Privacy Review: the export button is a convenience, not the boundary of access Access was listed as self-service and immediate, which implied the download carried everything. It carries the account, every episode and turn, and sign-in times. It does not carry problem reports and their traces, notification bookkeeping, or the inferred model of which concepts a player has met. That was accurate when written and the venue held four kinds of player data. It stopped being accurate as three more arrived, and no button was ever what the right of access required. The right is unchanged and could not be changed by a page: a person is entitled to a copy of everything held about them on request, and the same address that honors an erasure honors that. What changes here is the claim made for the button, which is now what it does.
Privacy Review: retention is indefinite, erasure is the deletion path Two rows carried a clock: sign-in times at ninety days, attached problem-report traces thirty days after a report was closed. Both are gone, along with the daily sweep that enforced them. The ninety-day figure was set when a sign-in record also held an IP address, coarse location and a user-agent. Those columns were dropped shortly after and the figure was never revisited, so what the sweep removed by the end was an account identifier already held elsewhere and a timestamp. The trace clock was never a considered decision; it was settled while the sweep was being written. Its reasoning was that a trace describes a device rather than a problem and has done its job once a report closes. The effect was worse: bugs recur, closed reports get reopened, and the trace is what makes the second report answerable. One criterion the venue keeps beats several periods it has to remember. The criterion is disclosed, which is what is asked for when a fixed period is not given, and erasure enforces it.
Privacy Review: erasure removes more than this page claimed The page said erasure removes the player record, episodes, turns and sign-in records. Three further categories of player data existed and were not cleared by it: problem reports and the traces attached to them, the notification history, and the inferred model of which concepts a player had met. No erasure request had been made, so nothing was mishandled. The venue now clears all of it, and the set of stores holding player data is derived from the schema and checked against what erasure actually does, in both directions, on every commit. A reviewer reading the old sentence would have been told something narrower than the truth about what survives a request. This says what happens.
Privacy Review: the problem-report trace now expires 30 days after closing The trace had no stated life, the only personal-data item without one. A scheduled sweep now deletes it thirty days after the report is closed, while the message stays until erasure, since the trace is the part describing a device rather than a problem. Deployed 2026-08-13.
wiki: name which machine makes each request
wiki: reviewer pages state current facts only
wiki: Security Review and Privacy Review pages