Privacy Policy
This describes what Commandant Vault actually collects today, in plain terms. No accounts, no login, no personal profile is ever required to browse, search, or download.
What we collect
When you accept the first-party analytics prompt, Commandant Vault records, for the duration of your browser tab:
- A random session identifier generated in your browser, held only in
sessionStorage— never a cookie, never sent to any third party - Page views: which pages you visit and when
- Resource and folder views, and file downloads
- Search queries you enter, whether they returned results, and whether the search was site-wide or limited to one folder
- The hostname of the site that referred you (e.g. “google.com”) — never the full referring URL
utm_source,utm_medium, andutm_campaign, if present in the link you followed- The first page you landed on in that session
If you refuse or haven’t yet responded to the analytics prompt, none of the above is collected — the site works identically either way, including search and downloads.
What we deliberately do not collect
- No IP address is stored by Commandant Vault’s own analytics (see the infrastructure note below for what that doesn’t cover)
- No browser/device fingerprinting of any kind
- No persistent cross-visit identifier, no cross-site tracking, no cross-device tracking
- No third-party analytics or advertising trackers are active today
- No account, no email address, no personal profile is required or built
Storage mechanism and consent
Your consent choice (accept or refuse analytics) is stored in your browser’s localStorage so you aren’t asked again on every visit. The analytics session identifier itself is stored only in sessionStorage, which your browser clears automatically when the tab closes — it does not persist from one visit to the next. See the Cookies page for the full technical breakdown, including why this is a real, functioning consent mechanism rather than a decorative banner.
Retention
Session-level analytics (sessions, page views, search queries) are targeted for retention of approximately 6 months, after which older raw records are intended to be deleted. This is a documented operational target, reviewed and applied manually rather than by an automated schedule at this stage.
Staff activity is excluded
Commandant Vault has a small internal staff team that manages content. Their own signed-in browsing, testing, and administrative activity is deliberately excluded from every visitor analytics figure, so internal work never inflates the numbers describing real visitors.
Infrastructure
Commandant Vault runs on:
- Vercel — application hosting
- Supabase — database, authentication (staff only), and file storage
These providers necessarily process standard infrastructure-level data (such as connection information) to deliver their service, under their own respective privacy policies and logging practices — this is outside Commandant Vault’s own analytics described above, and we do not control or claim to know the exact contents of infrastructure-provider logs. We do not instruct either provider to collect anything beyond what operating the site requires.
Future advertising (not active yet)
Commandant Vault may introduce advertising in the future (for example, Google AdSense) to help sustain the project. No advertising technology is active today, and nothing above describes an advertising system, because there isn’t one yet. Before any advertising technology is enabled, this Privacy Policy and the consent mechanism described on the Cookies page will be updated accordingly, including a dedicated advertising-consent flow where required.
No sale of data
Commandant Vault does not sell, rent, or trade personal data or analytics data to any third party.
Your rights and how to reach us
You can change your analytics consent choice at any time using the “Privacy choices” link in the site footer. For questions about this policy, or any request regarding data described here, contact: contact@commandant-vault.com.