site

Privacy

learn.mimmsy.com is a library of small interactive teaching widgets that anyone can embed, fork and improve. This page says what the site stores about you, for how long, which companies handle it on the site's behalf, and how to take it away. It is written to be read, not skimmed for a checkbox: it is short because the site keeps little.

Last updated 13 September 2026. The terms of use are the other half of the deal; the two pages agree, and where one names a rule the other does not repeat it.

What is stored without an account

Most of what the site does needs no account, and most visitors never make one. Reading a page, using a widget, searching, embedding a widget on your own site and submitting a draft all work while the site knows nothing about who you are.

While you do those things the site records signals: small notes that a widget or page sends back saying what happened, such as which widget was on screen, that it was interacted with, that one of its check questions was passed or failed, how many seconds it was visible, and that a visitor said “publish” or “discard” about a draft. Each signal carries the widget’s name and version, the event, a session id (a random string your browser makes up when you arrive and forgets when you close the tab; it is not tied to you), the origin of the page the widget was embedded on (the site address, such as https://example.org, never the full page address or its contents) and a hashed IP. Hashing means your network address is run one way through a function so the result cannot be turned back into the address; the site mixes in the current date, so the same address gives a different result tomorrow and nothing can be followed from one day to the next. The hash exists so that one visitor cannot send a thousand signals a minute, and for nothing else.

Raw signals are kept for 180 days and then deleted by a scheduled job. Before they go, they are folded into per-widget totals, such as the pass rate, the engaged seconds and how many sites embed it. The totals are what rank widgets and they are kept indefinitely, but they are sums with no session id, hash or origin in them.

If you submit a draft (a widget that has not been reviewed), the site stores the bundle you sent, its manifest, and a claim token: a secret string returned to you once, which is the only way to attach your name to the draft later. If you claim it, the name and web address you give are stored with it and shown beside it. If you say “publish” or “discard” about a draft, that assent is stored with the widget’s name and your session id.

Your progress through a page or a widget, such as a best streak or which checks you have passed, stays in your browser’s own storage and never reaches the site unless you sign in.

What is stored with an account

Signing in with GitHub creates an account. The site stores your GitHub id (a number GitHub uses for you), your display name, and the email address GitHub gives it. The email is stored so that account deletion can be confirmed to you; it is not used for anything else today and no email of any kind is sent yet. The site does not receive your GitHub password and does not keep the token GitHub issues during sign-in beyond that sign-in.

A session is the record that keeps you signed in. Each lasts 30 days from sign-in, then expires. Signing out ends it at once. Sessions are live credentials, so they are left out of your data export.

If you connect the site to a chat assistant such as Claude and sign in there, the site stores the grant that lets the assistant act as you, until you delete the account or the grant is revoked.

The site stores your plan, which is the name of your allowance for the chat and the date it renews, and metering rows: for each period, how many chat turns and authoring runs you used and what they cost, in the site’s own accounting. These rows count; they never contain the text of a conversation.

Nothing you type in the chat is stored. Your messages go to the model and come back, and the site keeps only the count and the cost. This will change when saved chats exist as a feature: when it does, saved transcripts will be stored under your account and this sentence will be replaced by one that says so.

You also own what you make while signed in: the drafts you submit carry your id instead of a claim token, and so do the links you propose between widgets and the reports you file about a widget or page. Signals sent from this site while you are signed in carry your id, which is how your progress on /me/ is worked out; signals from widgets embedded on other sites never do.

Who processes it

The site runs on Cloudflare, which hosts the site and its server, holds the database, stores draft bundles, runs the search index, and runs the embedding model that turns a widget’s claim and a search query into numbers so they can be compared. Cloudflare’s bot check, called Turnstile, runs in front of the anonymous write paths and the chat preview; it runs inside Cloudflare’s own frame and what it observes is governed by Cloudflare’s privacy policy. As the host, Cloudflare sees every request to the site, including your network address, the way any host does.

The chat and the screening step run on Anthropic’s models. When you use the chat, the messages you send, and the widget text the chat looks up or writes, are sent to Anthropic’s API. When a draft is submitted, its text is sent to a classifier on the same API that checks it before it is listed. Both go under Anthropic’s API terms, which do not allow the text to be used for training. If a second model vendor is ever added, it is named here before it receives anything.

Sign-in is through GitHub, which learns that you signed in to this site and gives the site the fields named above. Google sign-in is planned as a second option; when it is added it is named here first.

No email is sent today, and no email vendor receives anything. When a sender is configured, the vendor is named here first.

Nothing is sold, shared with advertisers, or given to anyone not named on this page.

Your own key

The chat can run on an API key you supply yourself, which is the secret string a model vendor gives you so requests are billed to your account. The key is sent with your request, used to make that request to the vendor on your behalf, and then gone: it is never stored, never written to a log, and never seen by anyone. What the request contains and returns is between you and your vendor under your vendor’s terms. The site still counts the turn, but counts it as yours rather than the site’s.

Retention and deletion

Raw signals are kept for 180 days. The per-widget totals made from them are kept indefinitely. Everything else, which is to say everything tied to your account, is kept until you delete it.

/me/ is where you manage your account. It has an export, which returns everything stored under your id as a single file, and a delete, which removes it. Deleting removes your account rows, your identities, your plan and metering rows, your grants to chat assistants, and the drafts, links and reports you own; it also ends every session. On the signals you sent while signed in, deletion blanks your id but keeps the row, so that the totals a widget earned while you used it stay honest. A row with a blanked id says only that some visitor once passed a check.

Anonymous data has nothing to delete against: a claim token is the only handle on an anonymous draft, and a signal’s hashed IP cannot be traced back to you.

Cookies

The site sets one cookie: the session cookie, which keeps you signed in after you sign in. It is strictly necessary for that one job and does nothing else. There are no advertising, analytics or tracking cookies, and none from third parties, which is why the site shows no cookie banner: the law only asks for consent for cookies that are not strictly necessary. Before you sign in, the site sets no cookie at all.

Widgets keep small things, such as your best streak, in your browser’s own storage. That is not a cookie, it never leaves your browser, and you can clear it in your browser settings at any time.

Contact

Questions about this page, or a request about your data that the controls on /me/ do not cover, go to abuse@mimmsy.com, described on the abuse page. The operator may change this page; the date at the top is the date of the current version, and the history is in the repository.