XPNook

Privacy

Privacy at XPNook

Product usage data

We use first-party product analytics stored in Supabase to understand usage and improve the website.

Events currently include page views on game and tool pages and the home page, successful code copies, and successful progress calculator use and recalculation. Events contain an event name, relevant game slug, page type or target identifier, and limited metadata such as content state, the copied public code and reward, calculator attempt number, tool kind and result state. Calculator input values are not sent in these events.

Our analytics does not ask for your account, name or email address. If you email us, we receive your address and the information you choose to include in your message.

Session identifier and browser storage

A random UUID is generated in your browser and stored in sessionStorage under pyramidlab_session_id. This pseudonymous, session-scoped identifier is sent with events to associate activity within a browser tab session. It survives reloads and normally clears when that tab session ends. It is not a claim of complete anonymity.

Product analytics does not use cookies or localStorage. The Supabase client is configured to persist authentication sessions using localStorage, or brokered storage in the Lovable preview if an authentication session exists. Players do not need an account for feedback; restricted XPNook administrator authentication is separate from player feedback identity. Hosting and service providers may process network information such as IP addresses and User-Agent headers when handling requests.

Public player feedback

Feedback submissions are intended as public content. We store your nickname, feedback title and messages, game/page/category context, timestamps, and moderation and thread status in Supabase. You do not need an email address or XPNook account to submit. Content is reviewed before publication and may be moderated or hidden.

A reply capability is stored in your browser's localStorage to prove permission to continue your thread; it is separate from analytics identifiers and administrator sign-in. Clearing browser storage or changing devices may lose that permission; there is no nickname-based recovery. Keep this capability private.

Do not submit passwords, email addresses, account credentials or other sensitive information. Application Feedback records do not store source IP addresses, browser history, calculator inputs or analytics session identity. Infrastructure providers may temporarily process source information for request handling and abuse protection.

The planned analytics retention period below does not apply to feedback. For feedback deletion or privacy requests, contact pyramidlab.contact@gmail.com and identify the thread without sending your reply capability or credentials.

Third-party services and tracking

We do not use Google Analytics, Meta Pixel, advertising trackers or third-party marketing tracking, and we do not sell user data. Supabase provides data infrastructure, and fonts are loaded from Google Fonts. Lovable editor previews may report runtime errors through preview tooling. These services may receive information needed to serve requests. Links to external sites are subject to those sites’ privacy practices.

Retention

Our planned retention period for raw product analytics events is 90 days. Automatic cleanup is pending production configuration and verification; this is not a statement that older events have already been deleted. This period applies to raw product events, not necessarily provider operational logs, backups or email correspondence.

Privacy questions and requests

Contact pyramidlab.contact@gmail.com with privacy questions or requests. Please avoid sending sensitive credentials.