Privacy Policy
Last updated: August 2026
What this site is
Lo-fi Harbor is a personal portfolio: a canvas harbour, public CV pages, and MØ, a robot that answers questions about Mohammad Farhadi. There is no account signup for visitors. One owner signs in to edit content.
Information we collect
Visitors
- Server logs. Like most sites, the host may record IP address, user-agent, requested URL, and time. Used to keep the site up and to investigate abuse — not for advertising profiles.
- Chat with MØ. Questions you type are sent to the backend so MØ can answer from the résumé corpus. Conversation turns are stored so a thread can continue. Do not paste secrets into the chat.
- Harbour preferences. Season, weather, and volume choices may be saved in your browser (
localStorage) so they survive a refresh. They never leave your device. - Weather (optional). On enter, local clock and calendar seed the starting time of day and season. After that the harbour cycles on its own. Rain/snow can match your real weather at that first moment only if you allow location; coordinates are sent to Open-Meteo and are not stored on this site. If you decline, the harbour still starts from your clock and then runs its cinematic loop.
Visitors are not asked to create an account. There are no tracking or advertising cookies.
Owner (Mohammad)
Signing in to The House sets httpOnly session cookies (lfh_access, lfh_refresh): SameSite=Strict, Secure on HTTPS. The access cookie lasts 15 minutes; refresh lasts 7 days and rotates. Content edits are versioned (actor, IP, diff) on the server. A password change signs out every session.
Cookies
Visitors: none required. Owner session cookies are httpOnly (not readable by JavaScript) and are not used for ads. Chat does not set a tracking cookie.
How we use information
- Run and protect the site
- Answer MØ questions from the published résumé and portfolio content
- Let the owner edit that content
- Optionally seed harbour weather from a location the visitor chose to share
Sharing
We do not sell or rent personal data. Chat answers are produced by a language-model API (currently Google Gemini) using retrieved résumé chunks — your question is sent as part of that request. Weather, if enabled, is fetched from Open-Meteo once on enter. Hosting, DNS, and logs may be processed by the VPS and CDN providers that serve this domain.
Security
Owner routes require a verified session cookie. Passwords are hashed with argon2id and never stored or logged in plaintext. No method of transmission is perfectly secure.
Changes
Updates will be posted on this page with a new "Last updated" date.
Contact
Questions: farhadimohammad6069@gmail.com