Aerod handles public IP visibility, browser exposure, fingerprinting surfaces, DNS and WebRTC behavior, proxy and VPN consistency, media-device permissions, affiliate redirects, Analytics, advertising, and security guidance. The default posture is data minimization and denied optional storage.
Static content and infrastructure
Most pages are static. Normal hosting infrastructure can process request metadata needed to deliver, secure, cache, and debug the site. Cloudflare Functions also enforce canonical-host redirects and receive sanitized CSP violation reports.
IP, browser, route, and media checks
IP Lookup requires network requests to obtain public route and intelligence data. Browser, WebRTC, fingerprint, and proxy/VPN checks run locally where practical and describe the current session.
The Online Webcam Test uses browser permission for local preview, input monitoring, and user-initiated local capture. Aerod does not require live camera or microphone streams to be uploaded.
Consent and optional Google services
Aerod creates a local aerod-consent-v2 record containing the Analytics choice, advertising choice, schema version, and update time. The legacy Analytics preference is maintained for compatibility.
Consent Mode v2 starts with Google Analytics and advertising storage denied. The Google Analytics GA4 tag loads only after Analytics is granted. The AdSense library can load while pauseAdRequests remains enabled. Advertising requests resume only when the local advertising choice is granted and the applicable certified consent signal permits them.
The AdSense account must publish a Google-certified privacy message where required. Aerod does not treat a local preference as a substitute for an applicable TCF consent signal.
Affiliate redirects
/go/<slug> routes select approved third-party destinations. Redirect and infrastructure logs should be retained only as needed for operation, security, debugging, compliance, and aggregate reporting.
Contact submissions
The contact form sends a reply email address, topic, message, and optional name, affected page URL, and up to three image or PDF attachments to Aerod by email. Attachments may total no more than 5 MB. A private Cloudflare service validates submissions, verifies Turnstile, applies rate limits, and delivers only to Aerod's administrative inbox.
Submission bodies and attachments are handled in memory and are not intentionally written to application logs, a separate submission database, or public storage. The service logs outcomes and reference IDs. Cloudflare and the receiving email provider can process delivery and security records, and delivered messages remain in the inbox as needed for the request and related obligations. File-type checks are not malware scanning. Do not send credentials, private keys, malware samples, or unnecessary personal information.
CSP reporting
The enforced Content Security Policy can submit violation details to /csp-report. The function limits logged fields and does not intentionally create a user profile from reports.
Scheduled quality monitoring
Production audits can crawl sitemap routes, test performance, and check recorded evidence-source availability. Reports are build or workflow artifacts and should not be published as personal profiles.
Publication records
Aerod keeps internal source and provenance records to protect route continuity and publication metadata. These operational records are not user profiles and are not exposed through article pages.
Review standard
Any new app, tag, consent message, redirect, CSP change, provider, or content process must be reviewed against this model before publishing.
Privacy preferences
Use Privacy Preferences to change or clear the local optional-service choices.