# bimql.link — Complete Site Content ## Site Identity - **Domain**: https://bimql.link - **Owner**: Hasta Bahadur Chhetri (alias bimql) - **Tagline**: Solo indie developer from Nepal, dedicated to creating meaningful mobile experiences that anyone can enjoy. - **Location**: Pokhara, Nepal - **Email**: bimal.chhetry122@gmail.com - **Phone**: +977 98251 71228 - **Status**: Available for opportunities (Remote international contractor, Nepal-based) --- ## Navigation Structure - Home (/) — Portfolio overview: hero, app showcases, about sections, footer - Articles (/blogs) — Blog posts about dev, design, and indie software (SSR + ISR with 1-hour revalidation) - Resume (/resume) — Full professional CV (also served at resume.bimql.link via middleware rewrite) - Research (/research) — Academic paper index with full paper pages - Research: Agri-IDS (/research/agricultural-iot-intrusion-detection) — ML intrusion detection paper - Research: Agentic AI (/research/agentic-ai-cyber-defense) — Systematic review paper - Apps: Mathheist: Math Quiz & Puzzle everywhere (/apps/mathheist) — App landing page with Play Store + App Store links - Apps: Mehendi Designs (/apps/mehendi-designs) — App landing page - Apps: Engineering Mock Test (/apps/engineering-mock-test) — App landing page - Nepal Travel Map (/map) — Interactive Leaflet-based district map - Service Status (/status) — Live health checks + 90-day uptime history (also at status.bimql.link) - QR Analytics (/analytics) — QR scan analytics dashboard (noindex) - Privacy Policy (/policies/privacy-policy) — Legal & data handling - Blog Admin (/blogs/admin) — CMS for managing blog posts (Firebase Auth protected with lockout mechanism) ### API Routes - GET /api/status — Runs live service health checks (Website, Blog, Travel Map, Firebase, Map Data GitHub) - GET /api/status/history — Returns 90-day uptime history from Firestore `statusDaily` collection - GET /api/status/record — Records daily status snapshot (Vercel Cron target, CRON_SECRET protected) - GET /api/qr-analytics?date=YYYY-MM-DD — Returns QR scan analytics by date - POST /api/qr-analytics — Supports `list_dates` and `date_range` actions - GET /qr — QR code redirect handler: parses UA, detects platform, geolocates via ip-api.com, logs to Firestore, redirects to App/Play Store ### Subdomain Routing (via middleware.ts) - `resume.bimql.link` → rewrites to `/resume` - `status.bimql.link` → rewrites to `/status` (lets API routes pass through as-is) - `www.bimql.link` → 301 redirect to `bimql.link` - `/resume` on apex → 307 redirect to `/` - `/status` on apex → 301 redirect to `status.bimql.link` - Old research slugs (/research/agri-iot, /research/agentic-ai) → 301 redirect to SEO-friendly paths - Old research PDFs → 301 redirect to new PDF paths --- ## Homepage Content ### Hero Section Brand name "bimql" displayed in Jersey 10 font at 207px. Subtitle: "Solo indie developer from Nepal, dedicated to creating meaningful mobile experiences that anyone can enjoy." Contains a "Research Papers" button linking to /research and a hamburger menu opening a NavDrawer with navigation links. ### Mathheist Section "Train your brain daily with fast-paced math challenges, exciting levels, XP leagues, streak rewards, and competitive leaderboards. Solve fun equations across 100 unique levels inspired by Duolingo-style progression and become the ultimate math champion." ### Mehendi Designs Section "Explore thousands of breathtaking henna designs. From classic bridal to modern finger art, find your perfect match. The ultimate inspiration tool for every occasion." ### Engineering Mock Test Section "Step into a focused learning arena built for future engineers. Conquer full-length mock tests, master tricky concepts and watch your scores rise as you prepare for the real exam with confidence." ### About Section 1 — "I try to turn bold ideas into great Apps" I'm pretty ambitious, hugely passionate and good-natured professionals committed to making the most entertaining and rewarding experiences across your favorite screens. My focus on gameplay, graphics and quality shines throughout my creations. ### About Section 2 — "Don't miss out" In this life I'm always full steam ahead onto the next thing, but there's no reason to feel left out — head over to my LinkedIn page to check out what I've been up to lately! ### Find Me Section — Careers Full-stack developer turning messy ideas into clean, fast products that actually ship. Hire me before your competitors claim they "accidentally" built the same thing. ### Footer - Links: Privacy Policy, Contact (email) - Social: Twitter/X (@ghoseyyy), Instagram (bimql.link), LinkedIn (bimql), YouTube (@Bimql.69) - Research Hub links: Agricultural IoT IDS, Agentic AI Cyber Defense - Copyright: Hasta Bahadur Chhetri, 2026 --- ## App Landing Pages ### Mathheist: Math Quiz & Puzzle everywhere https://bimql.link/apps/mathheist Features: 100 unique levels, XP leagues & leaderboards, daily streaks, Duolingo-style progression, fast-paced math challenges. Both iOS and Android. - Play Store: https://play.google.com/store/apps/details?id=com.bimql.mathematica - App Store: https://apps.apple.com/us/app/mathematica-math-quiz-game/id6760190002 - JSON-LD: SoftwareApplication schema ### Mehendi Designs https://bimql.link/apps/mehendi-designs Features: Thousands of designs, bridal & finger art, categorized collections, perfect for every occasion, offline browsing. iOS and Android. - Play Store: https://play.google.com/store/apps/details?id=com.bimql.mehendi - App Store: https://apps.apple.com/us/app/daily-mehndi-designs/id6757390158 - JSON-LD: SoftwareApplication schema ### Engineering Mock Test https://bimql.link/apps/engineering-mock-test Features: Full-length mock tests, concept revision mode, score tracking & history, built for Nepal engineering exams, confidence-building progression. iOS and Android. - Play Store: https://play.google.com/store/apps/details?id=com.bimql.nec - App Store: https://apps.apple.com/us/app/engineering-mock-test/id6757604629 - JSON-LD: SoftwareApplication schema ### Ludo Universe Not a dedicated landing page but featured on the homepage. 15K+ downloads, 60-69 DAU. Cross-platform mobile game developed solo using React Native & Expo. Firebase analytics and AdMob monetization. - Play Store: https://play.google.com/store/apps/details?id=com.bimql.ludo - Stack: React Native, Expo, TypeScript, Redux, Firebase --- ## Resume (Full Professional CV) URL: https://bimql.link/resume ### Contact Information - Phone: +977 98251 71228 - Email: bimal.chhetry122@gmail.com - Location: Pokhara, Nepal - GitHub: https://github.com/ghoseyy - LinkedIn: https://www.linkedin.com/in/bimql/ - Behance: https://www.behance.net/bimalchhetry - Dribbble: https://dribbble.com/bimal28 - ORCID: https://orcid.org/0009-0009-8909-2389 ### Professional Summary Creative and results-driven professional with expertise in UI/UX design, full-stack mobile development, and digital content creation. Skilled in React Native, TypeScript, and multimedia design, with proven experience in delivering engaging apps and marketing solutions. Also an independent researcher with two 2026 arXiv preprints in applied ML and AI for cybersecurity, and a peer reviewer for Elsevier's Internet of Things journal. Work Authorization: Remote international contractor (Nepal-based). ### Core Skills 1. **Software Development**: React Native, React, JavaScript, TypeScript, Expo, Redux, API Integration, Git/GitHub 2. **UI/UX & Design**: Wireframing & Prototyping, Mobile/Web Interfaces, Figma, Adobe Photoshop/Illustrator, Branding 3. **Digital Marketing & Multimedia**: SEO & Analytics, Photography & Videography, Meta Business Suite 4. **Communication & Collaboration**: Multilingual, Documentation, Reports, Team Coordination, Creative Problem-Solving ### Technical Proficiencies - **Development & Frameworks**: React Native, React, Expo, TypeScript, JavaScript, Redux, Node.js, Firebase, PHP - **Design & Creative Tools**: Figma, Photoshop, Illustrator, DaVinci Resolve, Prototyping - **Development Tools**: Git/GitHub, Android Studio, Xcode, AdMob, MMKV, Visual Studio - **AI-Assisted Development**: ChatGPT, Cursor, Claude, Perplexity (ideation, debugging, code assistance, problem-solving) - **Research & Machine Learning**: Python, PyTorch, scikit-learn, Pandas, NumPy, Jupyter ### Professional Experience #### 1. Growth & Digital Marketing Executive — Gaming & Paid Media **Yarsa Labs Pvt. Ltd.** | Dec 2025 – Present | Kaski, Nepal - Optimized User Acquisition (UA) and ROAS by 30% through data-driven paid media campaigns across Unity Ads, AppLovin, and Google Ads - Developed high-performing Playable Ads using Defold JS and Playable Factory, increasing interactive engagement and lowering average CPI for gaming titles - Managed end-to-end attribution and analytics via MMPs (AppsFlyer and Singular) to track user lifecycles, optimize eCPM, and refine audience targeting - Scaled creative production using AI tools like Creatify and OpenArt, generating high-volume ad variations contributing to a 40% increase in visibility - Executed multi-platform ad strategies via Meta Business Suite, overseeing commerce integration and deep-funnel performance reporting - **Tools**: Unity Ads, AppLovin, Google Ads, Meta Business Suite, AppsFlyer, Singular, Defold JS, Playable Factory, Creatify, OpenArt, Figma, DaVinci Resolve #### 2. Online Volunteer — Digital Media & Outreach **UNDP Nepal** | Feb 2026 – Mar 2026 | Remote, Nepal Collaborated with the UNDP Nepal team to support the "My Vote Matters" national campaign during the 2026 General Elections. Focused on leveraging digital platforms to increase voter awareness and combat electoral misinformation. - Content Production: Produced high-impact digital content, including a 60–90 second video focused on the first-time voter experience to drive youth engagement - Information Integrity: Actively monitored and reported digital misinformation, ensuring the distribution of factual, non-partisan electoral information - Strategic Outreach: Supported the public information campaign by distributing multimedia assets across various digital channels to reach diverse demographics in Nepal - Stakeholder Collaboration: Coordinated with international project managers and local media professionals to align campaign messaging with UNDP transparency standards - **Skills**: Digital Outreach, Content Strategy, Video Production, Misinformation Monitoring, Campaign Management #### 3. Creative & Digital Media Executive **Yarsa Tech Pvt. Ltd.** | Feb 2022 – Present | Kaski, Nepal Designed web and mobile interfaces, brand identities, and product packaging. Created multimedia content and managed social media campaigns, boosting engagement and visibility by 30%. - **Tools**: Figma, Photoshop, Illustrator, DaVinci Resolve, Meta Business Suite - **Portfolio Highlights**: Nizi iOS (App Store), Nizi Android (Google Play), Nizistore.com #### 4. Graphic Designer **Medicos International** | Mar 2021 – Sep 2021 | Chitwan, Nepal Learned and contributed to app interface design and coding, creating wireframes, high-fidelity visuals, branding, and graphics. Produced marketing visuals, edited promotional videos, and assisted with social media management. ### Personal Projects #### Ludo Universe (2024) - 15K+ downloads, 60-69 DAU - Cross-platform mobile game developed solo using React Native & Expo - Integrated Firebase analytics and AdMob monetization - Google Play: https://play.google.com/store/apps/details?id=com.bimql.ludo - Stack: React Native, Expo, TypeScript, Redux, Firebase #### Mathheist: Math Quiz & Puzzle everywhere (2025) - Math quiz game, iOS & Android - Interactive math quiz with multiple difficulty levels, timed challenges, and progress tracking - Play Store: https://play.google.com/store/apps/details?id=com.bimql.mathematica - App Store: https://apps.apple.com/us/app/mathematica-math-quiz-game/id6760190002 - Stack: React Native, Expo, TypeScript, Redux, Firebase #### Mehendi App (2025) - Full-stack mehendi design gallery with download, share, and AR "on-hand" try-on experience - Focus on architecture and state management - Play Store: https://play.google.com/store/apps/details?id=com.bimql.mehendi - App Store: https://apps.apple.com/us/app/daily-mehndi-designs/id6757390158 - Stack: React Native, Expo, TypeScript, Redux, Firebase #### NEC Mock Test App (2022–Ongoing) - Engineering mock test app with real-time progress tracking, semester-wise tests, and subject-specific content - Play Store: https://play.google.com/store/apps/details?id=com.bimql.nec - App Store: https://apps.apple.com/us/app/engineering-mock-test/id6757604629 - Stack: React Native, Expo, TypeScript, Redux, MMKV #### vRestro (Collaborator, 2024–Ongoing) - Contributing to mobile and web app redesign for restaurant management SaaS platform - Focus on UI/UX improvements, performance testing, and feature integration - Website: https://vrestro.com/ #### Personal Portfolio Websites - Online Notepad: https://bimql.vercel.app/ - Sandhya Thapa: https://sandhyathapa.com.np/ - Gofley: https://gofley.vercel.app/ - Niruta: https://niruta.vercel.app/ - Projekt69: https://www.projekt69.com/ - Bimql69: https://bimql69.vercel.app/ ### Research & Publications #### Paper 1 — Intrusion Detection for Agricultural IoT Networks (2026) Sole author. Preprint. Published as Hasta Bahadur Chhetri. Empirical evaluation of five machine-learning models (Random Forest, Decision Tree, Logistic Regression, Autoencoder, VAE) on the CICIDS2017 benchmark. Random Forest achieved F1=0.9965, ROC-AUC=0.9998; proposes a lightweight two-tier hybrid IDS for resource-constrained smart farms. Topics: Machine Learning, Intrusion Detection, IoT Security, Python, PyTorch, scikit-learn #### Paper 2 — Agentic AI for Critical Infrastructure Cyber Defense (2026) Sole author. Preprint. Published as Hasta Bahadur Chhetri. PRISMA-informed structured review of 26 selected studies (23 peer-reviewed + 3 preprints) on agentic AI for autonomous cyber-defense across ICS, IoT, and smart agriculture, classifying techniques against the five functions of the NIST Cybersecurity Framework. Topics: Agentic AI, LLM Multi-Agent Systems, Critical Infrastructure Security, NIST CSF ### Academic Service - Peer Reviewer, Internet of Things Journal, Elsevier (June 2026) - Verified by Elsevier on ORCID (0009-0009-8909-2389) - Reviewed a full-length research article on Agentic AI, Decentralized Physical Infrastructure Networks (DePIN), edge intelligence, and blockchain governance for IoT hardware deployment. ### Education **Bachelor of Computer Application (BCA)** — La Grandee International College, Pokhara University | September 2017 – August 2024 Faculty of Science and Technology Projects: 1. **Hospital Management System** — Terminal-based C application for patient records and report generation (File Handling, Data Structures) 2. **Movie Ticket Management System** — VB.NET + Visual Studio with SQL database integration for seat selection and booking confirmation 3. **Gantavya (Travel Platform)** — PHP, HTML, CSS, MySQL, Java responsive cross-platform UI/UX for travel information and itinerary planning ### References Available upon request. Including: - Narayan Thapa Magar, Mentor, Senior Mobile App Developer at FieldEx - Yarsa Tech Pvt Ltd. - Vrestro Pvt Ltd. - LA Grandee International College --- ## Research Papers (Full Content) ### Paper 1: Intrusion Detection for Agricultural IoT Networks URL: https://bimql.link/research/agricultural-iot-intrusion-detection DOI: 10.5281/zenodo.agri-iot Journal: Smart Agriculture & IoT Security Date: 2026 Author: Hasta Bahadur Chhetri Institute: La Grandee International College, Pokhara, Nepal **IEEE Citation**: H. B. Chhetri, "Intrusion Detection for Agricultural IoT Networks: An Empirical Comparison of Supervised and Unsupervised Machine Learning Approaches," arXiv:submit/7635491, 2026. [Online]. Available: https://bimql.link/research/agricultural-iot-intrusion-detection **Abstract**: The rapid proliferation of IoT technologies has fundamentally transformed global agriculture, enabling precision farming and automated resource management. However, this digital transformation has simultaneously expanded the attack surface, leaving interconnected agricultural systems vulnerable to sophisticated cyber threats. This paper addresses this gap by empirically evaluating five ML models—Random Forest, Decision Tree, Logistic Regression, Autoencoder, and Variational Autoencoder—using the CICIDS2017 benchmark dataset. Experimental results demonstrate that supervised models, particularly Random Forest (F1=0.9965, ROC-AUC=0.9998), significantly outperform unsupervised models in identifying labeled network attacks. Unsupervised Autoencoders provide essential capabilities for detecting zero-day anomalies in unlabeled scenarios. **Key Results**: | Model | F1 | ROC-AUC | PR-AUC | Precision | Recall | |-------|-----|---------|--------|-----------|--------| | Random Forest | 0.9965 | 0.9998 | 0.9996 | 0.9982 | 0.9947 | | Decision Tree | 0.9967 | 0.9976 | 0.9973 | 0.9965 | 0.9969 | | Logistic Regression | 0.8921 | 0.9797 | 0.9657 | 0.9282 | 0.8588 | | Autoencoder (full) | 0.6914 | 0.8363 | 0.7914 | 0.6792 | 0.7042 | | Autoencoder (quick) | 0.6975 | 0.8023 | 0.7281 | 0.5361 | 0.9979 | | VAE (quick) | 0.6445 | 0.7219 | 0.6727 | 0.4766 | 0.9946 | **Proposed Architecture**: Two-tier hybrid IDS: Tier 1 is a lightweight Random Forest for known attack signatures; Tier 2 is an unsupervised Autoencoder for zero-day anomaly detection. Random Forest filters high-confidence classifications; low-confidence flows pass to the Autoencoder. **Conclusion**: Supervised ensemble models achieve near-optimal classification. Unsupervised models achieve high recall but low precision. Future work: AgriIoT-specific benchmarks (LoRaWAN, MQTT, Modbus), field validation on edge hardware, federated learning, KL annealing for VAE stability, multi-class attack categorization. **Code**: https://github.com/ghoseyy/AgriIoT-IDS **References**: 20 scholarly references from IEEE, ACM, Springer, MDPI, PeerJ. **How to Cite**: Each paper page includes a "How to Cite" section after References, separated by an `
` block using the `select-all` utility class. ### Paper 2: Agentic AI for Critical Infrastructure Cyber Defense URL: https://bimql.link/research/agentic-ai-cyber-defense DOI: 10.5281/zenodo.agentic-ai Journal: Agentic AI & Critical Infrastructure Date: 2026 Author: Hasta Bahadur Chhetri Institute: La Grandee International College, Pokhara, Gandaki Province, Nepal **IEEE Citation**: H. B. Chhetri, "Agentic AI Systems for Autonomous Prevention, Detection, and Mitigation of Cyber Attacks in Critical Infrastructure: A Structured Literature Review," 2026. [Online]. Available: https://bimql.link/research/agentic-ai-cyber-defense **Abstract**: The escalating frequency and sophistication of cyber attacks targeting critical infrastructure have outpaced traditional signature-based defense mechanisms. This paper presents a structured, PRISMA-informed literature review of agentic AI systems for autonomous prevention, detection, and mitigation. A structured review of 26 selected studies (23 peer-reviewed articles and 3 preprints) reveals that the state-of-the-art is defined by modular multi-agent LLM architectures achieving 93.6% detection accuracy, SARSA-based reinforcement learning honeypots exceeding 0.99 accuracy for ICS intrusion detection, and autonomous frameworks enabling real-time incident response. **Methodology**: PRISMA-informed structured review of 26 studies from IEEE Xplore, ACM Digital Library, Scopus, arXiv, and Google Scholar (2018–2026). ≈410 initial records screened, 26 studies retained. Quality appraisal across 5 evidence levels. **Key Findings**: - Detect function: 24 of 26 papers (92%) - Respond: 10 (38%) - Protect/Prevent: 9 (35%) - Recover: 1 (4%) - Identify: 0 (0%) - 18 of 26 (69%) are literature reviews or position papers without original empirical validation - 4 studies provide original empirical results - SARSA-RL Honeypot: >0.99 accuracy (F-measure 0.98) - Multi-agent + LLM: 93.6% system-wide accuracy - Hybrid AI Framework: 95% (projected) - ML/DL Ensemble (survey): >90% **Domain Distribution**: General Cybersecurity (9, 34.6%), ICS/Critical Infrastructure (8, 30.8%), Network Security (5, 19.2%), Agricultural IoT (4, 15.4%). **Recommendations**: (1) Deploy multi-agent LLM architectures for cross-domain threat correlation in SOCs with human-in-the-loop; (2) Integrate RL-enhanced honeypots with defense-in-depth for ICS networks; (3) Align with NIST CSF focusing on Detect and Respond while building Identify and Recover capacity; (4) Mandate continuous model retraining on up-to-date operational data. **References**: 26 scholarly references (23 peer-reviewed, 3 preprints). **How to Cite**: Each paper page includes a "How to Cite" section after References, separated by an `
` line, with a copyable IEEE-formatted citation in a monospace `` block using the `select-all` utility class. ### Research Hub Index URL: https://bimql.link/research A minimal paper index page listing both papers with field tags, year, summary, and metadata badges. Features a clean, animated layout with Framer Motion staggered entrance animations. Each paper links to its full academic-paper-style HTML page with two-column introduction layout, inline SVG figures, tables, and reference lists. Includes a "Cite This Research" section at the bottom with pre-formatted IEEE citations for both papers in a copyable `` block. --- ## Blog / Articles URL: https://bimql.link/blogs A collection of thoughts on development, design, and building indie software. Server-side rendered with 1-hour ISR revalidation. Each article includes: - Title, excerpt, cover image - Author: Hasta Bahadur Chhetri - Reading time (calculated from content length at 250 WPM) - Publish date - Full markdown content with code blocks, headings, lists, links, bold/italic - Share functionality (native share API with clipboard fallback) - Reading progress bar (fixed top bar) Blog list page features a hero section with "ARTICLES" title in Jersey 10 font, a 3-column responsive grid with cover images, titles, excerpts, dates, read times, and "Read Article" CTAs. ### Blog Admin CMS URL: https://bimql.link/blogs/admin Firebase Auth-protected admin panel with: - Login form with lockout after 5 failed attempts (1-minute timeout) - Ghost-style sidebar with post list - Markdown editor with toolbar (heading, bold, italic, link, list, image upload) - Image upload to Firebase Storage - Preview mode - Settings panel: cover image (upload or URL), slug, excerpt, accent color picker, publish/draft toggle - Create, edit, delete, publish workflow ### Firebase Data Model (Blog) Collection: `blogs` - id (auto-generated) - title (string) - slug (string, auto-generated from title) - content (markdown string) - excerpt (string) - coverImage (string URL, optional) - coverColor (hex string, default #366d9c) - tags (string array) - published (boolean) - createdAt (Timestamp) - updatedAt (Timestamp) ### Firebase Server SDK Firebase Admin SDK initialized from `FIREBASE_SERVICE_ACCOUNT` environment variable. Provides: - `getAllPostsServer()` — fetches all published posts, sorted by createdAt desc - `getPostBySlugServer(slug)` — fetches single post by slug --- ## Nepal Travel Map URL: https://bimql.link/map Interactive map of Nepal built with Leaflet + react-leaflet showing districts visited by bimql. **Features**: - GeoJSON data loaded from external sources (mesaugat/geoJSON-Nepal, opentechcommunity/map-of-nepal) - 96 districts listed in Nepal (24 visited) - Visited districts highlighted in light blue (#7fb3dd) with darker border (#5a91c2) - Unvisited districts in white with brand-tinted hairlines - Continuous zoom via custom wheel handler (trackpad pinch + mouse wheel) - Hover tooltips showing district name (with ✓ for visited) - Hover highlighting with color change - Max bounds to keep panning near Nepal - Loading spinner and error state - Responsive full-screen layout **Visited Districts** (24): Kathmandu, Lalitpur, Bhaktapur, Syangja, Kaski, Baglung, Manang, Mustang, Palpa, Arghakhanchi, Gulmi, Rupandehi, Kapilbastu, Nawalparasi West, Nawalparasi East, Chitwan, Tanahu, Gorkha, Lamjung, Parbat, Myagdi, Rukum East, Rukum West. **Technical**: Custom continuous zoom replaces Leaflet's default stepped scrollWheelZoom. Uses `fitBounds` with padding. Fractional zoom with `zoomSnap: 0`. Keyboard navigation enabled. --- ## Service Status Page URL: https://bimql.link/status (also at status.bimql.link) Live health monitoring dashboard for bimql services with 90-day uptime history. **Monitored Services**: 1. **Website** (bimql.link) — Main site, mode: ok, degraded at 1500ms 2. **Blog** (/blogs) — Articles & writing, mode: ok, degraded at 1500ms 3. **Travel Map** (/map) — Nepal district map, mode: ok, degraded at 1500ms 4. **Firebase** (Firestore API) — Backend, mode: reachable (any non-5xx = up), degraded at 2000ms 5. **Map Data (GitHub)** (GeoJSON source) — District data, mode: ok, degraded at 4000ms **Architecture**: - `status-check.ts`: Checks all services with 8s timeout, classifies as operational/degraded/down - `GET /api/status`: Runs live checks on demand, returns JSON - `GET /api/status/history`: Fetches 90-day history from Firestore `statusDaily` collection, returns per-service day-by-day uptime - `GET /api/status/record`: Vercel Cron target (daily at midnight UTC), protected by CRON_SECRET, persists per-service up/total counters **Firestore Data Model** (statusDaily): - Collection: `statusDaily` - Document ID: date string (YYYY-MM-DD) - Fields: date, services (map of service name → { up: increment, total: increment }), updatedAt (server timestamp) **UI Features**: - Overall status banner with animated ping dot - Auto-refresh every 45 seconds - 90-day uptime bar charts per service (green = ≥99.9%, amber = ≥90%, red = <90%, white = no data) - Overall uptime percentage per service - Latency display, HTTP status codes - Manual refresh button - Loading skeleton and error states - "90 days ago → Today" labels on bars --- ## QR Code Analytics URL: https://bimql.link/analytics Real-time analytics dashboard for QR code scans from bimql's sticker/print materials. **Features**: - Date selector (calendar picker) - Stats cards: Total Scans, Countries, Cities, Devices - Platform breakdown (iOS, Android, Windows, macOS, Linux, Other) - Top 5 countries and cities - Browser distribution - Detailed scan table with: time, location (city/country), IP address, platform badge, device model, browser, redirect target **API**: GET /api/qr-analytics?date=YYYY-MM-DD Returns: totalScans, scans array with platform/device/location data, summary by platform/browser/device/OS POST /api/qr-analytics supports: - `list_dates` — returns last 30 days of scan data - `date_range` — returns scan counts for a date range ### QR Redirect System URL: https://bimql.link/qr Redirect endpoint that handles QR code scans: 1. Parses User-Agent to detect platform (iOS, Android, Windows, macOS, Linux, Unix, Other), device model, OS version, and browser 2. Geolocates the visitor via ip-api.com (free tier, 45 req/min, 3s timeout) 3. Logs scan data to Firestore `qr_scans_daily/{date}/scans/{id}` with: qrId, platform, deviceModel, osVersion, browser, redirectTarget, ipAddress, location (country, city, region, coordinates), userAgent, scannedAt 4. Updates daily scan counter with Firestore FieldValue.increment 5. Redirects iOS/macOS users to App Store developer page, others to Play Store developer page **Firestore Data Model** (qr_scans_daily): - Collection: `qr_scans_daily` - Document ID: date string - Subcollection: `scans` - Scan fields: qrId, platform, deviceModel, osVersion, browser, redirectTarget, ipAddress, location (country, city, region, coordinates), userAgent, scannedAt --- ## Cookie Consent System Location: src/app/lib/consent.ts Full cookie consent management with: - Three states: undecided, accepted (analytical=true), declined (analytical=false) - localStorage persistence with structured settings - Backward compatibility with legacy "cookieConsent" key - Event-based notification system (CustomEvent `cookieconsentchange`) - Subscribe/unsubscribe API for live listeners **Components**: - `CookieConsent.tsx` — Banner with Accept All / Settings / Decline (appears after 2s delay, slide-up animation) - `CookieSettings.tsx` — Settings popover/panel - `CookieController.tsx` — Orchestrator that manages banner and settings state - `FloatingShield.tsx` / `ShieldButton.tsx` — Floating cookie settings button **Analytics Integration** (AnalyticsProvider.tsx): - Firebase Analytics + Microsoft Clarity gated on consent - SDKs loaded via requestIdleCallback (deferred for LCP) - Consent change: grant enables collection, revoke disables collection - Page views tracked on client-side navigation - Consent state persists across sessions --- ## Technical Architecture ### Framework & Core - **Framework**: Next.js 16.0.10 (App Router, Turbopack for dev) - **Runtime**: Node.js (API routes), Edge (middleware, OG images) - **Language**: TypeScript 5 (strict mode) - **Package Manager**: npm ### UI & Styling - **UI Library**: HeroUI 2.8 (@heroui/react, @heroui/drawer, @heroui/system, @heroui/theme) - **CSS Framework**: Tailwind CSS 4.1 (@tailwindcss/postcss) - **PostCSS**: 8.5 with autoprefixer - **Animation**: Framer Motion 12 - **Icons**: lucide-react 0.561 - **CSS Utilities**: clsx, tailwind-merge - **Custom CSS Variables**: Full OKLCH color system for light/dark themes with CSS custom properties ### Fonts - **Geist** (primary, via next/font/google) - **Geist Mono** (monospace, via next/font/google) - **Jersey 10** (display/headings) - **Darker Grotesque** (body text) - **Alegreya Sans** (headings, research) - **Lato** (buttons) - **EB Garamond** (academic papers) - **JetBrains Mono** (terminal animation) - **@fontsource/alegreya-sans** (npm package) ### Backend & Data - **Database**: Firebase Firestore (client SDK + Admin SDK) - **Authentication**: Firebase Auth (email/password for blog admin) - **Storage**: Firebase Storage (blog cover images, via Admin SDK server-side) - **Server SDK**: firebase-admin 13.6 (service account from FIREBASE_SERVICE_ACCOUNT env var) - **Client SDK**: firebase 12.7 (lazy-loaded for analytics) ### Maps - **Leaflet** 1.9.4 + react-leaflet 5.0 with @types/leaflet - **GeoJSON Sources**: mesaugat/geoJSON-Nepal, opentechcommunity/map-of-nepal - Custom continuous zoom handler for smooth trackpad/mouse wheel experience ### 3D & Graphics - **@google/model-viewer** 4.1 (3D model display) - **@splinetool/react-spline** 4.1 (Spline 3D scenes) - Public 3D model: i_phone_14_pro_copy.glb ### Analytics & Monitoring - **Firebase Analytics** (consent-gated, deferred idle-load) - **Microsoft Clarity** (consent-gated) - **Custom QR Scan Analytics** (Firestore-based with ip-api.com geolocation) - **Service Status Monitoring** (custom health check engine with 90-day history) ### SEO Implementation - Per-route metadata (title, description, OG, Twitter) - JSON-LD structured data (WebSite + Person schema in root layout) - JSON-LD SoftwareApplication schema (on each app landing page) - robots.txt (Allow: /, Disallow: /qr, /blogs/admin) - Dynamic sitemap.xml (static routes + published blog posts from Firestore) - Canonical URLs on every page - Accessibility: Skip to main content link, semantic HTML landmarks - Responsive design (mobile-first Tailwind) - All images include descriptive alt text - OG images: Static (/bimql.png) + dynamic Edge OG images per app/research page ### Middleware & Routing Custom Next.js middleware with: - Subdomain rewriting (resume.bimql.link, status.bimql.link) - www → apex 301 redirect - /resume → / 307 redirect (on apex domain) - /status → status.bimql.link 301 redirect - Old research route 301 redirects (agri-iot → agricultural-iot-intrusion-detection, etc.) - Old research PDF 301 redirects ### Image Optimization - Formats: AVIF + WebP (next.config.ts) - Device sizes: 640, 768, 1024, 1280, 1536 - Remote patterns: firebasestorage.googleapis.com, *.googleapis.com - Most images served from /public directory (unoptimized) ### Deployment & CI/CD - **Hosting**: Vercel (Hobby plan) - **Vercel Cron**: Daily `/api/status/record` at midnight UTC - **Config**: vercel.json with cron schedule - **Build**: `next build` with TypeScript and ESLint ### Firebase Admin Server SDK Initialized in `firebase-server.ts`: - Service account loaded from `FIREBASE_SERVICE_ACCOUNT` env var - Used for: sitemap generation (fetching published blog posts), QR scan logging, status history/recording - Exports: firestore, admin, getAllPostsServer(), getPostBySlugServer() ### Firebase Client SDK - `firebase-app.ts`: Minimal Firebase app initialization from NEXT_PUBLIC_FIREBASE_* env vars - `firebase.ts`: Imports app, initializes auth, firestore, storage - `blog.ts`: Full CRUD operations for blog posts (create, read, update, delete, slugify, formatDate) - Analytics is lazy-imported via dynamic import() in AnalyticsProvider ### Scripts - `scripts/gsc-audit.mjs`: Google Search Console audit CLI tool. Fetches query/page analytics with OAuth2 JWT bearer auth (using Firebase service account). Supports 28/90-day windows, sitemap status, URL inspection, and custom site property selection. ### Configuration Files - `next.config.ts`: Images (AVIF/WebP, remote patterns) - `tailwind.config.js`: Tailwind config with HeroUI plugin, dark mode (class) - `postcss.config.mjs`: PostCSS with @tailwindcss/postcss + autoprefixer - `eslint.config.mjs`: ESLint flat config with eslint-config-next (core-web-vitals + TypeScript) - `tsconfig.json`: Strict mode, ES6 target, bundler module resolution, @/* path alias - `vercel.json`: Deployment config with daily cron job - `seraui.config.json`: Sera UI component registry config - `.gitignore`: node_modules, .next, build, env, scratch files ### Package Dependencies **Production**: - next@16.0.10, react@19.2.1, react-dom@19.2.1 - firebase@12.7.0, firebase-admin@13.6.0 - @heroui/react@2.8.6, @heroui/drawer@2.2.25, @heroui/system@2.4.24, @heroui/theme@2.4.24 - framer-motion@12.23.26 - leaflet@1.9.4, react-leaflet@5.0.0 - lucide-react@0.561.0 - clsx@2.1.1, tailwind-merge@3.4.0 - @google/model-viewer@4.1.0, @splinetool/react-spline@4.1.0 - @fontsource/alegreya-sans@5.2.8 - @microsoft/clarity@1.0.2 **Dev**: - tailwindcss@4.1.18, @tailwindcss/postcss@4.1.18 - postcss@8.5.6, autoprefixer@10.4.23 - typescript@5, @types/node@20, @types/react@19, @types/react-dom@19, @types/leaflet@1.9.21 - eslint@9, eslint-config-next@16.0.10 --- ## Privacy Policy URL: https://bimql.link/policies/privacy-policy Last updated: 20 June 2026 **Sections**: 1. Information Collected (personal, non-personal, QR analytics, automatic, device permissions, third-party) 2. How Information Is Used (provide services, communicate, improve, protect) 3. Information Sharing (not sold, user settings, service providers, legal, business changes) 4. Data Security (HTTPS, limited access, regular updates) 5. Data Retention (account active + legal obligations, QR data up to 12 months) 6. User Rights (access, correction, deletion, objection, consent withdrawal) 7. Third-Party Services (external links, integrated SDKs) 8. Children's Privacy (not intended for under legal age) 9. International Users (data may be processed/stored in other countries) 10. Policy Changes (updates posted with "Last updated" date) 11. Contact (bimal.chhetry122@gmail.com) 12-16: App-specific practices, deletion instructions, advertising disclosures, third-party SDK table (13 SDKs), Google Play Data Safety alignment **Contact**: Bimql Chhetry, bimal.chhetry122@gmail.com, https://www.bimql.link --- ---