LEGAL
Privacy Policy.
What we collect, why we collect it, and who else touches it. No dark patterns, no ad networks.
Effective July 21, 2026 · Last updated July 21, 2026
1. Who we are
This site is operated by Mystic Coders, LLC, a California limited liability company (“Mystic Coders,” “we,” “us”), based in Laguna Beach, California. This policy explains how we handle personal information collected through mysticcoders.com (the “Site”).
It covers the Site only. It doesn't cover client engagements, which are governed by the written agreement and any data-processing terms we sign with that client.
2. The short version
- We run no advertising networks, no third-party analytics, and no tracking pixels. There is no Google Analytics on this Site.
- We set one cookie, and only if you use the chat.
- We collect what you type into a form or the chat, plus your IP address for abuse prevention.
- We never sell or share your personal information for advertising.
3. What we collect
Information you give us in a form. Several pages host contact forms. Depending on the form, the fields are your name, email address, company, technology stack, the service option you selected, and your message.
Information you give us in the chat. The Site has an AI chat assistant, available as a widget on every page and as the primary interface on the contact page. We receive the messages you type. If a message contains something that looks like an email address or phone number, our system detects it and flags the conversation as a sales lead.
Technical information. Your IP address, which we use to enforce rate limits and block abuse. Our hosting provider also keeps standard server logs, including IP address, user agent, and requested URL.
We do not knowingly collect information from children under 13, and the Site is not directed at them.
4. The chat, specifically
The chat assistant deserves its own section, because it involves third parties and it remembers you.
Your messages leave our servers. To generate a reply, we send your message and the recent conversation history to Moonshot AI, the operator of the Kimi language model, whose API is hosted outside the United States. To find relevant background about our work, we also send your message to Upstash, a vector database provider. Don't type anything into the chat you wouldn't want processed by those providers — no credentials, no trade secrets, no personal information about anyone else.
We set a cookie. The first time you send a chat message, we set a first-party cookie named mystic_visitor_id containing a random identifier. It is HttpOnly, Secure, SameSite=Lax, and expires after 90 days. Its only purpose is to let the assistant recognize a returning visitor and pick up the thread. It is not an advertising identifier and it is not shared with anyone.
We store the conversation. Conversations are stored against that random identifier, along with a first-seen date, a last-seen date, a visit count, and any email address you provided. We retain the most recent 30 messages per visitor.
Leads reach a human. When you share an email address or phone number in the chat, we email that contact information and the conversation transcript to Andrew Lombardi at Mystic Coders, so a person can follow up. That's the point of the chat.
We keep a log. We retain a separate operational log of chat exchanges — the random visitor identifier, timestamp, page, your message, the assistant's reply, and any email address provided — which we use to review answer quality and improve the assistant.
5. Why we collect it
- To reply to you. If you submit a form or start a chat, we use what you gave us to respond and to evaluate whether we're a fit.
- To operate the Site. Serving pages, generating chat replies, and keeping things running.
- To prevent abuse. IP-based rate limiting stops automated traffic from draining our API budget.
- To improve the assistant. Reviewing logged conversations to find where it gave a bad answer.
Where the GDPR applies, our legal bases are your consent (when you choose to submit a form or use the chat), our legitimate interests in operating and securing the Site and in responding to business inquiries, and steps taken at your request prior to entering a contract.
6. Who else processes it
We use a small number of service providers. They process data on our behalf, under their own privacy terms:
- Netlify — hosting, form submissions, server-side storage, and server logs.
- Moonshot AI — the Kimi language model that generates chat replies. Processing occurs outside the United States.
- Upstash — the vector database used to retrieve relevant background for chat answers.
- Resend — delivery of lead notification emails to us.
We may also disclose information if legally required, or in connection with a merger, acquisition, or sale of assets. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
7. How long we keep it
- Chat conversations: 90 days from your last visit, capped at the most recent 30 messages.
- The visitor cookie: 90 days, refreshed by activity.
- Rate-limiting records: roughly two days.
- Chat quality logs: retained indefinitely unless you ask us to delete them.
- Form submissions and lead emails: retained as long as needed for the business relationship or inquiry.
8. Your rights
California residents have the right under the CCPA/CPRA to know what personal information we've collected, to request deletion or correction, and to not be discriminated against for exercising those rights. Because we don't sell or share personal information for advertising, there is nothing to opt out of — but you're welcome to confirm that with us.
If you're in the European Economic Area or the United Kingdom, you have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority.
To exercise any of these, email info@mysticcoders.com. If your request concerns chat data, include the conversation date and the email address you used so we can find it. We'll respond within the timeframe the applicable law requires.
You can also clear the mystic_visitor_id cookie in your browser at any time. Doing so ends the assistant's memory of your prior conversations.
9. Security
The Site is served over HTTPS, the visitor cookie is HttpOnly and Secure, and access to stored chat data is restricted. That said, no method of transmission or storage is perfectly secure, and we can't guarantee absolute security. Treat the chat as a public-facing channel, not a confidential one.
10. Third-party links
The Site links to services we don't control — our Substack, GitHub, LinkedIn, and Amazon author pages among them. Once you follow one of those links, their privacy policy governs, not ours.
11. Do Not Track
We don't track you across other websites, so there's nothing for a Do Not Track signal to change. We honor it by default.
12. Changes
We may update this policy. When we do, we'll revise the “Last updated” date at the top of this page. Material changes to how we handle personal information will be reflected here before they take effect.
13. Contact
Questions, requests, or complaints about privacy go to info@mysticcoders.com. Our Terms of Service cover everything else.