POLICY
Privacy, by design.
What this platform stores and why.
Information collected
Signed-in users have a platform-provided identifier, public alias, theme preference, saved challenges, scores, and activity history. The platform supplies identity to authenticate requests; this application does not store passwords or expose email addresses on leaderboards.
Contact submissions contain the name, email, optional company, enquiry reason and message you provide. They are visible to authorized administrators. No automatic email is sent.
Cookies and analytics
Authentication cookies are managed by the hosting platform. Guest practice uses an HttpOnly same-site session cookie. Theme preference uses local browser storage. Aggregate event counters record challenge starts, completions and contact submissions without third-party tracking cookies.
Retention and deletion
Account records remain until you delete your lab data in profile settings. Guest session cookies expire after one day; server sessions may persist until administrative cleanup. Contact enquiries remain until an administrator deletes them. Ask about access or deletion through the contact form; provide enough context to identify your enquiry without sharing sensitive credentials.
Visibility
Leaderboard entries show aliases, challenge names, scores and dates. Avoid including identifying details in your public alias. Site access is initially private and managed by the hosting platform.
Storage
Site data is held in the managed hosting database. Provider-level logs and security controls are subject to the hosting provider’s policies.