I've built this platform with privacy-first principles designed to align with DPDP, COPPA, and GDPR standards so your experience stays focused on exploration, not data collection.
The Vision
Expeditione is an Interactive 3D Encyclopedia built for the curious. My goal is to make learning an adventure, not a data-collection exercise. I believe in a web that respects its visitors by being transparent about what's under the hood.
What I Collect & Why
Expeditione is designed as a privacy-respecting, minimal-data platform.
I do not use Google Analytics or invasive behavioral tracking systems.
Cloudflare Analytics: I use Cloudflare’s privacy-focused analytics to understand basic aggregate metrics (such as total visits and performance). These analytics are designed to minimize personal data collection and do not track you across websites.
Anonymous Heartbeats (Tab-Scoped): To manage server resources and
understand engagement patterns at an aggregate level, I send a strictly anonymous "ping"
to Supabase every 30 seconds while you are actively viewing a page. This utilizes
a temporary, tab-scoped identifier (sessionStorage) that is
automatically erased when you close your browser tab. It is not a cookie,
does not track you across other sites, and is not tied to your personal identity.
This data is not combined with IP addresses or any identifiers that could be
used to re-identify a user, and it cannot be linked across sessions.
Email & Communication: If you join my mailing list or apply for a consultation, your data (such as name and email) is processed securely by my designated service providers, Kit (for mailing lists) and Web3Forms (for consultation form delivery). I use this only to communicate directly with you. I do not sell or trade your data.
Secure Payments: If you support Expeditione, payments are processed by Gumroad (Merchant of Record). I never see or store your credit card information.
Legal Basis for Processing
Where applicable under data protection laws:
- Email communication is processed based on your consent.
- Anonymous usage data is processed under legitimate interest to maintain and improve platform performance.
No profiling or automated decision-making is performed.
Global Children’s Privacy & Consent
Expeditione is an educational platform. While it may be accessed for general educational viewing, I take the privacy of minors seriously and do not knowingly collect Personally Identifiable Information (PII) from children under the age of 18 (the age of digital consent in the Republic of India and a strict standard I apply globally).
Age-Gating: Access to certain features (like the mailing list or direct contact forms) is protected by a neutral age-screening mechanism to ensure safety.
Data Purge: If I discover that I have inadvertently collected PII from a minor under 18 without verifiable parental consent, I will permanently delete that information from my servers immediately.
Global Data Rights
Regardless of where you live, I aim to extend the following rights to all visitors (aligned with GDPR, CCPA, and DPDP principles):
- Right of Access: You can ask me what data I have about you.
- Right to Rectify: You can ask me to correct any errors in your information.
- Right to Erasure (Forgotten): You can ask me to delete your data at any time.
- Right to Data Portability: You can request a copy of your info in a standard format.
- Right to Object: You can unsubscribe from my mailing list with one click.
International Data Transfers
Expeditione is operated from the Republic of India, but utilizes secure global infrastructure. Your information may be transferred, stored, and processed on secure servers located in the United States or other global regions by my trusted data processors (including Web3Forms for contact form processing, Supabase for database infrastructure, Kit for email communication, and Cloudflare for analytics and security). All data transfers are safeguarded by standard contractual clauses and strict encryption protocols.
Privacy by Design
I've built Expeditione to minimize data collection by default. Expeditione does not use non-essential cookies or behavioral trackers. Because the architecture relies entirely on strictly necessary session state, you will not find an intrusive Cookie Banner blocking the geometry. If the platform ever introduces non-essential tracking, this policy will be updated and explicit consent will be requested first. I believe in a web where you can explore without clicking "Accept" a dozen times.
Data Retention: I only keep your email for as long as you are on my list. Anonymous usage data is retained only as long as necessary for performance insights and system optimization.
Security: Information is protected using encryption in transit (SSL) and secure infrastructure at rest on Supabase.
Data Security & Incident Response: While I implement strong security measures, no system is completely immune. In the unlikely event of a data breach affecting your personal information, I will take appropriate steps to investigate, mitigate, and notify affected users if required under applicable laws.
Legal Disclosures & Law Enforcement
I respect your privacy and do not voluntarily share your personal data with third parties or government authorities.
However, I may disclose specific information if required to do so under a valid legal obligation, such as a court order, subpoena, or other binding legal process.
Privacy Desk & Grievance Redressal
Operated from: Republic of India
Under the DPDP Act (2023), you have the right to access, correct, or erase your personal data. Since Expeditione minimizes data collection, this primarily applies to my mailing list.
If you're on the mailing list, there is an "Unsubscribe" link in every email. For all other data inquiries or to exercise your rights, please contact my Privacy Desk:
aureon@expeditione.fun