Anonymous session and local drafts
The server stores an irreversible hash of a random session cookie, the pinned scenario version, necessary attempt and order state, and bounded coarse events. It does not write a full IP address to D1.
Detailed plans, review notes and preferences remain in localStorage on the current device until the user clears them. Free text is not uploaded automatically. Bars, unrevealed paths and authoritative order or fill state are not stored in localStorage.
Retention and security boundary
First-party raw anonymous activity becomes deletion-eligible after 30 elapsed days. Sydney-date anonymous session summaries, anonymous daily-browser observations and visitor-coverage diagnostics become eligible 120 days after that date ends. Daily aggregates, payload-free collection-health aggregates and their import state become eligible after 25 Sydney calendar months. Eligible records are removed by the next successful daily maintenance. activity_control and activity_visitor_control store only current operating state, not visitor history.
Cloudflare security logs and D1 Time Travel or backup data are separate platform-managed retention boundaries and follow the settings verified for the deployed service.
Cloudflare may process IP and device information and necessary logs for delivery, security, abuse prevention, reliability and troubleshooting.
First-party anonymous activity
For reliability, curriculum improvement and aggregate usage reporting, LDTH records page and navigation activity; curriculum and episode selection; play request, confirmed playing, progress, completion, pause, seek, buffering, media error and direct-link fallback; and Trader Lab enter, scenario, attempt and bounded API-error stages.
Each tab uses a random activity session ID held only in sessionStorage. The server stores only an irreversible key derived for the surface, Sydney date and collection phase. LDTH does not set an analytics cookie, fingerprint a device or bridge identity between the public site and Trader Lab.
Records may include fixed page or control IDs, locale, allowlisted acquisition values, coarse device and viewport categories, browser family, country code, curriculum IDs, media timing buckets and bounded error classes. They do not include a name, email address, phone number, full IP address, full User-Agent, free text, trading answers, operational attempt IDs or the submitted activity session ID. Global Privacy Control or Do Not Track prevents this activity tracker from initialising or sending data.
Optional daily visitor and return measurement
Only after you explicitly choose “Allow anonymous analytics” does LDTH store a random anonymous browser identifier in first-party localStorage. It is used to count daily browsers, new browsers and 7/30-day returning browsers. The public site and Trader Lab use separate identifiers that cannot be joined. The server stores only a surface-scoped irreversible derived key and the country code seen on the first accepted observation.
This metric represents consenting browsers whose identifier remains available. It is not a person, account or cross-device user count. The browser identifier expires after 180 elapsed days. Clearing storage, private browsing or changing device can make the browser appear new.
Continuing without analytics does not limit any website, course or Trader Lab feature. You can withdraw at any time through “Anonymous analytics settings” in the footer. Withdrawal immediately stops future visitor measurement and clears the local identifier. Server records already derived before withdrawal cannot be located from the cleared identifier and remain until the disclosed 120-day raw or 25-month aggregate retention limit. Global Privacy Control or Do Not Track blocks visitor measurement before visitor storage is read. If storage is blocked or analytics fails, the product continues to work.
Reporting and exclusions
Internal first-party reports use 7, 30, 90, 120 and 365-day windows, year-to-date and the comparable prior-year period. LDTH does not use third-party analytics, advertising pixels, remarketing, cross-site behavioural profiling, heatmaps or session replay.
Turnstile
When a human-verification challenge is required, Cloudflare Turnstile is used. The verification response is checked only by server-side Siteverify and is not written in plaintext to logs, D1 or an idempotency response.
External platforms
WeChat, X and Instagram apply their own privacy, cookie and data-processing terms after a user leaves landuth.com. LDTH does not embed their feeds, pixels, SDKs or login components.
Privacy contact
Privacy questions can be sent to support@landuth.com.
