Privacy policy

Last updated 2 October 2026

Overload (overload.design) is operated by Joel, India. This page says what we store about you, why, who else sees it, and how to have it removed. It is written to meet India's Digital Personal Data Protection Act 2023 and the EU's GDPR; where they ask for the same thing in different words, we do the stricter one.

What we store

  • Account: your email address, a hash of your password (never the password), a public handle, and when the account was created.
  • Play: every run you record: the build, its result and score, and how the build changed during the run. Saved builds. Which lessons you have finished and which walkthroughs you have seen.
  • How the product is used (our own database): which pages and levels you open, when you start and finish runs, which report tabs you read, when a wire is refused, when you share. Tied to your account when you are signed in and to a random id in your browser when you are not. No advertising identifiers, no cross-site tracking.
  • Analytics from other companies, only if you say yes: the first time you visit you are asked whether we may use Microsoft Clarity (session recordings and heatmaps) and Google Analytics (page and event counts). If you decline, or do nothing, neither is loaded. Neither is ever loaded on the sign-in, sign-up, forgot-password or reset pages.
  • Feedback: what you write in the feedback box and which page you were on.
  • Technical: server logs with your IP address and request path (not the query string, and not the content of requests), kept for 30 days for security and rate limiting.

Why

To run the game (a score has to belong to someone), to rank the leaderboard, to show a run you chose to share, to make the lessons better by seeing where people stop, to answer feedback, and to keep the service up. We do not sell data, and we do not show advertising.

What is public

Your handle, your best score per level on the leaderboard, and any run whose link you share (the numbers and the shape of the build: which components and wires, not your endpoints, tables or layout). A shared run is reachable by anyone who has its link; the link is not a secret and not a password, so share it only if you are happy for it to be seen. Your email address is never shown.

Who else sees data

  • Resend (Email delivery) receives: Your email address and the text of the message (confirmation and password-reset links). When we email you.
  • Groq (Language model (matches endpoint descriptions to a level; writes the optional review paragraph)) receives: The paths and descriptions of the endpoints you type, and anonymised run numbers. Never your email, handle or account id. When you run a build.
  • Google (sign-in) (Sign in with Google) receives: Your Google account address and profile name, from Google to us. Only if you choose Sign in with Google.
  • Microsoft Clarity (Session recordings and heatmaps) receives: Pages you open and how you interact with them. Only if you allow analytics, and never on sign-in or password pages.
  • Google Analytics (Page and event counts) receives: Pages you open and events, with a shortened IP address. Only if you allow analytics, and never on sign-in or password pages.
  • Our hosting provider (Runs the database and serves the site) receives: Everything stored about your account. Always.

How long we keep it

  • How the product is used: pages opened, runs started and finished, report tabs read: 13 months.
  • Which lesson steps you reached and finished: 13 months.
  • What you write in the feedback box and the page you were on: 24 months.
  • A hash of the address and your IP address for each email we send, to limit mail volume: 2 days.
  • Password-reset links (hashed): 1 day after it expires.
  • Email-confirmation links (hashed): 7 days after it expires.
  • Your sign-in sessions: 60 days idle.
  • Administrator sign-in sessions: 7 days.
  • Your account (email, password hash, handle): until you delete your account.
  • Your runs, saved builds, finished levels and leaderboard rows: until you delete your account.
  • Your consent choices: until you delete your account.

Cookies and browser storage

One cookie of ours, sd_session, keeps you signed in. It is essential and is not used for anything else. Browser storage holds your guest progress before you sign up, interface preferences, your analytics choice, and the random id used to count visits. If you allow analytics, Microsoft Clarity and Google Analytics set their own cookies; if you do not, there are no third-party cookies.

Your rights

You can see and correct your handle and password on the account page. You can delete your account there; that removes the account, every run, saved build and lesson record, and deletes the feedback you sent and the usage records tied to your browser, including ones from before you signed up. You can download everything we hold about your account from the Account page. For anything else, write to privacy@overload.design. We answer within 30 days. If you are in the EU you may also complain to your data protection authority.

Children

Overload is for people aged 16 and over. If you believe a younger person has an account, tell us and we will remove it.

Changes

If this policy changes in a way that matters, the date above moves and signed-in players see a notice on their next visit.