1. Who operates this site
Bayou Breach is a personal, noncommercial Louisiana cybersecurity-awareness project operated by Wes Merriott. For privacy questions, corrections or requests about information under our control, email wmerriott@fortinet.com. Please identify the relevant page and describe your request without sending sensitive records.
2. Information we use
Conversation and correction requests
The conversation form uses the name, organization, selected topic and message you type to prepare an email draft or text you can copy. Entries are held in the page’s temporary state; the application does not submit them to a server or save them in browser storage. Your browser may separately offer autofill or retain page state according to its settings.
If you choose to send the draft through your email service, Wes receives your email address, message and any information you include. That correspondence is handled in email, outside the website, to answer your request, review a correction or continue a conversation. Do not send passwords, API keys, criminal-justice information, protected health information, evidence files or stolen data. An ordinary email is not a secure incident-reporting channel.
Public-source information
The site stores selected public incident summaries, organization names, sector and location context, source URLs, relevant dates, aggregate reported counts, and minimal provider records. Automated records are filtered to reviewed Louisiana public-sector and critical-infrastructure organizations. We do not query visitors’ email addresses for breach exposure or host underlying breached datasets.
Technical information
Hosting and security infrastructure may process IP addresses, request time, requested URL, browser or device information, referrer information, error details and related service logs. These support delivery, availability, abuse prevention and troubleshooting. Do not put sensitive information in a URL or query string. Provider API checks run on the server; your search text and contact-form message are not sent to the connected intelligence providers.
3. Cookies, analytics and technical services
Bayou Breach does not add advertising pixels, session-replay tools or behavioral advertising analytics. The current public application does not require its own visitor account or set application tracking cookies. Hosting and security providers may use essential cookies or other technical mechanisms to operate or protect their services; their behavior is separate from the application code.
The site is hosted through OpenAI Sites using Cloudflare infrastructure. Its current styles request fonts from Google Fonts, which causes your browser to contact Google’s font services and transmit the technical information needed for those requests. You can block external fonts in your browser; fallback system fonts remain available.
The subtle background responds locally to scroll and pointer position. Those coordinates are used for the visual effect and are not logged or transmitted by the application. The site honors your device’s reduced-motion preference.
Relevant provider information: OpenAI privacy policy, Cloudflare privacy policy, and Google Fonts FAQ. These providers may process information in the United States or other countries where they operate.
5. Retention and security
Public editorial records are retained as part of the historical archive and revised when appropriate. Connected-source caches are replaced or updated by scheduled checks; a last successful snapshot may be retained during an outage. Source timestamps distinguish current checks from historical incidents.
Correspondence may be retained while handling your request and as needed to document a correction, maintain project records or meet applicable obligations. The website does not impose a separate retention schedule on your email provider or hosting providers; their settings and policies also apply. This policy does not promise a fixed deletion period for infrastructure logs outside the operator’s direct control.
The site uses HTTPS, keeps provider credentials on the server, and limits published data to relevant summaries. No internet service, email system or security measure can guarantee absolute confidentiality, availability or protection against unauthorized access.
6. Your choices and requests
You may browse without contacting us, leave the form blank, close the page to discard unsent entries, or use browser controls for cookies, external resources and motion. No email is sent merely by viewing the conversation page or preparing a draft.
To request access to, correction of or deletion of information you supplied directly, contact wmerriott@fortinet.com. Provide enough context to locate the information. We may need reasonable verification before acting. Requests will be considered under applicable law and the need to preserve legitimate records, security information and accurate public-interest reporting. No particular statutory right or exemption is assumed solely because you visited this site.
If a public incident record is inaccurate, provide its URL, the disputed statement and an authoritative public source. We can review material under our control, but cannot edit the originating publisher’s website, search-engine caches or third-party copies. Removal of an accurate public record is not automatic.
7. Children and future changes
The resource is intended for adult professionals and general public awareness. It is not directed to children under 13, and we do not knowingly solicit their personal information. If you believe a child supplied personal information, contact us so the matter can be reviewed.
This policy may change when the site’s features or practices change. The updated policy and effective date will be posted here. Material new collection or sharing practices should be explained before they apply. The terms and conditions explain the limits on using aggregated information.
