Privacy & data use
Clear about what is processed.
This portfolio uses limited personal data to provide its contact form, authenticated LEO assistant, security controls, and requested email delivery.
Last updated: 30 July 2026
Public contact form
When you submit the contact form, your name, email address, optional subject, and message are processed to deliver an email to Andreas. The website does not add this information to a mailing list or sell it.
Contact-message content is not stored in DynamoDB or application logs. The delivered email may remain in Andreas’s private inbox for normal correspondence and record-keeping.
LEO authentication and conversations
LEO requires Amazon Cognito authentication. The application uses short-lived session tokens in browser session storage to maintain your signed-in session.
Questions and answers are processed by Amazon Bedrock to provide the requested response. The portfolio application does not intentionally store conversation messages or chat history.
Transcript email
If you select “Email this transcript,” the conversation currently held in your browser tab is sent to your verified Cognito email through Amazon SES. The transcript is sent only at your request and is not retained as chat history by the website.
Temporary security and usage records
The website keeps temporary, pseudonymous counters to enforce contact-form limits, five-minute LEO sessions, question limits, and transcript-email limits. Contact email and IP values are hashed before being used in rate-limit records.
These records contain counters and expiry timestamps—not message content—and are automatically scheduled for deletion using DynamoDB Time to Live.
Security verification
The contact form uses Cloudflare Turnstile to distinguish legitimate visitors from automated abuse. Cloudflare may process technical browser and interaction information needed to perform that verification under its own privacy terms.
Operational logs
Minimal diagnostic logs may contain a request identifier, API route, response status, response size, latency, and service error details. They exclude request bodies, chat messages, contact content, email addresses, authorization tokens, and visitor IP addresses.
Operational logs are configured for a 14-day retention period.
Service providers
The portfolio uses Amazon Web Services for hosting, authentication, API processing, AI inference, temporary counters, monitoring, and transactional email delivery. Cloudflare provides contact-form bot protection. Porkbun provides domain registration, DNS, and forwarding for the public domain email address.
These providers may process information outside Singapore under their applicable privacy and security terms.
Your choices
You can browse the public portfolio without signing in. Contact-form use, LEO authentication, and transcript delivery are optional. Close the browser tab or sign out to remove the current browser session.
For a privacy-related enquiry, use the public contact form and state “Privacy enquiry” in the subject.