Skip to content
The Fine Print

Privacy

Anonymous by default. Optional accounts sync only the data needed for your identity, progress, and chosen public presence.

Last updated

Controller and contact#

We operate SQL Heist and act as the data controller for the processing described in this notice. Privacy and data-rights requests can be sent to [email protected].

Data we process#

Data is collected electronically: directly from the signup/profile forms and your browser, from Google or GitHub only when you choose that sign-in method, through Supabase API requests when signed in, and automatically through ordinary hosting requests. Anonymous play does not require a name or email. Your browser stores your language choice and completed case objectives locally; hosting requests may include IP address, user agent, requested URL, and time.

If you create an account, we process your email, chosen username, optional display name, public-profile choice and consent history (grant or withdrawal, notice version, source, and time), completed case and objective identifiers, and account/progress timestamps. If you choose Google or GitHub, Supabase receives and stores the provider name, provider account identifier, verified email, and available fields such as name, username, and avatar URL as provider identity metadata. We request only sign-in identity/profile access. SQL Heist does not retain provider access or refresh tokens or use them to call provider APIs; a transient Google credential is used only to submit a best-effort revocation request immediately after a completed Google sign-in. Supabase automatically links identities that use the same verified email. Your password, if used, goes directly to Supabase Auth; only a salted password hash is retained, and we cannot read it. If you email us, we also process your address, message contents, sent/received times, and ordinary mail-routing metadata. We do not send your SQL practice payloads to Supabase or intentionally collect special-category data.

Local and synced progress#

Progress is always written to your browser first. While signed in, completed-objective sets are also merged into your account so progress can move across devices without deleting either copy. Clearing browser data removes the local copy, not the account copy; signing out does not erase either. Account settings let you export or request deletion of the synced copy.

Public profile and casual leaderboard#

Accounts are private by default. If you opt in, your username, optional display name, join date, objectives-cleared count, and activity timestamp may appear publicly. Email and internal user ID are never included. You can withdraw the opt-in from account settings; the profile and leaderboard entry then disappear immediately. We record each actual grant or withdrawal with a database timestamp and notice version so the choice can be demonstrated and respected. The casual leaderboard is based on client-submitted progress and is not a verified competition.

Service and sign-in providers; international transfers#

Cloudflare proxies the sqlheist.com domain and may process request/security data; Vercel serves the static site; Supabase provides authentication and database services for optional accounts; Microsoft Outlook.com/Hotmail handles messages sent to the contact address. If you choose provider sign-in, Google or GitHub authenticates you and sends the limited identity data described above to Supabase. The Supabase project database is in its eu-west-1 (Ireland) region. These providers do not receive your local SQL practice payloads from the game.

These providers and their disclosed subprocessors may process data outside your country, including outside Türkiye or the EEA, under their own terms and privacy notices where applicable. The required transfer mechanisms must be documented for the existing hosting, proxy, authentication, and contact-message processing. Contact us for current provider, subprocessor, transfer-basis, and safeguard details.

Retention and deletion#

Local data stays until you clear site data. Account, synced progress, and public-profile consent history remain while the account is active; there is currently no automatic inactive-account purge. Public visibility lasts only while you remain opted in. Closed support/privacy correspondence is deleted within 12 months, unless a law or active claim requires longer retention; it is then deleted when that period or claim ends. After we delete a message from Outlook.com, Microsoft says it generally remains in Deleted Items for about 7 days unless emptied sooner and, after that folder is emptied, can remain in Microsoft's systems for up to 30 days before final deletion unless law requires longer.

A deletion request immediately makes the profile private, locks later browser writes, and signs you out. The operator permanently deletes the Auth user and cascading profile, progress, and consent-history rows within 30 days. After completion, a private operator-only ledger keeps only a keyed HMAC of the Auth UUID and request, completion, deadline, and confirmation times for at most 90 days, then it is deleted; it contains no email, username, or raw UUID. SQL Heist submits a best-effort revocation request to Google immediately after each completed Google sign-in but cannot verify the response from this cross-site browser request. GitHub authorization may remain after SQL Heist account deletion; revoke SQL Heist separately in GitHub's Authorized OAuth Apps settings if you want to end it. Deleting SQL Heist does not delete your provider account. If provider logs or disaster-recovery copies contain related data, they remain only until no longer needed for security or until the applicable rolling backup is replaced; exact current periods are available from the controller.

Your rights#

Depending on the law that applies to you, you may request access, correction, deletion, restriction, objection, and portability, and may withdraw public-profile consent at any time. Account settings provide a JSON export of your email, account and provider identity metadata, profile, synced progress, and public-profile consent history, plus visibility and deletion controls.

Email [email protected] for a request the app cannot complete, including a username correction. We may verify your identity and will respond within the applicable legal deadline. You may also complain to your competent data-protection authority, including Türkiye's Personal Data Protection Authority where applicable.

Storage, tracking, and security#

This build's only measurement is Vercel's cookieless, aggregate analytics (anonymous page views and coarse device/referrer data, no personal profiling or cross-site tracking); it includes no advertising trackers or marketing cookies. It uses browser local storage for language, local progress, this notice, and—only when you sign in—the necessary Supabase session. A same-tab OAuth return record expires after 10 minutes; a successful deletion re-verification receipt is one-time and expires after 2 minutes. SQL Heist strips Google/GitHub provider tokens from persistent session storage. During email signup, the pending address expires after one hour and is removed on the next load/check; sign-in, sign-out, or clearing site data removes it sooner. Supabase Row Level Security limits base account rows to their owner, but no online system can promise absolute security.

Children and changes#

SQL Heist is an educational tool aimed at developers and is not directed at children. If you are below the age required to manage an online account where you live, do not create one without a parent or guardian. We will revise this notice and the date above before materially changing these practices. Questions or requests? Contact the controller.