How we protect your exercises, participant responses, and account data — from infrastructure to application layer.
Secure in production and expire after 7 days. Sessions are stored server-side in the database — there is no sensitive data in the cookie itself.owner_id tied to your account. Every database query for protected resources includes a mandatory owner filter — it is architecturally impossible for one account to read another account's data.