Privacy

What we store.

Written to be accurate rather than reassuring.

Accounts are optional

On your first visit the server creates a pseudonymous profile and gives your browser a signed cookie that points at it. No name, no email, no password. You can use everything on the site in that state indefinitely.

If you do sign in, we ask for one thing: an email address. We send a single-use link to it and you click that to prove it's yours. There is no password — none is set, sent, or stored, so there is none to leak. Signing in claims the profile you were already using rather than starting a new one, so your history follows you.

Your email is stored so we can sign you in again and send the notifications you switch on. It is never shown to another user, never displayed on your profile, and never sold or shared. What other people see is your username, or the two-word handle we assigned you if you haven't set one.

The session cookie is httpOnly, so page scripts can't read it, and signed, so it can't be edited to impersonate anyone. Without an account, clearing it means starting over as a new person — there's nothing to recover you by. That's the main practical reason to sign in.

What's in the database

Without an account this is all keyed to a pseudonymous id that we cannot connect to a real person, because we never collected anything that would. With an account, the one identifying thing we hold is your email — used for sign-in and the notifications you asked for, and nothing else.

What third parties see

This site runs Vercel Analytics and Speed Insights for aggregate traffic and performance numbers. They process visitor IP addresses transiently to derive coarse location and device data, and do not expose the raw address to us. We don't store IP addresses ourselves, but it would be wrong to tell you none are ever processed.

Text you write may be sent to Google's Gemini API for two jobs: turning headlines into claims, and drafting the summary card at the end of a crux. That means the contents of a crux transcript can leave our servers. If that is not acceptable to you, don't write anything in a crux you wouldn't want processed by a third party.

Sign-in emails are delivered through Supabase, and notification emails through Resend when it is configured. Both see your email address and the contents of the message sent to you. Notification emails can quote the claim a crux is about, so if you'd rather that not pass through a mail provider, turn email off in settings — the notifications will still appear on the site.

Published versus private

A crux becomes public only when both participants approve the card. Until then it is visible to the two of you. Translations become visible in the feed once written — that is the point of writing one. Your drift, your notes, your confidence levels, and your reading history are never shown to anyone.

How the product worksBack to the feed