Privacy

Build Physics privacy

The app can use PostHog to count a small set of anonymous product-usage events. Analytics are disabled unless the site operator supplies both required PostHog environment variables when creating the production build.

Anonymous analytics

The app only sends these event names and limited non-personal categories:

What analytics do not collect

The analytics code does not collect names, email addresses, school names, typed content, uploaded scene files, saved scene contents, world names or descriptions, object labels, exported data, account identifiers, URL query strings or fragments, or other personally identifiable information. Automatic click, form, and input tracking, session replay, console-log capture, surveys, and user profiles are disabled.

Anonymous operation

Analytics use an anonymous identifier held only in browser memory, are not persisted across visits, respect the browser's Do Not Track setting, and ask PostHog not to use IP addresses for analytics or geolocation. As with any web request, the analytics service may process basic network metadata to deliver the request.

Optional feedback

The Send Feedback feature opens a Tally form only when you choose it. If you submit the form, Tally receives the answers and attachments you intentionally provide, an optional contact email if you enter one, and limited technical context: app version, build number, current preset and curriculum unit, whether a tutorial is active, browser and operating-system category, screen size, page URL without its query or fragment, and submission time.

Do not include student names, grades, school identification numbers, or other private information in feedback or attachments. A saved-world JSON file may contain labels or other text entered into the simulation, so review it before uploading. Feedback is separate from anonymous analytics and is never submitted automatically.

Local and cloud scene data

Automatic scene recovery, display preferences, and tutorial progress are stored locally in the browser. Downloading a scene to your computer does not require an account and does not send the scene JSON to the server.

If you choose “Save to my account,” the reviewed scene is sent to the Build Physics API and stored privately in Cloudflare R2. Cloudflare D1 stores the account owner, world name, optional description, dates, size, and object count. Cloud scene data is not sent through anonymous analytics. A pending save stays in page memory during authentication and is not placed in browser storage or a URL.

Accounts, Google sign-in, and transactional email

If you create an account, Cloudflare D1 stores your email address, a salted password hash, email-verification status, and hashed session, email-verification, and password-reset tokens. Build Physics does not store plaintext passwords or raw authentication tokens.

If you choose Sign in with Google, Google authenticates you and provides a stable Google account identifier, your email address, and confirmation that Google verified that address. Build Physics stores the identifier with your account so you can sign in again. It does not request or store your Google profile name, profile photo, contacts, files, or other Google account data, and it does not retain Google access or identity tokens.

Resend processes your email address and the contents of verification and password-reset messages only to deliver those requested account emails. Verification and reset links expire, are single-use, and are not sent to anonymous analytics.

Return to Build Physics