qedbot

Privacy

Privacy policy

qed.bot is run by The Logic Company, which decides how the personal data described here is used and is responsible for it under the UK General Data Protection Regulation. Write to hello@qed.bot about anything on this page.

Without an account

Everything on the register can be read without an account: the statements, the formal record, the museum, the datasets and the games. Reading sets no cookies. The games keep your progress and streaks in your own browser's storage, and none of it reaches us unless you are signed in and submit a score.

What an account holds

Account
Your handle; your email address, if you give one or a sign-in provider confirms one; the picture your provider shows for you; when you joined; and your settings.
Ways to sign in
For Google or GitHub, the identifier that provider keeps for you, the email address it reports and whether it has verified it, and your GitHub username or Google address as a label. We never see your password, and we keep no access token from either provider.
Sessions
A random token in a cookie, of which we store only a hash; when the session began and was last used; and the description your browser gives of itself, so you can recognise and sign out your devices.
What you do here
Your posts, replies, votes, bounties and claims, reports, followed problems, notifications and game scores.
Email
The messages we send you, such as sign-in links, alerts and digests, and whether each was delivered.
Abuse prevention
Counts of recent actions for each account, and of sign-in requests for each email address and each IP address, including the address itself.

How it is used

Running your account
Signing you in, following problems, discussion, votes, bounties and scores. The basis is our agreement with you to provide the service.
Sending what you ask for
Sign-in links, alerts on the problems you follow, and digests. Every alert carries a one-click unsubscribe. The basis is our agreement with you.
Keeping it safe
Rate limits, the check on sign-in forms that a person rather than a script is sending them, and moderation. The basis is our legitimate interest in a service that works and is not abused.

Your handle, posts, replies, bounties, claims and their verdicts, leaderboard scores and the vote counts on your contributions are public. Your email address, the votes you cast, the problems you follow and your settings are never shown to anyone else.

We do not sell personal data, show advertising, or use analytics or tracking cookies. Votes never change a grade.

Who else handles it

Cloudflare
Hosts the site and its database, and runs the Turnstile check on sign-in forms.
Resend
Delivers our email.
Google and GitHub
When you choose to sign in with them. What they do with your data is governed by their own privacy policies.

These providers may process data outside the United Kingdom. Where they do, it is under the data protection terms they offer their customers for such transfers.

Cookies

qed_session
Keeps you signed in. It lasts thirty days and renews while you use the site.
qed_oauth, qed_oauth_google
Protect a GitHub or Google sign-in while it is in progress. They last ten minutes.

Each is strictly necessary for something you ask for, so there is no consent banner. qed.bot sets no other cookies.

How long it is kept

Account data
Until you delete your account.
Sessions
Until they expire or you sign out; expired sessions are deleted within minutes.
Sign-in links
Deleted a day after they expire.
Abuse-prevention counts
Forty-eight hours, IP addresses included.
Email records
Thirty days, or one day for sign-in and confirmation emails, whoever they were sent to.

When you delete your account, we delete your email address, ways to sign in, sessions, followed problems, notifications, scores, sign-in links and the email we sent you. Your posts, replies and votes stay, attributed to a deleted account under a replacement handle, so that discussions and counts remain intact.

Your rights

From your account page you can see and download everything your account holds, including your sign-in identifiers, the email we have sent you and the abuse-prevention counts tied to your account, correct your handle and email address, and delete the account at any time. You can also ask us to restrict or stop using your data, or object to how we use it, by writing to hello@qed.bot. If you are unhappy with our answer, you can complain to the Information Commissioner's Office at ico.org.uk.

Age

Accounts are for people aged 16 and over.

Changes

When this policy changes, the date at the top changes with it, and significant changes are announced to account holders by email before they take effect.