TRUST · Privacy
Privacy policy
The short version: we store only what the features you use require, we never sell data, there are no advertising trackers, and you can delete your account — and everything it owns — yourself, at any time. Last updated 2026-08-20.
What do we store, and why?
- No account: nothing personal. Circuits you build live in your browser (localStorage) and in share URLs you create. Server logs are standard and short-lived.
- With an account: your email, display name, and a scrypt hash of your password (we cannot read the password itself); your lesson progress; experiments you sync; comparisons you save; threads and replies you post.
- Session cookie: one httpOnly cookie (qpu137_session) that keeps you signed in for up to 30 days. It is essential, not tracking — no consent banner theater is needed for it, so we don't show one.
- Error reports: if a page crashes in your browser, an error message and stack trace (no personal data) may be sent to us to fix it; at most a small rolling buffer is kept.
- Analytics: if enabled on this deployment, we use privacy-respecting product analytics (page views and feature usage) to decide what to build — never to profile you across other sites. We do not use advertising trackers.
Who else touches your data?
- Payments (when live): handled by Stripe; your card number never touches our servers. We store only your plan and a Stripe customer reference.
- Email (when configured): password-reset and verification emails are delivered by our email provider; the content is only the link involved.
- We never sell or rent personal data, and we don't share it except as above or where the law requires.
How long do we keep it?
- Account data: until you delete the account. Deletion is self-serve on your account page and removes your profile, progress, experiments, saved comparisons, and all your threads and replies, immediately and permanently.
- Community content you soft-deleted yourself: retained up to 30 days for moderation review, then hard-deleted.
- Expired sessions, reset tokens, and rate-limit counters are purged automatically.
Your rights
Access, correction, export, deletion — for any of these, use the account page or write to corrections@qpu137.com. If you are in the EU/UK or California, the rights under GDPR/CCPA apply to you and we honor them without making you cite the statute.