identity confirmation in support scenarios. The key is visible to the account owner on their own logged-in profile and to the site owner in the protected dashboard users panel.

5. Public vs Private Profile Data

Public profile pages may show your name, avatar, comment activity, contribution graph, and profile fields you choose to publish (title/bio/social links). Your email and service key are private identity fields and are not intended for public profile display.

6. Journal, Feedback, and Moderation Metadata

Community comments/feedback and related moderation metadata are stored in MongoDB Atlas. For abuse prevention and account safety, we may store first/last activity timestamps, IP, and country markers tied to account activity. This data is used only for platform integrity and owner moderation.

7. Authentication and Tokens

Sign-in is powered by Google OAuth 2.0 identity tokens. We verify Google credentials server-side for protected actions. We do not store Google access tokens or refresh tokens in the database. Browser-side session state may be kept in localStorage and naturally expires per token lifetime.

8. Third-Party Services

This infrastructure integrates with Google OAuth, Vercel hosting/runtime, and MongoDB Atlas database services. It may also use Google Favicon service for profile link icons. Use of these providers is subject to their own privacy terms and policies.

9. Data Security and Retention

API traffic uses TLS in transit and secured backend connections. We retain operational data as needed for site functionality, moderation, and support. You may request profile/content deletion by contacting the maintainer via the official support channels listed in SUPPORT.md.

10. Watermark Tracking Metadata

For websites that use the official Powered by Deep watermark script, we may process the submitted page URL, domain, favicon, optional tagline/title, status labels (pending/approved/declined), and visibility state (shown/hidden). This is used to verify attribution, prevent abuse, and manage showcase listings.

Hidden entries are retained for moderation/audit purposes but may be excluded from public project listings.

11. Policy Changes

This policy can be updated as features evolve. Material changes will be published on this page with an updated effective date.

System Node: LEG-PRIV-V3