What we collect

When you visit a page on mogambo.info, the following is recorded by our self-hosted analytics:

We do not collect: your full IP address, your name, your email, your device fingerprint, your behaviour across other websites, or any personally identifying information.

Your analytics controls

Even though our analytics is cookieless and stores no personal data, we honor two opt-out signals. If either is active, the analytics script never loads on your device and nothing is sent.

  1. Do Not Track. If your browser sends the DNT: 1 header (Firefox, Brave, and some Edge/Safari configurations support this in their privacy settings), we automatically suppress analytics. No action needed from you.
  2. One-click toggle on this page. Click the button below to opt out (or back in) for this device. Your choice is stored in your browser's localStorage and persists across visits until you clear site data.

What we don't do

How we secure the site

Independently verified, not just claimed

You don't have to take our word for the security posture above. Three independent scanners report the following grades against https://mogambo.info/ as of 2026-05-15:

Re-run any of these whenever you want a fresh read. The grades are not paid placements; they reflect what response headers and TLS config the scanners actually observe.

What CSP and HSTS preload actually protect against — and what they don't

Scanner grades sometimes get summarized as "strict CSP and HSTS preload make the site virtually immune to XSS and MITM attacks." That's overstated, and we'd rather call out the residual risk explicitly than imply stronger guarantees than the controls provide. Honest read:

The point of the section above isn't "this site is unhackable" — nothing is. It's "we've moved the controllable layers as far as they go, named the layers we haven't, and you can verify both."

What our tools store locally on your device

Content pages (everything under /moments/, the pillar landings, About, and so on) store nothing on your device — no cookies, no localStorage, no IndexedDB. Three interactive tools are different: they keep state in your browser's localStorage so your progress survives a page reload. Nothing is sent to our server; the data lives in your browser and is wiped when you clear site data for mogambo.info.

To inspect or wipe: in any browser, open DevTools → Application tab → Local Storage → https://mogambo.info. To clear it, right-click → Clear. To delete it permanently for this site, browser settings → Site Settings → mogambo.info → Clear data.

Documents render in your browser, not a third party's

Research pages on this site (M365 Copilot Architecture, the IPO Investment Framework) include embedded documents. Until early May 2026 those documents were rendered via Microsoft's Office Online public viewer, which meant your IP address was visible to Microsoft during the iframe load. That dependency is now gone. Microsoft deprecated their public viewer service in May 2026; we responded by pre-converting the source Word documents to PDF on Amit's local machine and serving the PDFs directly from this site. Your browser's built-in PDF viewer renders them inline. No third-party server sees your visit. If you want the original Word document, request it by email — the link is on the relevant research page.

If you contact us

The site lists mogambo@mogambo.info for feedback, corrections, and questions. Email you send to that address is read by Amit personally and stored in a regular email inbox under standard email-service security (TLS in transit, encrypted at rest with the provider). If you'd like a piece of feedback to remain anonymous, just say so and we won't reference your name or email in any update.

How feedback form submissions are handled

Every ah-ha moment carries an inline "Tell Mogambo" form at the bottom. When you submit it:

If you subscribe to Mogambo's newsletter

Mogambo offers an optional email subscription on the subscribe page and on every ah-ha moment's feedback form. Two channels: a monthly digest (~once on the 1st) and per-moment notifications (an email each time something new ships). You can pick either, both, or neither.

Requesting your data (or its deletion)

If you'd like to see what we have on you, or have it deleted entirely, email mogambo@mogambo.info with the address you signed up under (or any contact you've had with us) and a short note describing what you want. Amit fulfills these manually — no self-service portal, but a real human reads the request and responds.

What's coming (and how it'll be handled)

The Lab is small today. One future change will introduce more data handling. We're documenting it here so you know what to expect:

If anything in this policy materially changes, the page will carry a dated "Updated" line and a brief note describing what changed.

Verifying any of the above

You don't have to take our word for it. From any Lab page:

Found a discrepancy between this policy and what your browser's DevTools shows you? Tell us. We treat that as a security report and respond within a few days.

Last updated: 2026-05-14 — Phase G live: newsletter subscription added. Two new sections above — "If you subscribe to Mogambo's newsletter" covers what's stored, the double opt-in, send path through Mailjet, retention; "Requesting your data (or its deletion)" documents the GDPR-aligned data-export / right-to-erasure workflow (manual fulfillment, 30-day window).