Data and privacy

What data SupaKewber uses—and what stays private

SupaKewber needs data to save progress and run community features. Search-indexed discovery is controlled separately, and research publishes aggregates.

This page describes current product behavior in plain language. SupaKewber is independently operated by Kalle under the Kewber identity. Questions and data requests can be sent through the contact page.

Data map

Data used by each feature

FeatureData usedPurposePublic by default?
Account and securityUsername, email, password hash, session/security records and optional MFA settings.Sign-in, recovery, abuse prevention and protection.No
Saved solvesTime, scramble, penalties, mode and, when available, stage milestones, move count and normalized cube family.History, statistics, feedback and eligible aggregates.No. Search publication is separate.
CompetitionEntries, averages, completion state and results.Tournaments, ranks, rewards and result pages.Eligible results can be public; contact/security fields are not.
Connection diagnosticsOutcome; coarse browser, OS and cube family; error category and duration.Find compatibility and reliability problems.Only aggregate statistics after threshold.
Contact formName, email, subject, message and optional account link.Support, feedback, corrections and press.No

Bluetooth privacy

Raw Bluetooth names are not kept in telemetry

The diagnostic endpoint normalizes a device into a broad family such as GAN iCarry, GAN 12 ui or GAN 356i before storage. It does not store the Bluetooth name verbatim because names can contain user-assigned or hardware-specific text.

Connection events use a random identifier and do not include account ID, solve, scramble, move sequence or cube MAC address. Diagnostics are best-effort; failure does not interrupt the cube connection. Browser privacy signals that disable optional diagnostics are respected.

Public activity

Community visibility and search indexing are different controls

The in-app community can show cubing activity without email, authentication details, full scrambles or move sequences. A permanent search-indexed player page has stricter rules: the player opts in, chooses a public slug and has enough valid smart-cube activity.

  • Profile pages require at least 25 valid smart-cube solves plus a personal best and current average.
  • Statistics pages require at least 100 valid smart-cube solves.
  • Empty, private or incomplete profiles are excluded from player sitemaps.
  • Published records never add email, password/security data, raw Bluetooth identity, scramble or full move sequence.
  • Players can delete individual solves and change profile or solve visibility controls.

Research privacy

Public datasets use minimum group sizes

First-party research normally publishes a cell only after 20 distinct users and 100 eligible observations. Anonymous connection diagnostics require at least 100 observations. Below-threshold cells are suppressed.

Research downloads omit username, email, account ID, solve ID, scramble, raw moves and individual result. WCA export analysis is labelled separately.

Security and retention

How access is protected and data is kept

Passwords are stored as hashes. Authentication uses random server-side session tokens in secure, HTTP-only production cookies. State-changing requests use anti-forgery protection, and optional multi-factor authentication is supported.

Operational data is retained while needed for the account, history, competition, security or support feature and legitimate integrity needs. Expired sessions are cleaned up. SupaKewber does not promise a shorter fixed period where the product does not enforce one. Backups and server logs may persist for a limited operational period and are not used for public profiles.

Your choices

Control, correction and deletion

You can keep a permanent profile private, control selected solve visibility and delete saved solves. For access, correction, account deletion or another request not available in the interface, use the contact form with the account email.

Do not send passwords, multi-factor secrets or recovery codes. Identity may need verification before an account-specific request is completed.

Changes

When this explanation changes

Last updated . Material changes to collection, public visibility or research rules will update this date and explanation.