route.console
Status: ONLINE
paiva@jcpaiva.dev:~$cat ./privacy.config

Privacy, cookies & analytics

What this portfolio stores, why it is used, who receives it, and the controls available to you. Optional analytics stays off until you explicitly accept it.

Last updated: 12 August 2026
controller.profile

Who is responsible

José C. Paiva operates jcpaiva.dev from Porto, Portugal and is the controller for personal data submitted directly through this portfolio.

paiva@kriol.io
storage.manifest

Browser storage at a glance

  • jcpaiva_analytics_consent is a first-party cookie that stores your accept or reject choice for up to six months. It is necessary to remember that choice and render the correct privacy state before the page becomes interactive.
  • portfolio-concierge:* uses session storage only after you use the AI assistant, so the interface can recover the active browser-tab session.
  • portfolio_session_* is an essential, HTTP-only security cookie created only when you start an assistant session. It protects that session from unauthorised access and expires within 30 days.
analytics.optional

Google Analytics is opt-in

Google Analytics does not load and no analytics request is sent before you accept. If accepted, it measures page visits, session statistics, approximate location, browser and device information, and interactions with portfolio features. The legal basis is your consent.

Advertising storage, ad user data, ad personalisation, and Google Signals are disabled in the site configuration. Analytics uses first-party _ga and _ga_<container-id> cookies. This site configures them to stay scoped to the current host and expire after no more than six months from first acceptance, although browsers may shorten that period.

Google may process analytics data under its own service terms and international-transfer safeguards. Read Google's privacy policy and GA4 cookie details .

interactive.services

Contact and assistant data

When you contact José, the name, email, subject, message, and any project details you choose to provide are processed to answer your enquiry, prepare requested next steps, and maintain the security of the service. The basis is taking steps at your request and the legitimate interest in responding securely.

Contact messages are delivered through the configured email provider. AI-assistant messages are sent to the configured assistant and language-model service only when you open and use it. Assistant sessions are configured for deletion after 30 days; browser session storage clears when the tab session ends. Contact correspondence is kept only as long as needed to handle the enquiry, resulting correspondence, security incidents, or applicable legal obligations.

Google reCAPTCHA loads only after you initialize the contact form and is required to prevent automated abuse. Google may receive technical data needed to provide that verification under its privacy policy.

rights.execute

Your choices and data rights

You can accept, reject, or withdraw analytics consent at any time through “Privacy & analytics”. Withdrawal disables further collection and removes accessible Google Analytics cookies from this site. You may also request access, correction, deletion, restriction, portability, or object to eligible processing by emailing paiva@kriol.io. Withdrawing consent does not affect processing that was lawful before withdrawal.

If a privacy concern is not resolved, you can lodge a complaint with Portugal's Comissão Nacional de Proteção de Dados (CNPD) .

Contact José
privacy.config
Read the privacy and storage details