Privacy and data controls

A useful portfolio without hidden surveillance.

This notice explains the limited information this site collects, why it is useful, how long it remains, and how you can delete it.

Effective July 29, 2026 · Version 2026-07-29

First-party visitor analytics

The site may record allowlisted events such as a page view, opening or submitting a public feature, or starting a resume download. Events may include the public page, referral origin, UTM campaign fields, coarse country and region, device and browser category, and a random identifier kept only in your current browser session.

Analytics never contain your chat question, job posting, contact message, contact fields, full user agent, raw query string, or a browser fingerprint. The application does not retain your raw network address as an analytics identifier. Anonymous events expire after 90 days. Browser Global Privacy Control and Do Not Track signals disable these analytics events.

Contact messages

If you use the contact form, the site stores your declared role and intent, message, optional contact details, disclosed attribution and device context, consent time, and policy version. Reply email is optional; Tyler cannot reply if you do not provide one.

The online contact record remains for at most 24 months. Marking it resolved or spam shortens its online retention to a one-day deletion grace period. Tyler also receives a plain-text email copy containing the message and disclosed context. That email may remain for up to 12 months.

Role analysis and Ask Tyler

A submitted job posting, optional contact context, evidence match result, consent record, and management-token digest may remain for up to 12 months. The limited administrator email digest does not contain the complete posting and may remain for up to 12 months.

Ask Tyler processes your question and recent conversation context to produce an evidence-grounded response. The application currently records only redacted usage and cost metadata for this feature, not the question or answer as visitor analytics.

Deletion and full erasure

Contact and role-analysis submissions return a random management token to your browser. While that token remains in the browser session, you can immediately delete the online record without creating an account. The server stores only a one-way digest of the token.

Deleting an online record does not automatically delete an email already delivered to Tyler. For full erasure, email tylerjkonesky@gmail.com with the contact or analysis identifier so the corresponding email copy can also be removed.

Deleted records may remain temporarily in encrypted point-in-time disaster-recovery backups until the AWS recovery window expires. Those backups are not used for ordinary access or analytics. A non-identifying deletion marker containing only the record identifier and deletion time remains for 45 days so a disaster recovery can reapply the deletion before restored data is used.

Security and choices

Public submissions are encrypted in transit and at rest, strictly validated, rate limited, time bounded, and accessible to the administrator only through server-enforced authentication. Visitor analytics and the contact form can be disabled independently without making the public portfolio unavailable.

You can browse the portfolio without providing a name, email, company, job posting, or contact message. You may also email Tyler directly instead of using the contact form.