qedbot

Privacy policy

qed.bot is run by its operator ("we"), who decides how the personal data described here is used and is responsible for it. Write to hello@qed.bot about anything on this page.

Without an account

Everything on the register can be read without an account: the statements, the formal record, the museum, the datasets and the games. Reading sets no cookies. The games keep your progress and streaks in your own browser's storage, and none of it reaches us unless you are signed in and submit a score.

What an account holds

Account
Your handle; your email address, if you give one or a sign-in provider confirms one; the picture your provider shows for you; when you joined; and your settings.
Ways to sign in
For Google or GitHub, the identifier that provider keeps for you, the email address it reports and whether it has verified it, and your GitHub username or Google address as a label. We never see your password, and we keep no access token from either provider.
Sessions
A random token in a cookie, of which we store only a hash; when the session began and was last used; and the description your browser gives of itself, so you can recognise and sign out your devices.
What you do here
Your posts, replies, votes, bounties and bounty claims, corrections, reported results and the claims you add to the register, the claims you are recorded as an author of, reports, followed problems, the papers and phrases you watch for, notifications and game scores.
Corrections, results and claims
For each correction you request, result you report or claim you add, the record or problem it concerns, what you wrote, the sources you cite, the AI systems you name, and its review. A claim also holds the people you name, the day and outcome you give, the Lean proof you link with the outcome of each check it reaches, and any autonomy grade an administrator gives it on review. An accepted claim enters the register and its datasets with your handle as the reader who added it.
Authorship of claims
For each claim you say is your work, which claim it is and how you were verified. Through GitHub: the repository that verified you, and whether the GitHub account you connected owns it, contributes to it or publicly belongs to the organisation that owns it. Through an administrator: the evidence you give, and its review. And any statement you post as its author.
Bounties
For each bounty you pledge, the name you give, which is shown publicly with it, and the email address you confirm with a code, which is kept private.
Email
The messages we send you, such as sign-in links, alerts and digests, and whether each was delivered.
Abuse prevention
Counts of recent actions for each account, and of sign-in requests for each email address and each IP address, including the address itself.

How it is used

Running your account
Signing you in, following problems and watching for papers and phrases, discussion, votes, bounties, corrections, reported results and claims, and scores.
Sending what you ask for
Sign-in links, the codes that confirm a bounty, alerts on the problems you follow, and digests, which also carry sightings of the papers and phrases you watch for. Every alert carries a one-click unsubscribe.
Keeping it safe
Rate limits, the check on sign-in and pledge forms that a person rather than a script is sending them, confirming that the email address behind a bounty works, and moderation.

Your handle, posts, replies, bounties and the name you pledged them under, bounty claims and their verdicts, corrections, reported results and claims with their sources, checks and review, the claims you are recorded as an author of with how you were verified and your statements as an author, leaderboard scores and the vote counts on your contributions are public. Your email addresses, including the one behind each bounty, the evidence you give an administrator to be recorded as an author, the votes you cast, the problems you follow, the papers and phrases you watch for and your settings are never shown to anyone else.

We do not sell or share personal data, show advertising, or use tracking cookies. Votes never change a grade.

Counting visits

To know which pages are read, qed.bot uses Cloudflare Web Analytics. A small script from Cloudflare reports each page view: the page, the site that linked to it, your browser, operating system and type of device, your country, and how quickly the page loaded. It sets no cookies and stores nothing in your browser, and Cloudflare does not use it to identify or fingerprint you. We see only totals.

Some browsers send a Do Not Track signal. qed.bot does not track anyone across other sites, and neither does anything it loads, so every visit is treated the same whether or not the signal is sent.

Who else handles it

Cloudflare
Hosts the site and its database, runs the Turnstile check on sign-in forms, and counts visits with Web Analytics.
Resend
Delivers our email.
Google and GitHub
When you choose to sign in with them. To verify that a claim is your work, we also read GitHub's public records of the repository it cites: who owns it, the public members of the organisation that owns it, and who has contributed to it. What they do with your data is governed by their own privacy policies.

These providers may process data in countries other than yours, under the data protection terms they offer their customers.

Cookies

qed_session
Keeps you signed in. It lasts thirty days and renews while you use the site.
qed_oauth, qed_oauth_google
Protect a GitHub or Google sign-in while it is in progress. They last ten minutes.

Each is strictly necessary for something you ask for, so there is no consent banner. qed.bot sets no other cookies.

How long it is kept

Account data
Until you delete your account.
Sessions
Until they expire or you sign out; expired sessions are deleted within minutes.
Sign-in links
Deleted a day after they expire.
Unconfirmed pledges
Deleted within minutes of their code expiring, thirty minutes after it is sent.
Abuse-prevention counts
Forty-eight hours, IP addresses included.
Email records
Thirty days, or one day for sign-in, confirmation and bounty-code emails, whoever they were sent to.

When you delete your account, we delete your email address, ways to sign in, sessions, followed problems, the papers and phrases you watch for, notifications, scores, sign-in links, unconfirmed pledges, your authorship of claims and the statements you posted as an author, the email addresses behind your bounties and the email we sent you. Your posts, replies, votes, bounties, corrections, reported results and claims stay, attributed to a deleted account under a replacement handle, so that discussions, counts and the register remain intact; a bounty keeps the name it was pledged under.

Your rights

From your account page you can see and download everything your account holds, including your sign-in identifiers, the email we have sent you and the abuse-prevention counts tied to your account, correct your handle and email address, and delete the account at any time. You can also ask us to restrict or stop using your data, or object to how we use it, by writing to hello@qed.bot. You keep any further rights the law where you live gives you, and can use them the same way.

Age

Accounts are for people aged 16 and over. An account we learn belongs to someone younger is deleted.

Changes

When this policy changes, the date at the top changes with it, and significant changes are announced to account holders by email before they take effect.