Privacy
What Enablement Studio collects, what it does not sell, and how to ask us to delete it.
What we collect
- Email and password — only if you create an account. We store a slow hash of the password. We use the email to send a confirm link and, if you ask, a reset link.
- Visitor kit cookie
es_sid— an HttpOnly cookie so this browser can keep its own kits for about an hour. The client never mints it. - Optional account cookie
es_aid— set after you confirm the address, so this browser stays signed in for 30 days. - Practice answers — only when someone shares a kit’s quiz as a practice link. For each learner we keep which option they chose on their first try, tied to a random cookie
es_lrn: no name, no email, no account. A practice link and its answers are deleted 90 days after it was shared.
What we do not do
We do not sell your email, pastes, or kits. We do not run ads against them. We do not put a learner portal, learning-platform login, or completion tracker on this host. A practice link is one anonymous page: no sign-in, and it never records who answered.
Cookies
es_sid, es_aid, and the practice cookie es_lrn are first-party, HttpOnly, SameSite=Lax, and Secure on the public host. Theme preference lives in localStorage on this device only. We do not use third-party tracking cookies.
Page analytics
We use PostHog for anonymous, cookieless page analytics. PostHog runs in the US cloud. There is no cookie and no local storage for analytics. We do not record sessions. Page text and form values are masked and never sent. We honor Do Not Track. We do not identify you, and we do not build a profile. Practice links and their results pages load no analytics at all.
When a generate runs
After you confirm the address, your own paste can run through generate(). If you run a paste that is not labeled EXAMPLE DATA, the draft is sent to OpenAI so generate() can write the kit. EXAMPLE DATA, Keep / Drop, kit chrome, and exports of what is already in the session never spend that path. Doors work without an account.
Files and links
Files you add are read on our server. We keep the text they contain with the kit, not the files themselves. A link is fetched from our server; for job boards and Google files we read the posting or the export behind the page. A scanned PDF or a picture of text has no text to read, so after you confirm the address it is sent to OpenAI to be transcribed, and the kit marks that source as read from the page images.
Deletion
Write Contact or login@enablementstudio.app and ask us to delete the account on that email. Visitor kits die with the es_sid cookie. Practice links and their answers are deleted 90 days after they were shared; write to us to delete one sooner.