Privacy policy

What we collect, and what we do with it

Last updated 2026-08-19.

What we collect

An account requires an email address and a password. You may optionally add a display name. If you enable two-factor authentication, we store the authenticator secret encrypted (AES-256-GCM) — we never store or transmit it as plain text, and it is never visible to us in readable form. If you submit evidence, claims, or other contributions to the platform, that content is stored and attributed to your account.

Where it's stored

The production database runs on Supabase Cloud, hosted in an EU region (Frankfurt). This satisfies EU data residency for the database itself; it does not yet mean every part of our infrastructure is under our own direct control — we are transparent that this is a deliberate, named tradeoff for our current stage, not an oversight.

How long we keep it

We classify stored data into three categories, and treat each differently:

  • Personal data

    Directly tied to an identifiable person — your display name, your attribution on an evidence submission. This is what an account-anonymization request removes.

  • Evidentiary record

    The evidence, claims, and pathway content itself, once it has entered the shared record other users' work may depend on. This is retained independent of who submitted it — deleting your account does not remove content you contributed, only the identifying link to you.

  • Operational

    Logs, audit events, and session/security records. Time-bound in principle; we have not yet set a specific retention period for this category.

Account deletion

Requesting account deletion anonymizes your account — your display name is cleared and the account is marked anonymized — rather than deleting your contributions outright. This is deliberate: your evidentiary contributions may already be corroborated, contradicted, or built upon by other users' work, and removing them outright would remove real information from the shared record, not just your connection to it.

This is currently a manual process, not a self-service button in your account settings — that flow has not been built yet. If you want your account anonymized, there is also no working contact channel in-product yet to request it. Both of these are real, known gaps, stated here plainly rather than hidden.

Cookies

We use one strictly-necessary cookie to keep you signed in. We do not run analytics, advertising, or tracking of any kind, so there is nothing beyond that session cookie to ask your consent for.

What this policy doesn't cover yet

We do not yet have Terms of Service — that depends on product decisions that have not been finalized, and we would rather have none than publish placeholder legal terms. This policy will be revised as our data-handling practices change, not left to drift out of date.