DunceLab — Privacy Policy
Last updated: 2026-06-30
DunceLab is an educational app: an infinite feed of live, tweakable STEM simulations. This policy explains what data the app does and does not handle. Short version: you can use DunceLab with no account and no personal information at all. A few optional features — signing in, commenting, voting, reporting a problem, asking the in-app AI tutor, or supporting our work — involve a small amount of data, all described below.
What we collect
By default, nothing personal. You can browse, play every simulation, search, and keep progress on your device without an account. We do not ask guests for a name, email, grade, school, or location.
Only if you choose to create an account: community features (discussion, thumbs up/down, reports, the contact form, and the AI tutor) require an account. Before asking for a name or email, we present a neutral age screen. You enter your full birth date so we can calculate your age accurately. The date is processed transiently, converted to a coarse age band, and immediately discarded; we do not store your birth date. If the account is eligible, you choose a public display name, accept the current Terms, acknowledge the Privacy Policy, and sign in with Google or an emailed sign-in code. The account stores only:
- your email address;
- your chosen display name, any handle you set, and an avatar if you use Google sign-in;
- a coarse age band (
13–15,16–17, or18+) and when it was declared; - the versions and timestamps showing that you accepted the Terms and saw the Privacy Policy; and
- the comments, votes, reports, and contact messages you choose to submit.
Signing in is entirely optional. Guest mode does not include community posting, reports, the contact form, the AI tutor, cloud sync, or financial support, but every simulation, search, and local-device progress feature remains available.
Community content is public
Comments you post are visible to other users, and your votes affect public rankings. A "Something not right?" report is visible to our reviewers and may lead to a public, versioned change to a simulation (recorded in that node's public change history). Please don't include personal or sensitive information in anything you post.
The AI tutor ("Dunce") and AI review
When you summon the in-app AI tutor (an @dunce mention or the chat panel) or file a
"Something not right?" report, the text you submit — together with the relevant simulation's
content — is sent to our AI provider (Anthropic) to generate a response or review.
We do not use this content to train AI models, and we ask you not to enter personal or
sensitive information into the tutor or a report.
Supporting DunceLab
Supporting DunceLab is optional and is available only to signed-in users whose age band is 18+. If you choose to contribute, payments are processed by Stripe — your card details go to Stripe, not us, and DunceLab never sees or stores your full payment information. Stripe shares limited details (such as the email or name on the payment) so we can match your contribution and, if you ask, credit you; your name is shown publicly only if you opt in. Contributions are support of Swrl LLC's work — not a purchase and not a tax-deductible donation. See the Funding Policy for details.
Contacting us
If you use the account-only contact / "suggest a concept" form, we receive the message you send and link it to your account display name and email so we can read and respond to it.
Data stored on your device
To make the app useful, DunceLab saves a small amount of progress data locally on your own device (in the browser/app local storage), including:
- which concepts you've completed,
- your day streak and XP,
- your chosen feed difficulty level, and
- the search terms you entered that didn't match a built simulation (to help us decide what to build).
This progress information stays on your device. It is not transmitted to us, and we cannot see it. During account setup, your browser also holds a short-lived signed registration claim in session storage. It contains an age band, display name, and legal-document versions, but no birth date, and is removed after sign-in or when the browser session ends. If the age screen does not allow an account, the session also stores a temporary ineligible marker to prevent immediate age re-entry; it contains no date or identity and disappears when the browser session ends. Clearing the app's data, uninstalling the app, or clearing your browser storage removes local data.
Cookies and on-device storage
DunceLab uses no advertising, analytics, or tracking cookies. The on-device data above is stored only to make the app work — your theme choice and your learning progress — and is strictly necessary to provide the features you ask for. Our backend uses a session and security (CSRF) cookie only when an administrator uses the Django admin tools; ordinary sign-in (Google or an emailed code) is token-based and sets no such cookie. Because this storage is strictly necessary, we do not need a cookie-consent banner for it. If we ever add analytics or tracking, we will ask for consent first where the law requires it.
Network and third parties
The simulations run entirely on your device and bundle everything they need, so they work offline. The app itself loads no advertising, no analytics, no trackers, and no third-party SDKs that collect personal data. That "no trackers/analytics" statement is about the app code — it loads nothing that profiles you. One narrow exception: if you choose "Sign in with Google", your browser loads Google's sign-in script from Google at that moment (and only then) — Google is listed in our sub-processors. Anonymous use and email sign-in never load it.
When you use an optional online feature (signing in, commenting, voting, the AI tutor, support, or the contact form), your device connects to our backend, and our hosting provider (Railway) and our server keep standard, short-lived technical logs — including your IP address, the time of the request, and basic device/browser information — to operate the service, prevent abuse, and keep it secure. These logs are not advertising or behavioral analytics, are not sold, and are not used to build a profile of you.
The optional account, community, AI, and support features rely on a few service providers that act on our behalf:
- Railway — hosts our backend and database, transiently processes the birth date used by the age screen, and stores your account age band, legal-acceptance records, and content you submit.
- Google — processes "Continue with Google" sign-in, if you use it.
- Anthropic — powers the AI tutor and AI review described above.
- Stripe — processes payments if you choose to support DunceLab.
These providers process data under contracts that limit them to acting on our instructions. A current list of the providers we use is published in SUBPROCESSORS.md.
We do not sell your data, and we share it only with the providers above as needed to run these features, or where required by law.
International data transfers
Swrl LLC is based in the United States, and all of the service providers above process data in the United States. If you use DunceLab from outside the U.S. — for example from the EEA or the UK — the limited personal data tied to an optional account is transferred to and stored in the United States. Where the law of your country requires a transfer safeguard, we rely on the appropriate mechanism for each provider, which may include the European Commission's Standard Contractual Clauses, the UK's International Data Transfer Agreement (or Addendum), and, where a provider is certified, the EU-U.S. / UK / Swiss Data Privacy Framework. You can ask us for more detail about the safeguard that applies, or for a copy of the relevant terms, by emailing Contact@SwrlSite.com.
Our legal bases (EEA/UK users)
If you are in the EEA or UK, we process your personal data on these legal bases:
- Performing our agreement with you (Art 6(1)(b) GDPR) — to create and run your optional account and to process a contribution you choose to make.
- Our legitimate interests (Art 6(1)(f)) — in keeping DunceLab safe, preventing abuse and spam, applying an accurate age screen, displaying community content, and noting which searches found no simulation so we know what to build. You can object to legitimate-interests processing at any time.
- Your consent (Art 6(1)(a)) — where we ask for it (for example, the text you choose to send to the AI tutor), which you can withdraw at any time without affecting earlier processing.
- Compliance with our legal obligations (Art 6(1)(c)) — for example, keeping limited records of financial contributions for tax and accounting purposes.
Everything educational works with no account and no personal data at all.
Your choices and rights
Everything educational works with no account. If you have an account, you can delete it at any time from within the app: open Profile → Data & privacy → Delete account. Deletion is immediate and removes your email, display name, handle, age band, legal-acceptance records, comments, votes, and contact messages, and de-links unpublished workflow records from your identity. A report description already published in the public source history cannot be recalled, as explained below. (Records of any financial contributions are retained in de-identified form where tax or accounting law requires — see How long we keep data and Supporting DunceLab.) You can also email Contact@SwrlSite.com to ask us to access, export, correct, or delete your data, and we'll take care of it.
Depending on where you live, you have additional rights. If you are in the EEA or UK, you have the right to access, correct, delete, restrict, or port your personal data, to object to processing based on our legitimate interests, and to withdraw any consent at any time (without affecting prior processing). Email Contact@SwrlSite.com and we will respond within one month (we may extend by up to two further months for complex requests, and will tell you if we do). You also have the right to lodge a complaint with your local data-protection supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk). If you are in California or another U.S. state with privacy rights, you can exercise the rights your state grants by contacting us at the same address, and we will honor them.
How long we keep data
We keep account and community data (your email, display name/handle, age band, legal-acceptance records, comments, votes, reports, and contact messages) for as long as your account is active, and we delete it within a reasonable period after you delete your account or ask us to remove it — except where we must keep limited records to meet a legal, tax, accounting, or fraud-prevention obligation. In particular, if you make a financial contribution we retain a minimal, de-identified record of that transaction (amount, date, and Stripe transaction identifiers, without your name) for up to seven (7) years to meet tax and accounting obligations; deleting your account removes your email and name from these records to the extent the law allows. The birth date entered at the age screen is not written to our database. Signed age and registration claims expire within minutes. Sign-in codes and links also expire within minutes and are then deleted, and AI-tutor conversations are not stored by us after the request. The short-lived server logs described above are kept only briefly for security and abuse-prevention. On-device progress data stays on your device until you clear it.
Please do not include personal information in a "Something not right?" report. Reports are reviewed internally and may be retained without your account identity when needed to document a correction, prevent abuse, or maintain service integrity.
Data security and breach notification
We use reasonable administrative and technical measures to protect the limited data our optional features collect — for example, payment card details are handled by Stripe and never reach us, and sign-in uses tokens rather than stored passwords. No system is perfectly secure. If we become aware of a security breach that affects your personal information, we will investigate promptly and notify affected users — and any regulators where required — without undue delay and within the timeframes required by applicable law. Our notice will describe, to the extent known, what happened, the data involved, and the steps you can take.
Children's privacy
DunceLab's simulations are free for everyone and collect no personal information, so anyone can browse, search, and play in guest mode; progress stays on the device. Optional accounts and online features are for users age 13 and older. The neutral age screen comes before collection of a name or email and accepts a freely entered full birth date. We use it only to calculate eligibility and an age band, then discard it. If the result is under 13, we do not ask for or collect a name, email, post, prompt, or account identifier, and the learner remains in guest mode.
We store only the resulting age band for eligible accounts. Users age 13–17 may use account,
community, contact, and AI-tutor features with parent or guardian involvement where local law
requires it. Financial contributions and subscriptions require an 18+ account.
We do not knowingly collect personal information from children under 13. If you
believe a child under 13 has created an account, contact us at
Contact@SwrlSite.com and we will delete it promptly. Parents may contact us at the
same address to review or delete information associated with their child. Account holders can
re-run the age check from Profile → Update age band when they move into a new
band; the newly entered birth date is again discarded after the check.
Changes to this policy
If this policy changes, we'll update the "Last updated" date above and post the revised version at the same location.
Contact
DunceLab is operated by Swrl LLC, a Tennessee limited liability company. Questions about privacy: email Contact@SwrlSite.com, or write to 6339 Charlotte Avenue, Unit #C341, Nashville, TN 37209, USA.