Privacy Policy

This policy covers sunnypatneedi.com, a personal site for Sunny Patneedi. It does not cover SayMake, which is a separate service with its own privacy policy and protections for children.

The short version

This personal site has no advertising or advertising pixels. Optional, cookieless analytics on Work with me is disabled unless configured, and respects Do Not Track and Global Privacy Control.

No analytics cookies or persistent browsing identifiers are stored. When configured, Work with me sends page views and form or payment-link interaction events to PostHog. A random identifier held only in page memory groups those events. No names, email addresses, form text, or referring URLs are sent to analytics. Payment-link clicks are not evidence of completed payments.

Private resume links and local settings

Each time a valid labelled private resume link is rendered, a separate page-view record is created. Revisiting or refreshing the link creates another record. A record contains the resume version that was opened, the browser user-agent string, the referring URL if the browser sent one, and a random per-view token. The token is generated fresh for each view, is not derived from an IP address or device, and cannot be linked to another visit. IP addresses are not recorded.

The site uses browser local storage in limited cases. After a successful passcode unlock for a protected resume, it stores a resume access token so the browser can validate access on a later visit; the token is sent only to the resume access service when validation is needed. The site owner’s timeline editor may also save timeline drafts in that browser. Those drafts are an authoring convenience and do not change the public timeline. Any local data can be cleared through browser settings.

Intake requests

When you send an intake request, I collect the contact details, company and role, links, product context, engagement and payment preferences, and notes you choose to submit. Referral information includes campaign parameters and the referring page, when available. These details are used only to respond to your request and arrange the conversation.

Requests are delivered through Resend to my email inbox. There is no intake database. Emails are deleted after 12 months, or after 90 days if I decline the request. This includes delivery-provider and inbox copies. You can ask for earlier deletion by replying to the acknowledgement.

Abuse controls use a salted hash of your IP address, not the raw address. The intake page has no advertising pixels. Do not include passwords, credentials, or confidential customer data in the form.

Children, sharing, and choices

This site is directed to adults such as recruiters, founders, investors, and collaborators. It does not offer accounts to children and does not knowingly collect personal information from anyone under 13. If a child has provided information through this site, contact Sunny to request deletion.

The site runs on Replit. Supabase stores existing resume-related site data, not intake requests. Resend delivers intake emails, and PostHog receives optional analytics events when configured. Nothing is sold, shared with advertisers, or used to build a visitor profile. A visitor can request information or deletion of a resume-view record by referencing the private link they received; because the record has no direct personal identifier, that link may be needed to locate it.