Skip to content

Data handling / implementation disclosure

Follow your data.

This page describes the project’s current data flows. It does not claim a compliance certification or a guaranteed retention period.

Anonymous learning

Lesson milestones, guided-defense completions, legacy LLM completion markers, and scripted agentic progress are stored in browser localStorage. Guided requests and policies go to our Next.js server, execute on synthetic resources, and return a result. The guided endpoint does not persist the request or full evidence to Firestore. Full guided evidence exports are generated in the browser.

You can export and clear new device milestones from your learning record. Clearing browser site data also removes local records and saved viewer-key settings.

Google sign-in and competition

Firebase Authentication verifies Google identity. The private player record may link email, user ID, cohort membership, handle, and optional college. Public leaderboards use handles, scores, completion counts, and solve timestamps; email is excluded from their API responses.

Ranked LLM sessions store the authenticated user ID, mission, expiry, submitted prompts, bounded model-response excerpts, attempt counts, and execution state in server-only Firestore collections. Session expiry stops execution after 20 minutes; expiry does not automatically delete stored records. Competition and rate-limit records are also stored server-side.

Signed-in agentic runs store ranked solve identifiers, backend information, points, and timing. Cohort organizers retain the existing private email-to-player linkage for participant administration.

Model providers

Hosted live execution uses the configured OpenAI or Anthropic provider. Submitted prompts, relevant conversation history, synthetic target instructions, and model-grading material may be transmitted to that provider. Provider handling is governed by the operator’s provider configuration and applicable provider terms.

Viewer-key LLM mode stores the key in browser localStorage and sends requests directly from the browser to the selected provider. Our grading endpoint does not receive that key. A localStorage key is accessible to scripts running on the site; use key settings or clear site data to remove it.

Analytics and community

The project records aggregate daily funnel counters, such as visits, attempts, solves, and user-triggered shares. Those counters do not include raw prompt text. Hosting and model providers may maintain their own operational logs.

Community submissions are public text, not private evidence storage. The current community board does not establish whether a submitted prompt succeeded. Do not submit credentials, private participant data, or sensitive production evidence.

Retention and requests

This implementation does not yet enforce automatic deletion periods for all server records or provide self-service server deletion. Device milestones can be cleared locally. For a server-data or security request, use the project’s GitHub contact route without including private data in a public issue.

Firestore permissions deny client writes to scores and deny direct client access to private sessions and player records. Server APIs verify identity where ranked or private data is required. Synthetic tool worlds are isolated per execution and do not perform real payment or publication actions.

Project security information ↗ · Execution documentation