Cognitive Scaffold

Preparing your thinking workspace

PRIVACY · DATA

Privacy Policy P1-6

Last updated: 2026-08-02. This page explains how Thinking Models collects, uses, stores, and protects your data, and the rights you have over it.

1. Data we collect

  • Account information: the email you provide for passwordless sign-in, or public profile information authorized through GitHub.
  • Personal data: favorites, learning progress, private notes, comparison lists, and public submissions you choose to make.
  • Operational logs: structured error and health-check records used to keep the service reliable; they never include passwords or plaintext verification codes.

2. How we use data

  • To provide and personalize your learning path, favorites, and progress sync.
  • To review and, with your authorization, publish submissions.
  • To send sign-in codes only when you request them.
  • To monitor service health, troubleshoot faults, and prevent abuse.

3. Cookies and sessions

  • tm_session is an HttpOnly, SameSite=Lax session cookie with a rolling 30-day lifetime; frontend scripts cannot read it.
  • tm_csrf is a SameSite=Lax CSRF-protection cookie and carries no identity or private content.

4. Storage and backups

  • Structured data is stored in Cloudflare D1; sessions and comparison lists are stored in Cloudflare KV.
  • Daily database backups are retained in Cloudflare R2 for disaster recovery and may contain the data described above during their retention window.

5. Third-party services

  • Resend sends sign-in codes when configured.
  • GitHub OAuth is used only when you choose GitHub sign-in and only for authorized public profile data.
  • Turnstile may be used for bot protection during sign-in.

6. Your rights

  • Data portability: after sign-in, use Export my data to download your personal data as JSON.
  • Erasure: after sign-in, Delete account permanently removes your account and associated favorites, progress, notes, submissions, and sessions.
  • We do not sell your personal data.

7. Contact us

For privacy questions or requests, contact the site administrator through the feedback channel or visit the administrator profile.