Privacy
What we store, what we don't, and how to delete it.
What we store
Your did:key is generated and stored on your own device — device-key-wrapped under a non-extractable IndexedDB key. P31 keeps no server-side identity store. The public DID is what the rest of the workspace sees; the private key never leaves your device.
Analytics
None. The site ships without Google Analytics, Plausible, or any tracking script. The zero-telemetry posture is a documented gate in the build, not a marketing claim.
Cookies
The site’s own code sets no cookies. The only preferences stored are the theme and spoon level in localStorage, which stays on your device — these are functional preferences, not tracking. Your Cloudflare edge provider may set strictly necessary cookies (e.g., for bot management) on its own infrastructure; under the ePrivacy directive these fall in the "strictly necessary" exemption, are not tracking cookies, and we do not read them.
Children’s privacy
P31 is designed for use by a parent or guardian who manages a child’s device-local identity. The site does not knowingly collect personal information from children under 13. No child profile is stored server-side — the child’s identity lives on the device and never leaves it. For COPPA-related inquiries, contact willyj1587@gmail.com.
GDPR — visitors in the EU/EEA
If you are located in the EU/EEA and we process your personal data (for example, you email us or make a donation through a linked processor), we do so under the lawful basis of legitimate interest for responding to inquiries, and consent for any marketing communication. You have the right to access, correct, delete, and port your data, and to object to processing. To exercise these rights, contact willyj1587@gmail.com. P31 has not appointed a GDPR Article 27 representative; data-subject requests are handled directly.
Donation processors
Donations are processed by named third parties, not by P31 directly: Stripe, Ko-fi, PayPal, and Blockonomics (crypto). Your card or payment details go to the processor you choose; P31 does not receive or store them. Each processor handles your data under its own privacy policy.
The audit chain
The Loom records that an action happened and by whom — not the content of what was said or built. The chain is hash-linked and independently verifiable at the public verify endpoint.
How to delete
Clear the site data for this origin (the DID is stored locally). Removing it removes your on-device identity. No server-side copy exists to delete.
Contact
For privacy questions or a deletion request, email willyj1587@gmail.com.
Effective: June 10, 2026