Privacy

A small, privacy-conscious site

Microsoft Clarity behavior analytics loads only after you choose “Allow analytics.” Advertising storage is always denied, and the inquiry, thank-you, privacy, and other private or noindex pages are never recorded.

Behavior analytics

On public portfolio and service pages, Clarity can collect strictly masked clicks, scrolling, pointer movement, viewport and device details, performance information, and session playback. Liam uses these signals to understand which work people engage with and improve the site. Strict masking prevents page text and form values from being sent as readable content. Clarity is not connected to advertising accounts.

Inquiry attribution

The site keeps the first landing path, the referring site’s hostname, a readable source label, and standard UTM campaign fields in your browser’s session storage. Query strings, URL fragments, and full referring URLs are not retained. This information is sent to Liam only if you submit the inquiry form.

Linking an inquiry to a masked visit

If you allow analytics on an eligible page, the site creates a random per-tab session reference. Clarity receives that random reference—not your name, email, organization, or inquiry answers—and the same reference is included with an inquiry submitted in that tab. This lets Liam locate the related masked visit. Declining or withdrawing analytics clears the reference.

Inquiry information

The details you submit are handled by Netlify Forms and used to evaluate and respond to your request. Liam does not sell them or use them for advertising.

Personal Gmail reply routing

PhotoOS includes a private tool used only by Liam to copy genuine replies to tracked outreach from liam.swad@gmail.com to his NYU inbox. With Liam’s consent, it requests Gmail read-only access to identify the exact sent thread and incoming reply, and Gmail send access to create that one matched copy. It does not globally forward Liam’s inbox or delete, archive, label, or change settings in Gmail.

Message content is read only after a message is tied to a tracked outreach thread. Automated replies, mailing-list traffic, delivery failures, and unrelated inbox mail are excluded. Reply content is handled transiently while the copy is created and is not stored in PhotoOS. The local audit database keeps only the minimum Gmail identifiers, cryptographic hashes, timestamps, and routing state needed for deduplication and recovery. The OAuth refresh token stays in Liam’s macOS Keychain.

Google user data is used only to provide this personal reply-routing feature. It is not sold, used for advertising, shared with data brokers, or used to train a general-purpose AI model. The only content transfer is the matched reply copy to the NYU mailbox Liam controls. Access can be revoked at any time from Google Account connections. This use follows the Google API Services User Data Policy, including its Limited Use requirements. See the feature description.

Cookies, choices, and retention

No Clarity request is made before opt-in. If you allow analytics, Clarity may set analytics cookies so activity can be grouped into a session; advertising storage remains denied. You can change your choice at any time from the footer. Clarity ordinarily keeps playable recordings for 30 days and heatmap or click data for up to 9 months. Microsoft processes Clarity data under its Privacy Statement.

Questions or a data-removal request? Email whs9964@nyu.edu.