Your data.
No Mistakes is an early learning-game experiment. This page describes what the current version stores and how its self-service controls work.
When you play
You can play without an account. In guest mode, your choices and progress stay in this browser’s local storage.
If you create an account, Cloudflare D1 stores your username, a salted password hash, session records, and the missions you complete. A completion contains the mission ID, XP, and completion time. The application database has no mission-attempt history table and does not store your wrong choices. It does not store your plain-text password, and it does not display your username or progress publicly.
When you join the waitlist
The waitlist stores the email you enter, your mobile-app interest, willingness to pay, selected price range, optional feature feedback, consent and update times, and a private source hash derived from network information. That source hash remains with the entry while the entry exists. The database also stores a hash of the private token used to remove the entry.
These answers are used to plan possible future versions. Joining is an expression of interest, not a purchase or paid subscription. No email service is connected to this version, so joining does not send an automated confirmation or update.
Cookies, browser storage, and hosting
A first-party, HTTP-only session cookie keeps signed-in players logged in for up to 30 days. Browser storage remembers guest progress and, after a new waitlist signup, the private removal link shown on screen. Cloudflare hosts the site and D1 database and receives request information needed to serve and protect the app.
Rate limiting stores HMAC-derived operational identifiers, a time window, and a request count. Session tokens are stored as hashes. Expired sessions and old rate-limit records are removed in small batches during some later requests; cleanup is periodic and is not guaranteed to happen immediately. The waitlist source hash is separate from that cleanup. This version has no advertising pixel or third-party product analytics integration.
Your choices
You can leave the waitlist blank and play as a guest. Signed-in players can permanently delete their account, active sessions, and saved completions from the account page. A waitlist entry is separate from a game account and can be deleted from the waitlist removal page with its private removal link.
Save that link when it is shown. The app cannot recover a lost removal link. Do not include passwords, credentials, or other sensitive information in the optional feedback field.
Early-version limits
There is no email verification, username reminder, or password reset. If you forget your username or password, the app cannot recover the account. Keep the credentials in a password manager. AI evaluation, a mobile app, and paid features are ideas being tested; they are not available in this version.
Back to the campaign ↗