Privacy

Lakenaut works without an account and without cookies of its own. This page lists everything the site stores when you do choose to give it something, and how to take it back.

Without an account

  • Your progress, theme and preferences stay in your browser (localStorage). They never reach the server.
  • If analytics are switched on, cookie-free tools run for everyone; tools that set cookies only start after you accept the banner.
  • If you send a report from a concept page, we store the message, the page, the optional reply address you typed, and a keyed hash of your IP address. The hash is only used to spot floods of reports; the address itself is never stored.

With an account

  • Your email address and, if you add one, a display name.
  • How you sign in: an email link, GitHub or Google. From GitHub and Google we keep only the account id and the verified email, never a token.
  • The concepts you mark as done and the badges you claim. A badge page shows your name only if you ask for it.
  • A session identifier in an HttpOnly cookie, stored on our side only as a hash.
  • Whether you agreed to be contacted, and when. The box is never ticked for you, and unticking it takes effect immediately.

From your account page you can download all of it as JSON, or delete the account. Deleting removes your progress, badges and sign-in methods at once; reports you sent stay, detached from you.

Newsletter

The newsletter is separate from accounts, uses double opt-in, and every email carries a one-click unsubscribe.

Where it lives

Everything is stored on Cloudflare (D1 and KV). Emails are sent through Resend. Nothing is sold or shared with anyone else.

Contact

Questions or requests: hello@lakenaut.dev.