Skip to content

World B-1The Archive

Privacy

Privacy notice

What this website collects, why, where it goes, and how to see, export or delete it. Last updated 2026-09-25.

Plain summary
  • The contact form is emailed to me and used only to reply. It is not added to any list.
  • Signing in with Google stores your name, email address, sign-in times, your settings and any promo code you claim from the level. Nothing else. No picture, no tracking, no analytics, no ads.
  • You get email from me only if you tick the box, and you can untick it any time in Settings.
  • Export or delete your account yourself from Settings → Account. Deletion is immediate and permanent.

Who I am

This website is operated by me, Connor Hagans, through Hagans Consulting, LLC, a Michigan company, trading as Hagans Tech. Questions about this notice, or requests you cannot complete from Settings, go to [email protected].

What I collect and why

1. The contact form

Your name, email address, business name and current website (both optional), the kind of project, a rough timeline and your message. The submission is delivered to my inbox as an email through Resend, an email delivery service, and is kept in that mailbox for as long as the conversation lasts. It is used only to reply to you. A hidden anti-spam field and a per-address rate limit protect the form; neither stores anything about you.

2. Accounts (optional)

If you choose to sign in with Google, the site stores: your name and email address as Google reports them, the fact that Google has verified the address, an internal account id and the Google account identifier used to recognize you next time, when you first signed in, when you last signed in and how many times, your settings and game progress, whether you ticked the newsletter box and when you last changed it, and any promo codes you claim from the level, with the time and your coin total at the time. The site also keeps a short audit log of account events (sign-in, sign-out, export, deletion, opt-in changes, code claims) by account id only, for security.

Purpose: to remember your settings and progress across devices, to keep a claimed promo code on your account so it can be honored when I scope your project, and to send you occasional email only if you asked for it. Legal basis, where one applies: your consent, which you can withdraw by deleting the account. The conditions attached to promo codes are on the terms page.

3. What I do not collect

  • No analytics, advertising pixels or cross-site tracking of any kind.
  • No profile picture, even though Google offers one.
  • No IP addresses or browser details stored by the application.
  • No data sold or shared with anyone for marketing.

The reverse proxy in front of the site keeps standard web-server access logs (address, path, time) for seven days, for security and troubleshooting only. Those logs are not linked to accounts.

Cookies and browser storage

  • ht_session: set only when you sign in. Strictly necessary; it keeps you signed in for up to 30 days. HttpOnly and, on the live site, Secure.
  • ht_oauth: set for at most 10 minutes during the sign-in handshake and removed as soon as it finishes.
  • Browser storage key ht:prefs: your settings and game progress, kept in your own browser. It is sent to the server only while you are signed in, so it can follow you.

There are no advertising or analytics cookies, so there is no cookie banner to click.

Davi, the site assistant

The chat bubble in the corner is Davi, an automated assistant, not a person. It runs on a small language model hosted on my own hardware; no message is sent to a third-party AI provider. Your messages in a conversation are held in memory only for as long as the conversation lasts and are not stored. If you ask Davi to pass a project inquiry to me, the details you confirmed and the transcript of that conversation are emailed to my inbox the same way the contact form is, and are handled under section 1. Davi can answer only questions about this site and the business; its replies are automated and can be wrong, so anything that matters is confirmed by me by email. You can always use the contact page instead.

Sign in with Google

Sign-in uses Google’s OpenID Connect service. When you sign in, Google shares your name, email address and whether it is verified, and a stable account identifier. Google’s own handling of your Google account is described in the Google Privacy Policy. You must be at least 13 years old and confirm you have read this notice before the first sign-in.

Services I rely on

  • Google, for sign-in only.
  • Resend, for delivering contact-form email to my inbox.
  • My own server infrastructure in the United States, where the site and its database run.

How long I keep things

  • Accounts: until you delete them.
  • Sign-in sessions: 30 days from creation, then removed.
  • Account audit log: 12 months.
  • Contact-form email: in my mailbox for the life of the conversation and normal mailbox housekeeping.
  • Proxy access logs: 7 days.

Your rights and how to use them

  • See and export everything held about your account: Settings → Account → Export. You get a JSON file immediately.
  • Delete your account: Settings → Account → Delete. It takes effect immediately and cannot be undone; the only trace left is an audit entry with the account id.
  • Stop email at any time: untick the box in Settings → Account, or use the link in any message.
  • Correct your name or email: they are refreshed from Google each time you sign in.
  • Anything else, including requests under the GDPR, the UK GDPR or the CCPA/CPRA, and questions about how a decision was made: email [email protected]. I do not sell personal information and I do not discriminate against anyone for exercising their rights.

Children

Accounts are for people aged 13 and over. I do not knowingly collect personal information from anyone younger. If you believe a child has created an account, email me and it will be removed.

Security

The site is served over HTTPS. Session cookies are HttpOnly and SameSite; the server stores only a hash of the session token, so a copy of the database cannot be used to sign in. Sign-in uses PKCE, a per-attempt state and nonce, and verifies Google’s signature on every identity token. Data-changing requests are rate-limited and checked against the site’s own origin. The database lives on a volume that is backed up nightly on infrastructure I administer myself. No system is perfect; if something goes wrong that affects you, you will be told.

Changes to this notice

When this notice changes, the date at the top changes with it and the change is recorded in the site’s changelog on the Lab page. Material changes to what is collected will be explained on this page before they apply.