Back to home page

Privacy Policy

Privacy Policy for User Feedback System and Conversational Design Portfolio Application

Introduction:

We prioritize your privacy and are committed to protecting it. This policy explains how our application (the "Application"), encompassing the User Feedback System and the Conversational Design Portfolio Application, collects, uses, and safeguards your personal information.

Information Collection and Use:

Our Application collects the following personal information:

  • Name
  • Email Address
  • Company Name (if applicable)
  • Feedback message content
  • User Interactions with our digital assistant, including queries and responses
  • Session Data, including details of each session such as intent, messages, timestamps, and user feedback status

Purpose of Data Collection:

The collected information is used to process your feedback, personalize responses, improve user experience, understand user needs, and maintain interaction records for quality and training purposes.

Email Communication:

By providing your email, you consent to receive responses from our support team via the Gmail API (.../auth/gmail.send scope).

Data Storage and Protection:

Cloud Storage: We securely store conversations and feedback data in our cloud database.

Confidentiality: Access to your data is limited to authorized personnel with strict confidentiality obligations.

Data Encryption: We use encryption and other security measures to protect your personal information.

Sharing of Information:

We do not sell, trade, or transfer your identifiable information to external parties, excluding trusted third parties assisting in application operation, under confidentiality agreements.

Processors we rely on to operate the Application: OpenAI: your messages to the assistant are processed to understand your question, generate the reply, and screen messages for safety; safety flags are recorded as categories only (never your message text, unless you have introduced yourself); Google Cloud / Firebase: hosting, storage and authentication; and the Gmail API: sending feedback responses, as described above. Each processor receives only what its function requires.

Safety flags are recorded without any link to your identity: they carry no visitor identifier and cannot be joined to a profile. They therefore persist on their own retention clock, independent of the erase controls described below.

User Consent and Control:

Consent: where consent is the legal basis, we ask for it explicitly with a control that starts off: use of the site is never treated as agreement. Strictly-necessary operation (answering the question you asked, session handling) runs without consent because the site cannot work without it, and is described here rather than agreed to.

Access and Correction: You have the right to access and correct your personal information.

Behavioural Visit Mapping (three tiers):

Within a visit, for everyone: the portfolio adapts to you as you explore. This mapping is first-party, session-scoped and never cross-site: it observes what you do during the current visit under a random session identifier, sets no persistent identifier on your device, and everything identifying about the session is deleted automatically when it ends: records carry a 24-hour expiry enforced by our database's time-to-live policy, and session identifiers rotate, so nothing can be joined to you later. An "Erase this session" control is always one press away in the ◈ Intent chip and deletes the current session's records immediately.

What the site keeps from anonymous visits: shapes, not people. Before deletion, a session's journey may be condensed into a keyless record of its shape: the ordered sequence of journey stages and intents with coarse timing buckets, and coarse conversation-derived categories (the topic area, the type of question, a per-step sentiment) drawn from closed lists, and never the content of your messages, quoted, paraphrased or summarised. These records contain no session identifier, no visitor identifier, no IP address, no device key and no exact timestamps, cannot be joined to each other or to anyone, and journeys with a shape rarer than a small threshold are withheld from every view so an unusual path cannot single anyone out. These anonymous shapes, together with anonymous counts (intent frequencies, drop-off rates, error rates, coarse device mix), form the aggregate statistics the portfolio's owner learns from.

Across visits, only if you introduce yourself: the start screen (and the ◈ Intent control) offers three optional fields: your name, your role and your business. Submitting them is your consent: it sets one first-party cookie holding a random visitor id (kept for 90 days, renewed when you return, created only at that moment, never before) and creates an identified profile so the portfolio can recognise you and tailor the experience to your role. When identified, the profile includes your name, role and business, the pages and case-study depths you open, media you view, the intent recognised on each turn with its journey stage, coarse device context, and the content of your conversations with the assistant, which may be analysed as part of that profile. Introducing yourself also keeps what you have done so far in the current visit. Earlier visits were already deleted and stay deleted. The experience without introducing yourself is identical apart from the remembering; you will not be re-prompted.

Retention: the identified profile is kept for 90 days per device, matching the cookie.

Google Analytics, in consent mode: until you introduce yourself it receives, from our server, the same anonymous session-scoped interaction events we keep for 24 hours, under a hashed session number: no cookie is set by Google, every storage flag in your browser stays denied, and it holds no identifier of yours. Introducing yourself is the consent that lets it set its own analytics cookie; erasing withdraws it. Nothing is shared with Google for advertising, and Google signals are off.

Erase: the "Erase everything collected" control (always available from the ◈ Intent chip) deletes your name, role and business, the cookie, the profile, every derived analysis, and every behavioural link to your conversations in one action. The conversations themselves remain stored for the functional purposes above, but nothing behavioural references them any more.

Retention of Data:

Retention Period: Your personal information is retained only as necessary for the purposes stated in this policy or as required by law.

Anonymization: We anonymize data where possible for analysis.

Changes to our Privacy Policy:

We may update this privacy policy at any time, with changes taking immediate effect upon posting. We encourage frequent review of this policy for updates.

Contacting Us:

For questions regarding this privacy policy or your personal data, please contact us at zampognamichelangelo@gmail.com.

Cookies Policy:

Every cookie this Application sets is first-party. We use no third-party cookies at all: no third-party analytics, no advertising cookies, ever; video embeds use YouTube's no-cookie player for the same reason. Cookies are small text files placed on your device; ours are exactly these:

  • Session identifiers (strictly necessary): temporary session handling for the visit and for the conversation surface, so the conversation you are having stays yours; they rotate, and their records expire as described above.
  • The behavioural visit-mapping identifier (optional): set only after you introduce yourself, never by default; kept 90 days, renewed when you return, described in full above.
  • An authentication cookie for the site owner's admin sign-in, never set for visitors.

We use session cookies (temporary), and, only with your explicit consent, the one persistent cookie above. There is nothing else.

No third-party cookies means exactly that: no partner, analytics or advertising cookie is used for any purpose, and nothing on this site is subject to another company's cookie policy.

You can manage or remove cookies through your browser settings at any time; removing the strictly-necessary session cookie simply starts a fresh session.

Strictly-necessary cookies (session handling) are set because the Application cannot function without them, and are described here. Any cookie that is not strictly necessary, such as the behavioural visit-mapping identifier above, is set only after you explicitly switch it on, and never by default or by implication from use.

The controls live where you are: the ◈ Intent chip carries the introduction, the erase controls and the details. There is no separate cookie-preferences page because there is nothing more to configure.

Policy Last Modified on 5 August 2026.