Privacy
Privacy policy
Effective 23 August 2026. This describes what StringTheory actually collects and does with it — nothing more.
What we collect
- Account details. Your email address and password credentials, handled by our authentication provider, plus the display name, location and roles you enter during onboarding.
- What you publish. Threads, replies, corrections and claim evidence, stored with your person record and shown with your display name.
- Claims and reports. The record you claimed or reported, the note you wrote, and the moderator's decision.
- Technical data. Standard server and error logs — request paths, timestamps, browser and IP information — used to keep the site working and to investigate abuse.
We do not sell personal information, and we do not run advertising or advertising trackers.
Directory records about you
Most directory records are compiled from public sources — a maker's own site, a school's programme page, an event listing. They contain professional information: name, role, business, city, public links. They do not contain private contact details. If a record about you is wrong, incomplete, or you want it removed, use suggest a correction or contact us and we will act on it.
What is public
Public: your display name, anything you post in discussion, and any directory record you manage. Private to you and StringTheory staff: your email address, your claim evidence, reports you file, and your account preferences. Discussion posts and directory records are indexed by search engines and may be summarised by AI answer engines.
Who processes it
StringTheory runs on a managed Postgres database and authentication service (Supabase) and is served through a cloud hosting provider. These providers process data on our instructions in order to run the site. Access controls in the database restrict rows to the account they belong to; staff access is limited to moderation and support.
Cookies and local storage
We use browser storage for one purpose: keeping you signed in. There are no advertising or cross-site tracking cookies.
Retention
Account and profile data is kept while your account exists. Discussion contributions are retained as part of the public record, though we will remove or anonymise your posts on request. Moderation records are kept as long as needed to run the platform fairly. Logs are kept short-term.
Your rights
You can ask for a copy of your data, correct it, or have your account and personal information deleted. Ask through contact and we will respond within 30 days. Depending on where you live, you may also have the right to object to processing or complain to a data protection authority.
Children
StringTheory is not intended for children under 13, and we do not knowingly collect their information. Education records describing youth programmes are about the programme, not about individual students.
Changes
Material changes will be posted here with a new effective date. See also our terms of use.