Privacy
What we store.
Written to be accurate rather than reassuring.
Accounts are optional
On your first visit the server creates a pseudonymous profile and gives your browser a signed cookie that points at it. No name, no email, no password. You can use everything on the site in that state indefinitely.
If you do sign in, we ask for one thing: an email address. We send a single-use link to it and you click that to prove it's yours. There is no password — none is set, sent, or stored, so there is none to leak. Signing in claims the profile you were already using rather than starting a new one, so your history follows you.
Your email is stored so we can sign you in again and send the notifications you switch on. It is never shown to another user, never displayed on your profile, and never sold or shared. What other people see is your username, or the two-word handle we assigned you if you haven't set one.
The session cookie is httpOnly, so page scripts can't read it, and signed, so it can't be edited to impersonate anyone. Without an account, clearing it means starting over as a new person — there's nothing to recover you by. That's the main practical reason to sign in.
What's in the database
- Your positions on claims, including how sure you said you were, and the timestamps — this is what draws your drift.
- The private notes you attach to a reading. Never shown to anyone else.
- Translations you write, and the verdicts people gave them. Authors see the tally, never who voted.
- Everything written in a crux, which the person you're talking to can read by design.
- Your reactions, and reports you file.
- Notifications generated for you, and whether each was emailed.
- If you signed in: your email address, your username, and your notification preferences.
Without an account this is all keyed to a pseudonymous id that we cannot connect to a real person, because we never collected anything that would. With an account, the one identifying thing we hold is your email — used for sign-in and the notifications you asked for, and nothing else.
What third parties see
This site runs Vercel Analytics and Speed Insights for aggregate traffic and performance numbers. They process visitor IP addresses transiently to derive coarse location and device data, and do not expose the raw address to us. We don't store IP addresses ourselves, but it would be wrong to tell you none are ever processed.
Text you write may be sent to Google's Gemini API for two jobs: turning headlines into claims, and drafting the summary card at the end of a crux. That means the contents of a crux transcript can leave our servers. If that is not acceptable to you, don't write anything in a crux you wouldn't want processed by a third party.
Sign-in emails are delivered through Supabase, and notification emails through Resend when it is configured. Both see your email address and the contents of the message sent to you. Notification emails can quote the claim a crux is about, so if you'd rather that not pass through a mail provider, turn email off in settings — the notifications will still appear on the site.
Published versus private
A crux becomes public only when both participants approve the card. Until then it is visible to the two of you. Translations become visible in the feed once written — that is the point of writing one. Your drift, your notes, your confidence levels, and your reading history are never shown to anyone.