PricingOpen Lab
TRUST · Privacy

Privacy policy

The short version: we store only what the features you use require, we never sell data, there are no advertising trackers, and you can delete your account — and everything it owns — yourself, at any time. Last updated 2026-08-20.

What do we store, and why?

  • No account: nothing personal. Circuits you build live in your browser (localStorage) and in share URLs you create. Server logs are standard and short-lived.
  • With an account: your email, display name, and a scrypt hash of your password (we cannot read the password itself); your lesson progress; experiments you sync; comparisons you save; threads and replies you post.
  • Session cookie: one httpOnly cookie (qpu137_session) that keeps you signed in for up to 30 days. It is essential, not tracking — no consent banner theater is needed for it, so we don't show one.
  • Error reports: if a page crashes in your browser, an error message and stack trace (no personal data) may be sent to us to fix it; at most a small rolling buffer is kept.
  • Analytics: if enabled on this deployment, we use privacy-respecting product analytics (page views and feature usage) to decide what to build — never to profile you across other sites. We do not use advertising trackers.

Who else touches your data?

  • Payments (when live): handled by Stripe; your card number never touches our servers. We store only your plan and a Stripe customer reference.
  • Email (when configured): password-reset and verification emails are delivered by our email provider; the content is only the link involved.
  • We never sell or rent personal data, and we don't share it except as above or where the law requires.

How long do we keep it?

  • Account data: until you delete the account. Deletion is self-serve on your account page and removes your profile, progress, experiments, saved comparisons, and all your threads and replies, immediately and permanently.
  • Community content you soft-deleted yourself: retained up to 30 days for moderation review, then hard-deleted.
  • Expired sessions, reset tokens, and rate-limit counters are purged automatically.

Your rights

Access, correction, export, deletion — for any of these, use the account page or write to corrections@qpu137.com. If you are in the EU/UK or California, the rights under GDPR/CCPA apply to you and we honor them without making you cite the statute.

Terms of service →