Cognitive Scaffold

Preparing your thinking workspace

PRIVACY · DATA

Privacy Policy P1-6

Last updated: 2026-09-09. This page explains how Thinking Models collects, uses, stores, and protects your data, and the rights you have over it.

1. Data we collect

  • Account information: the email you provide for passwordless sign-in, or public profile information authorized through GitHub.
  • Personal data: favorites, learning progress, private notes, comparison lists, and public submissions you choose to make.
  • Operational logs: structured error and health-check records used to keep the service reliable; they never include passwords or plaintext verification codes.

2. How we use data

  • To provide and personalize your learning path, favorites, and progress sync.
  • To review and, with your authorization, publish submissions.
  • To send sign-in codes only when you request them.
  • To monitor service health, troubleshoot faults, and prevent abuse.

3. Cookies and sessions

  • tm_session is an HttpOnly, SameSite=Lax session cookie with a rolling 30-day lifetime; frontend scripts cannot read it.
  • tm_csrf is a SameSite=Lax CSRF-protection cookie and carries no identity or private content.
  • Analytics is off by default. You can accept or reject optional analytics cookies in the banner, and reopen Cookie settings at any time. Your choice is stored locally as tm_analytics_consent_v1.
  • When accepted, Google Analytics 4 may use the first-party cookies _ga and _ga_<container-id>, and Microsoft Clarity may use _clck and _clsk. Rejecting or withdrawing consent removes these cookies where the browser permits.

4. Storage and backups

  • Structured data is stored in Cloudflare D1; sessions and comparison lists are stored in Cloudflare KV.
  • Daily database backups are retained in Cloudflare R2 for disaster recovery and may contain the data described above during their retention window.

5. Third-party services

  • Resend sends sign-in codes when configured.
  • GitHub OAuth is used only when you choose GitHub sign-in and only for authorized public profile data.
  • Turnstile may be used for bot protection during sign-in.
  • Microsoft Clarity helps us understand aggregate usage and usability through diagnostics such as page interactions and session performance.
  • Google Analytics 4 helps us analyze aggregate traffic and usage so we can improve the experience. It collects page-view and session statistics, approximate geographic location, and browser and device information by default. Google processes this information as a third party. You can disable or delete cookies in your browser, or use the Google Analytics opt-out browser add-on.

6. Your rights

  • Data portability: after sign-in, use Export my data to download your personal data as JSON.
  • Erasure: after sign-in, Delete account permanently removes your account and associated favorites, progress, notes, submissions, and sessions.
  • We do not sell your personal data.

7. Contact us

For privacy questions or requests, contact the site administrator through the feedback channel or visit the administrator profile.