Privacy

No tracking. Only what an inquiry needs.

axis-core.dev runs no analytics and sets no cookies. The one place information is collected is the private inquiry channel, which keeps only what it needs to verify a sender and route an inquiry — and deletes it on the schedule below.

The public pages

Nothing is stored in your browser

The public pages set no cookies, use no local or session storage, and load no analytics, advertising or tracking scripts. Every page asset is served from this origin. Reading the site sends AXIS Core nothing beyond the ordinary request described under Logs.

The one third-party component is Cloudflare Turnstile, the robot check on the inquiry channel. It loads only on /contact/, and only after you choose to unlock robot verification on a completed inquiry.

The inquiry channel

What an inquiry collects

The inquiry channel on /contact/ collects the following, and nothing else. There is no phone field, no attachment or upload of any kind, and organization and corporate email are never required.

Who you are

  • Full nameRequiredYour name, so a reply can address you.
  • EmailRequiredYour email address — verified before anything is delivered, and used as the reply-to on the routed inquiry.
  • OrganizationOptionalOrganization, if you give one. Never required.
  • Role / titleOptionalRole or title, if you give one.
  • Country / regionOptionalCountry or region, if you give one.
  • Professional website or LinkedInOptionalA professional website or LinkedIn address, if you give one. Only public http(s) addresses are accepted.

How it is routed

  • Nature of inquiryRequiredThe nature of the inquiry, chosen from a fixed list; it decides the private route.
  • Describe the other inquiryRequired for OtherA short description, only when the nature of inquiry is Other.
  • Relevant planeOptionalThe relevant plane, if you choose one.
  • Relevant capabilityOptionalThe relevant capability, if you choose one.
  • Timeline / urgencyRequiredThe timeline or urgency, chosen from a fixed list.

The inquiry

  • Inquiry / project contextRequiredThe inquiry itself — the context you write.

Security reports only

  • Affected AXIS CORE surfaceRequired for security reportsThe affected AXIS CORE surface (security reports only).
  • Severity assessmentOptionalYour severity assessment, if you give one (security reports only).
  • Impact / reproduction summaryRequired for security reportsAn impact and reproduction summary (security reports only).
  • Reference URL or identifierOptionalA reference URL or identifier, if you give one (security reports only).

Recorded by the service

  • Consent timestampWhen you gave consent on the form.
  • Verification stateWhether and when your email address was verified, and whether delivery succeeded.
  • Request countryThe two-letter country code Cloudflare attaches to the request, kept with the inquiry for abuse triage.
  • Robot-verification resultThat Cloudflare Turnstile passed for this submission — pass or fail only.

Your IP address is used while a request is handled — to compute a keyed hash for rate limiting and in the robot-verification check sent to Cloudflare — and is not stored with the inquiry. The verification token in your email link is stored only as a keyed hash. Security-report fields are accepted only when the nature of inquiry is Security / Vulnerability Disclosure; on any other inquiry they are discarded.

Why it is collected

Verify, route, respond, protect

Solely to verify that the sender controls the email address given, to assess and route the inquiry to the AXIS owner for its scope, to respond where appropriate, and to protect the intake from abuse.

Nothing collected here is used for advertising or marketing, added to a marketing list, built into a profile, sold, or used for tracking-based profiling of any kind.

Who handles it

Named infrastructure, nothing more

Cloudflare serves this site, runs the separate inquiry service and its database (a Cloudflare Worker and Cloudflare D1), and provides the robot check (Turnstile). Turnstile runs in a frame served by Cloudflare under Cloudflare’s own Turnstile privacy terms; AXIS Core receives only whether the check passed, for which hostname and form.

A transactional email provider — currently Resend — sends the verification message, delivers the verified inquiry to a private AXIS mailbox, and sends you the acknowledgement.

These providers handle the information to perform those functions. AXIS Core does not share it with anyone else.

How long it is kept

Deleted on a fixed schedule

  • A verification link is valid for 30 minutes and works once. At most 3 verification emails are sent for one inquiry.
  • An inquiry that is never verified cannot be verified or resent after 60 minutes. Any inquiry that is not delivered — unverified, expired or failed — is deleted in full, record and content, 2 hours after submission. Deletion runs every 60 minutes, so nothing undelivered is kept beyond 3 hours.
  • When a verified inquiry is delivered, everything you entered — including your email address — is removed from the service’s database in the same step. A minimal record remains for 30 days — reference, category, route, status, timestamps and the number of delivery attempts — for delivery status, protection against duplicate delivery and troubleshooting, and is then deleted.
  • Rate-limit counters hold keyed hashes, never an address in readable form. A counter is deleted by the first cleanup after its 60-minute window ends, so none is kept beyond 2 hours.
  • Deletion removes a record from the service’s live database at once. Cloudflare D1 also keeps a point-in-time recovery history of that database (Time Travel) for up to 30 days, from which a deleted record could be restored by the service’s operator until that history ages out. It is not otherwise readable, and AXIS Core does not restore deleted inquiries.
  • The delivered inquiry is correspondence in a private AXIS mailbox, kept as long as needed to assess and answer it and to keep a record of it. The email provider keeps its own delivery logs under its own retention.

Logs

Operational records only

This site and the inquiry service are served through Cloudflare, which records ordinary request data such as IP address, user agent and requested path in order to deliver and protect them. AXIS Core does not build profiles from those records or combine them with anything else.

The inquiry service writes operational log lines — an event name, the inquiry reference, the route and a reason code. They never contain your name, email address, message or verification link.

Questions and deletion

Through the same channel

Questions about this notice, or a request to delete an inquiry sooner, go through the same private channel on /contact/ — include the inquiry reference from your acknowledgement if you have one. AXIS Core publishes no receiving address.

If anything described here changes — a field, a provider, a retention period — this page changes in the same release. The collection list and the retention figures above are rendered from the inquiry service’s own contract, and the build checks that they match.