Privacy
Last updated: 25 September 2026
The short version: this site keeps an account (an email, a username, a password hash), the concepts you marked as learned, a count of page views (counted on our own server — no third party, no IP, no cookie), and any feedback you choose to send (with an email address only if you leave one). Nothing else. No advertising, no tracking pixels, and no request from your browser to anybody else while you read.
What is kept on your machine
- The language you picked, and your display settings — in your browser's own local storage, on your machine only.
- Your session, as a cookie named kg_session (HttpOnly, Secure, 30 days). It holds a random token, not your name: signing out deletes it, and deleting it signs you out.
- One random id under the name kg-visitor, so that different visitors can be counted without knowing who anybody is — see “Counting page views” below. It lives in local storage; clearing site data removes it.
What is kept on the server
Only when you make an account, and only these:
- Your email address and your username.
- Your password, as a PBKDF2-SHA256 hash with a per-account salt. The password itself is never stored and never logged.
- The concepts you marked as learned, with the moment you marked them — that is what makes your progress follow you to another machine.
The address is not verified at signup — there is still no confirmation link. The one email this site sends is a password reset link, and only when you ask for one from Sign in → Forgot password: it goes to the address already on the account, and asking for one tells us nothing new about whether that address exists.
Signing in with Google or Apple
You can sign in with a Google or an Apple account instead of a password. In that case the provider tells us an account id (its own, stable id for you) and your email address, and we store exactly those two — nothing else. We ask for no other permission, we keep no access token, and we never call the provider's API on your behalf. No Google or Apple script runs on this site: the sign-in is a redirect, handled on the server.
If you use Apple's Hide My Email, the address we receive is the private relay one Apple generated, and that is the address stored.
Counting page views
Each time a page is opened, this site's own server writes one row: the path (with everything after a ? removed), what kind of event it was (a page view or an app download), the random id above when there is one, and the date (UTC). Nothing else — no IP address, no user agent, no referrer, no screen size, no time spent on the page.
What it is for: only so the site's owner can see which pages get opened and how many times the app is taken. No personalisation, no advertising, no selling, no sharing. Rows older than 400 days are deleted automatically, and clearing site data in your browser starts you over with a new id that cannot be connected to the old one.
The feedback you send
If you send feedback, the server stores exactly what the form has: what you wrote, your email address if you chose to leave one, the image if you chose to attach one, the path of the page you were on (with everything after a ? removed), and when you sent it. No IP address, no user agent, no cookie, and no account needed.
About the image: also optional, one per message. It is stored as you sent it (not altered, and its metadata is not mined for anything) and only the site's owner can open it — the image address answers 401 to anyone not signed in and 403 to any other account. A screenshot can hold more than you meant to send, so do glance at it first: whatever is in the frame is what gets stored.
The address is optional, and it is used for one thing: replying to you. No mailing list, no marketing, no sharing. Leave it blank and the message is still read. Only the site's owner can read these — the same single account that can read the page-view numbers above.
What is not done
- No third-party analytics, no advertising, no tracking pixels. The page-view count above is kept by this server, and does not go through Google Analytics or any other service.
- No third-party requests while you read: the topics, the fonts and the icons all come from this site. No content delivery network of ours sees you visiting anything but this site.
- Your data is not sold, shared or published.
- No IP address, no device fingerprint, no history is stored on an account row — and none of those are in the page-view table either.
Where it lives
The site is static files on Cloudflare Pages, and the account and progress records are in a Cloudflare D1 database (SQLite) in Cloudflare's APAC region.
One outside service: Resend, to deliver the password reset email. It sees the address you typed and nothing else about your account — no password, no progress, no notes.
Deleting it
There is no delete button in the interface yet — that is the honest answer rather than a missing paragraph. Mail the address below from the account's own email and the account is deleted: the account row, its sessions, its sign-in identities, and the progress record it owns. Nothing else in the database mentions it.
Feedback too: say what you sent (or write from the address you left) and the row is deleted, together with the image if there was one. A message sent without an address cannot be connected back to you by anybody, us included, so quote what you wrote and the right row can be found.
Contact
Or use the feedback form — no address and no account needed.