Crucible

Privacy

The short version

Where your library lives

On your own disk, in a database file, and that copy is the one Crucible reads and writes. The app works with the network cable pulled out — everything below is about a mirror, not about where the work happens.

With syncing on, which is the default, a copy of these is stored against your account so another machine you sign in from can pick them up:

Nobody else can read any of it — not other members, not people who follow you. It is your row in a table, and the database refuses the request if anyone else asks for it. Turn syncing off in Settings and none of it is sent at all.

Some things are never sent, whatever your settings say, because they are facts about a machine rather than about your library:

What the server does hold

Your account — always

Crucible asks you to sign in before it opens, so that your library belongs to you rather than to one particular laptop. That account consists of your email address, a display name, a one-way hash of your password (we never hold the password itself), and the dates you created it and last signed in.

If you sign in with Google, Microsoft or Apple instead, that provider tells us your email address and name and nothing else. We do not receive your password, your contacts, or anything else in that account.

Being findable, and refusing to be

A profile is public by default: anyone signed in can find you under People and open your page. You can turn that off in Settings → Your public profile. Unlisted means you are out of the square, not out of the building — you drop out of search, out of suggestions and out of the Everyone feed, and someone who does not follow you cannot open your page. The people who already follow you keep seeing what you post, because you let them. And you are still listed in a space you share: a roster is the members of a room you were both admitted to, and hiding a classmate from a classmate is a broken class list rather than privacy. Either way none of it is visible without an account, and none of it reaches the open internet.

The public feed — only if you post

If you choose a handle and post, then your handle, your description of yourself, your posts and replies, and who you follow are held on the server. That is the point of them. Who you have blocked is held too, and is visible only to you — a block that the blocked person can see is an announcement, and we do not make it one.

None of the feed is readable without an account. It is not on the open internet.

Groups — only if you join one

If you join a classroom, parish or study circle, the server holds your membership, anything you submit to it, any marks given, shared annotations and co-written documents, and files given to the group. This is shared with the other people in that group, which is what joining one means.

Syncing between your own devices

Because Crucible asks you to sign in before it opens, and because your library belongs to that account rather than to one computer, syncing is on by default: a copy of your library rows is stored against your account so another machine you sign in from can pick them up. It is your data, nobody else can read it, and it has nothing to do with any space you belong to.

You can turn it off in Settings, and turning it off sticks — reinstalling will not switch it back on. With it off, your library stays on that machine alone and the server holds nothing of it.

If you apply to be recognised as a teacher or priest

The note you write explaining the claim is held so that it can be assessed, along with the decision. It is readable by you and by whoever administers the server, and by nobody else.

Cookies

There are no advertising or analytics cookies, so there is no consent banner to dismiss. The app stores one thing in your browser: the token that keeps you signed in. It is read by Crucible and sent to no one.

Who else touches it

Two companies, both because the software runs on their infrastructure:

If Crucible ever begins sending email — for confirming an address or resetting a password — the provider that sends it will be named here before it does.

Taking it back

Deleting your account: Account → Close this account, inside the app. It removes your profile, your posts and replies, who you follow, your blocks, your group memberships, your submissions and their marks, your shared annotations and documents, and the synced copy of your library. There is no waiting period and no undo.

Two things survive on purpose. Work you gave to other people — a group someone else is still in, the assignments set in it, files you handed it — stays with them, with your name taken off. And your library on your own computer is untouched, because it was never ours to delete; export anything you want to keep before you close the account, since you will need an account to open Crucible again.

You may also ask for a copy of what is held, or for something to be corrected, by writing to the address below.

Children

Crucible is built partly for schools, so children will use it. If you are setting it up for pupils, the school or the parent is responsible for the permission to do so, and a child's account should be created with the school's involvement rather than by the child alone. If you believe a child has created an account without that, write to the address below and it will be removed.

Keeping it safe

Every table on the server is protected by row-level security, so the rules about who may read what are enforced by the database itself rather than by the app asking nicely. Passwords are stored as bcrypt hashes. All traffic is over TLS. No system is perfect, and if something goes wrong that affects you, you will be told rather than left to find out.

Changes

If this policy changes in a way that affects what is collected or who sees it, the date at the top changes and the previous version stays available. Quiet edits to widen what is collected are exactly the thing this document exists to prevent.

Getting in touch

Crucible is made and operated by William Reckley. Write to crucible@reckley.org about anything on this page — a copy of your data, a correction, a deletion, or a question about how any of it works.