Site policies · Goh Kun Ming
Privacy notice
What this portfolio stores, what leaves your browser, and the choices you control.
Updated:
Who is responsible and what this notice covers
This is Goh Kun Ming's personal portfolio, based in Singapore. You can contact me about privacy at kunmingaden@gmail.com. This notice describes the portfolio application and the information you choose to send me; it does not replace the privacy notices of your browser, email service, hosting provider or websites you visit through a link.
The portfolio is static by default, with no visitor accounts, payments, advertising, analytics trackers or contact-form service. It sets no application cookies. The local guide processes questions in your browser. AWS is the selected hosting and optional live AI service. This release prepares that connection; live AI remains disabled pending activation and deployed checks. Loading pages and assets still makes ordinary network requests.
Settings and exploration saved on your device
The application uses your browser's local storage to remember optional display, navigation and audio choices. These records are kept for this website in that browser; the application does not upload them or use them to build a visitor profile.
Local storage has no expiry set by this application. It can remain until you clear the website's data, your browser removes it, or the relevant saved value is replaced. Private browsing and browser settings may limit persistence. If storage is blocked, the portfolio remains usable and applicable settings work for the current page visit.
- Reading preferences: plain reading font, stronger contrast, reduced motion and keyboard shortcuts.
- Scenery preference: whether you paused the background scenery.
- Exploration progress: visited sections used for the local progress display, and whether the optional mining activity was completed.
- Language preference: your selected website language.
- Audio preferences: background music and click-sound settings, each channel's volume, and whether audio is muted.
The local guide and its conversation history
In local mode, the guide uses application rules to look up the portfolio's published information. It is not a live AI model or a messaging service, and a question does not contact me. Questions and topic context in this mode are processed in your browser and are not sent to the live AI provider.
The guide saves up to the latest 20 questions, with at most 500 characters per question, and limited topic context in session storage. Answers are rebuilt from the current portfolio information instead of being saved as a separate transcript. The history can survive reloads in the same tab. A browser's session restoration may restore it; closing a tab is therefore not a reliable secure-deletion method.
Use Clear chat to remove the guide's saved history and current conversation. If the browser refuses removal, the guide displays a warning that saved history may remain. You can then use the browser's controls to clear this website's data. Avoid entering passwords, identification numbers, confidential work information or other sensitive details.
Copy conversation writes the displayed conversation to your clipboard only when you choose it. Download conversation saves a text file through your browser only when requested. The website does not read your existing clipboard or upload these exports. Clear chat does not remove a downloaded file or a copy you have made elsewhere.
Optional live AI through AWS Bedrock
Every page load starts in local mode. Live AI is unavailable unless the optional server is configured. If available, you must explicitly enable it and send a question. Requests for the published résumé and academic transcript are answered locally in your browser, even in live mode, without a model request. Those local exchanges can be included among the bounded prior exchanges sent with a later live question. For other live questions, the website sends your question (up to 500 characters), up to six prior exchanges from the live AI conversation, your selected language and current section through its same-origin API to Amazon Bedrock. The browser request is limited to 16 KiB of UTF-8 data. Local-mode history is never included. The server also supplies selected published portfolio facts and available PDF text excerpts, generated search queries, and bounded references to previously cited sources so Amazon Bedrock can answer. It does not browse external websites to answer.
Up to 20 live AI exchanges remain only in this page's memory; model replies are not saved in session storage. Reloading clears them and returns to local mode. Clear chat clears both conversations and aborts the active request, but cannot undo processing already started. The application does not store conversation text in a database or write questions or replies to its logs. One live question can involve up to three model calls.
Amazon Bedrock processes the question and selected context. AWS describes default protections against retaining prompts and replies or sharing them with model providers, but model-specific rules, abuse review and account logging settings can create exceptions. This notice does not promise zero provider retention. Model and account settings must be checked before live AI is enabled. Current AWS rules: https://docs.aws.amazon.com/bedrock/latest/userguide/data-protection.html and https://docs.aws.amazon.com/bedrock/latest/userguide/data-retention.html .
The prepared AWS service converts the visitor IP address into a keyed hash for shared abuse counters; it does not store the raw IP in those application records. A hash is a pseudonymous identifier, not a guarantee of anonymity. IP counters have a 24-hour expiry, hashed request and attempt markers a two-day expiry, and aggregate daily counters seven- or 90-day expiries. Aggregate monthly usage totals and control settings have no automatic expiry. These records contain no question or reply text. DynamoDB expiry schedules deletion; removal may take several days.
The prepared configuration keeps database recovery history and operational function logs for seven days. Recovery history may contain counter records after their live expiry. The application does not deliberately log conversation text, and it does not enable Bedrock invocation logging; account-level logging must still be checked before activation. These are configured retention periods, not a promise of immediate erasure from every AWS system.
You can leave live AI off and use the local guide. Do not submit confidential or sensitive information. Clearing this page cannot retract information already sent to AWS or erase exported copies or provider records. The selected global inference service may process a request outside Singapore. Public deployment, provider settings and processing arrangements still require verification before activation.
Email, external websites and hosting
Email links open your configured email application; no email is sent until you send it there. Published résumé and academic-transcript links open or download public PDF files and do not send email. If you email me, I receive your address, the message and any attachments or other details you include. I use that information to handle your request and related correspondence. Email providers process the message under their own terms. The copy-email button only copies my public address to your clipboard when your browser allows it; the site does not read your existing clipboard contents.
Links to GitHub, LinkedIn, publications and other services take you to separately operated websites. Their data practices apply when you visit them. The application does not embed their tracking widgets or send them your local guide history.
Optional audio plays through your browser. The background track is requested from this website's own host only after you choose to start or enable audio; it is not loaded from a streaming service. Click sounds are synthesised locally. Audio features do not use your microphone, record sound or send listening analytics. The host may handle the ordinary media request as described below.
AWS is selected to deliver this site through CloudFront's global network, with the application and counter database configured in Singapore. Delivery and security can involve IP addresses, request times, paths and browser information. Global AI inference may process requests in other AWS regions, so this is not a promise that all information stays in Singapore. The application adds no analytics tracking. Actual hosting, logging and provider settings must be verified before public activation; local browser storage is separate from hosting records.
Your choices and privacy requests
You can change reading, language and audio preferences through the website's controls, pause scenery, clear the guide conversation, or remove all local records using your browser's site-data settings. Reset display options resets the display preferences; it does not clear exploration progress, scenery pause, language, audio preferences or guide history. Removing local site data does not remove an email you already sent or records held by a hosting provider.
For information you have sent me, you may contact kunmingaden@gmail.com to request access, correction, deletion or withdrawal of permission for further use. Please identify the relevant correspondence without sending unnecessary identity documents. I may need proportionate information to verify a request. Applicable law, records needed to deal with the request and legitimate legal retention requirements may affect what can be removed.
Retention of correspondence depends on the purpose of the exchange and any applicable legal requirements. No fixed mailbox retention period is stated for this release. Contact me to discuss the information relevant to your request; hosting records are subject to the arrangements described above.
Changes to this notice
The version date identifies these practices. Before a material change to data handling takes effect, I will describe it on this page and in the affected feature. Where a new use requires your consent, I will ask before that use begins. Adding analytics, a contact form or changing AI providers requires review of this notice before use. Translated editions describe the same practices; please report unclear or inconsistent wording.
2026-09-21: This edition explains the published portfolio facts and PDF excerpts used by live AI, clarifies request limits, and adds this visible change summary.
2026-09-22: This edition distinguishes email links from public résumé and transcript PDFs, and explains local document replies in live mode and their possible inclusion in later live AI context.
2026-10-06: This edition clarifies fictional background artwork and timed-scenery controls. These presentation changes do not add visitor tracking or change the disclosed data practices.
2026-10-08: This edition describes the selected AWS hosting and optional Bedrock service, possible processing outside Singapore, and the prepared abuse-counter, expiry and recovery arrangements. Live AI remains disabled pending activation checks.