Public-site practices

Privacy and Security

How Moortekweb handles website visits, project inquiries, and Free Lead Check data.

Ordinary project inquiries

The contact form collects your name, email, optional phone number, business or project type, and the message you choose to send. It does not accept uploads, create an account, or process a payment.

Submissions are saved outside the public web files for Michael to review. They are not added to a marketing list.

Public-site operation

Cloudflare serves and protects the site and may process the request information needed to do that. Public demonstrations, images, audio, transcripts, and JSON reports are public by design.

The contact form limits request size, rate-limits repeated submissions, uses a bot honeypot, and rejects common secret and token patterns.

Free Lead Check

The check stores an opaque session, lead-workflow answers, version information, safety flags, and a preliminary result in an encrypted private database outside the public web files.

Raw message storage is off by default. Detected secrets, card numbers, private keys, and authentication values are blocked before model use or storage. Medical and other regulated identifiers are prohibited by the assessment terms but are not automatically detected — please do not submit them. Answers are processed on Moortekweb-controlled private AI infrastructure.

The check uses browser session storage under moortekweb_assessment_session_v1 to keep an opaque session identifier and session token available while the browser session remains open. Selecting Reset clears that session-storage entry.

The check sends same-site operational events to /conversion-event, including events such as opening, starting, progressing, completing, abandoning, or declining contact. Event records can include a one-way client hash, event and label, page path, document referrer, optional session identifier, extra event detail, and timestamp. The log has no time-based expiry: it is size-bounded and retains one rotated prior file. These records support reliability and funnel review, not advertising.

Contact details and receipts

Name, email, phone, and company are requested separately after the preliminary result and are not sent to the model. Cloudflare Turnstile protects that optional handoff.

If you explicitly ask for an email receipt, the authenticated Moortekweb Gmail account sends one fixed receipt without your assessment answers or model-written copy. Other email and calendar actions remain under human control.

Website Repair Desk

The Repair Desk collects a public website URL, name, email address, optional company, the free-text problem description, any outcomes you select, and whether you consented to contact. It stores the request in a private database outside the public web files for human review, quoting, status updates, and delivery evidence.

A successful request creates a hard-to-guess private status link containing the request identifier and access token. Keep that link private. The link continues to work until the request is deleted; repair requests currently have no automatic time limit. Use the project form to request deletion.

Retention and deletion

Abandoned anonymous sessions expire within 24 hours. Submitted lead records are retained for up to 90 days unless deletion is requested sooner. Encrypted local backups are retained for up to 30 days.

Use the project form to withdraw contact permission or request deletion, and identify the email used for the request. A receipt already delivered through Gmail may remain in the sender and recipient mailboxes until separately deleted.

Security questions

HTTPS and restrictive browser security headers protect the public site. Private tools, internal dashboards, and private workflow details are not placed in the public website files.

For a business inquiry or responsible disclosure, start with the published project form and keep the first message brief and non-sensitive.

Last updated July 28, 2026.