← Home

Privacy

Minimal collection by design.

Search visibility

The site is intentionally configured not to be indexed by search engines. Direct links still work. Public pages remain crawlable only so search engines can observe the site's noindex response and remove already-discovered URLs.

Accounts and advertising

The public educational pages do not require a user account. The site does not include advertising pixels or an advertising network.

StudyHub

StudyHub stores game progress locally in the browser. Cross-device save uses a high-entropy family token held by the participating devices; the server stores a hash of that token rather than the plaintext token. There is no email/password sign-in for the family save.

Keep private share links private. Whoever has the family sync token can access that family save. Do not post a StudyHub share link in a public issue or message.

Resident learning progress

The resident-education hub can remember the last module selected so a learner can continue later. That value stays in browser localStorage and contains only the module route, module title, and save time. It is not a user account and is not sent to a server.

Analytics

The repository defines a privacy-first analytics policy. Cloudflare Web Analytics may be enabled for aggregate page/performance measurement. Custom behavioral events are disabled unless a same-origin endpoint, retention policy, and constrained event schema are explicitly approved.

Clinical and sensitive information

Do not submit protected health information, patient details, credentials, or other sensitive information through this site or its public issue tracker.

Internal areas

Administrative/control-plane routes are classified separately from public content and are intended to require Cloudflare Access or deployment exclusion.