Anonymous learning history and device credentials
When the adaptive learning service is available, Cloudflare D1 stores a random learner ID, state, practice sessions, reviewed question IDs and versions, selected answers, whether an answer was correct, an optional “not sure” confidence mark, optional response time, confidence-aware topic mastery, deliberately saved rule IDs, and session timestamps.
Each linked device receives a separate random bearer credential. D1 stores only a SHA-256 digest of that device secret, a user-chosen device label, creation and last-use timestamps, expiration, and revocation status. The raw credential remains on that device. Legacy anonymous learner tokens are accepted only during migration to the revocable device model.
The learning database does not store a name, email address, password, birthday, driver-license number, payment information, precise location, IP address, user-agent string, or browser fingerprint.
One-time cross-device pairing
A linked device can create a 12-character pairing code for another device. The visible code expires after 10 minutes and can be redeemed once. D1 stores an HMAC digest of the code rather than the plaintext code, plus its creation, expiration, redemption, and linked-device records.
Anyone who receives an active code can link a device to the same anonymous history. Keep it private, use it only between devices you control, and revoke unfamiliar devices from the device-sync page.
On-device fallback progress
If the learning service is unavailable—or you explicitly choose the local engine—the quiz continues from the public reviewed question files. A small summary may be stored in browser local storage, including the state, mode, score, missed or guessed question IDs, topic results, recent full-session percentages, deliberately saved rule IDs, and completion time.
Local summary data is not synchronized. When devices are deliberately linked, they share the D1 learning history but keep separate local summaries and separate revocable credentials. Clearing browser site data removes this device's credential and local summary, but it does not revoke another linked device.
Anonymous aggregate difficulty
Each answer also contributes to state-level aggregate question totals: attempts, correct answers, answers marked “not sure,” and confidence-aware learning credit. These counters contain no learner ID, device ID, IP address, or answer sequence. They are used only after a question has at least 20 anonymous attempts, so “Hardest rules” can reflect observed difficulty without exposing one person's history.
Deleting a learner removes the raw sessions and attempts linked to that anonymous profile. It does not subtract the already combined, non-identifying aggregate counters because those totals no longer retain a learner-level link that could support subtraction.
Your controls
Each state page has a “Clear progress” control that removes that state's local score summary and, while a valid device credential is available, that state's server-side sessions, attempts, confidence marks, and topic mastery. Saved Rules remain separate so they are not erased accidentally and can be removed individually. The sync page can rename or revoke devices. The control below deletes the anonymous learner profile, synchronized Saved Rules, every device and pairing record, and all linked server learning data; this browser also removes its local Saved Rules.
No advertising, behavioral analytics, or email capture
The product contains no advertising SDK, behavioral analytics SDK, marketing pixel, social login, newsletter form, or payment form. It does not use a marketing cookie or build an advertising profile from practice answers.
Cloudflare delivery and security data
The site, API, and database run on Cloudflare. Like other network and hosting providers, Cloudflare may process request information such as IP address, user agent, requested path, timestamp, and security signals to deliver and protect the service. Cloudflare's own terms and privacy notices govern that provider processing.
External official-source links
Question explanations link to agency and federal sites. When you follow an external link, that site's privacy practices apply. We do not control those sites.
Changes
If the product later adds named accounts, analytics, feedback submission, ads, payments, or new categories of stored information, this notice must be updated before those features are enabled. Material changes receive a new effective date.