Privacy
Build Physics privacy
The app can use PostHog to count a small set of anonymous product-usage events. Analytics are disabled unless the site operator supplies both required PostHog environment variables when creating the production build.
Anonymous analytics
The app only sends these event names and limited non-personal categories:
- page views, page leaves, app opening, and simulation starting;
- the identifier of a selected preset or tutorial;
- tutorial completion and graph opening;
- the export format used for a world export and when feedback is opened;
- save workflow steps, with only “computer” or “account” recorded as the destination;
- browser errors with messages and source-code context redacted.
What analytics do not collect
The analytics code does not collect names, email addresses, school names, typed content, uploaded scene files, saved scene contents, world names or descriptions, object labels, exported data, account identifiers, URL query strings or fragments, or other personally identifiable information. Automatic click, form, and input tracking, session replay, console-log capture, surveys, and user profiles are disabled.
Anonymous operation
Analytics use an anonymous identifier held only in browser memory, are not persisted across visits, respect the browser's Do Not Track setting, and ask PostHog not to use IP addresses for analytics or geolocation. As with any web request, the analytics service may process basic network metadata to deliver the request.
Optional feedback
The Send Feedback feature opens a Tally form only when you choose it. If you submit the form, Tally receives the answers and attachments you intentionally provide, an optional contact email if you enter one, and limited technical context: app version, build number, current preset and curriculum unit, whether a tutorial is active, browser and operating-system category, screen size, page URL without its query or fragment, and submission time.
Do not include student names, grades, school identification numbers, or other private information in feedback or attachments. A saved-world JSON file may contain labels or other text entered into the simulation, so review it before uploading. Feedback is separate from anonymous analytics and is never submitted automatically.
Local and cloud scene data
Automatic scene recovery, display preferences, and tutorial progress are stored locally in the browser. Downloading a scene to your computer does not require an account and does not send the scene JSON to the server.
If you choose “Save to my account,” the reviewed scene is sent to the Build Physics API and stored privately in Cloudflare R2. Cloudflare D1 stores the account owner, world name, optional description, dates, size, and object count. Cloud scene data is not sent through anonymous analytics. A pending save stays in page memory during authentication and is not placed in browser storage or a URL.
Accounts, Google sign-in, and transactional email
If you create an account, Cloudflare D1 stores your email address, a salted password hash, email-verification status, and hashed session, email-verification, and password-reset tokens. Build Physics does not store plaintext passwords or raw authentication tokens.
If you choose Sign in with Google, Google authenticates you and provides a stable Google account identifier, your email address, and confirmation that Google verified that address. Build Physics stores the identifier with your account so you can sign in again. It does not request or store your Google profile name, profile photo, contacts, files, or other Google account data, and it does not retain Google access or identity tokens.
Resend processes your email address and the contents of verification and password-reset messages only to deliver those requested account emails. Verification and reset links expire, are single-use, and are not sent to anonymous analytics.
Return to Build Physics