Privacy

Effective September 4, 2026

The short version

Your case history, preferences, saved paintings, and taste profile remain in your browser. Cabinet runs no advertising and builds no identity profile. It measures page use without cookies and adds each submitted painting point to an anonymous aggregate grid. Three running totals are kept that way: where points land on a painting, how many were submitted on a calendar day, and how often one painting is stepped through to another. Each is a counter with no visitor in it.

What Cabinet stores

On your device: closed cases, chosen points, discoveries, saved paintings, streaks, and settings. On Firebase: anonymous crowd totals for each painting, a per-day count of how many points were submitted for each painting, and a count of how many visitors moved from one painting to another. The current release does not offer accounts, AI readings, credits, or payments. The dormant account system can also hold a random account identifier and a credit ledger if those features are introduced later.

Anonymous painting points

When you submit a point to find visual echoes, Cabinet converts its normalized position into a coarse grid cell for that painting. Firebase stores the painting ID, grid dimensions, total sample count, and count for each occupied cell. It does not store the raw coordinate, account ID, session ID, network address, timestamp, device information, or route you followed.

Each painting has a grid shaped to its own aspect ratio, so cells remain approximately square. These totals may be used to show where visitors collectively looked and to improve Cabinet. They cannot be connected to a particular visitor or browsing history.

Two further counters work the same way. A per-day total records how many points were submitted for each painting on a calendar date, which is what lets Cabinet say how many people stood in front of a painting today. A step counter records that some visitor moved from one painting to another, which is what lets it say which doors are most walked. Neither stores who moved, when within the day, or in what order, so a sequence of steps cannot be reassembled into the route any one person took.

These totals are collected whether or not you choose to see them. The Workshop's “Show the crowd” setting controls what Cabinet displays to you, not what it counts, because a crowd measured only from the people who wanted to see one would describe nobody accurately. What is counted contains no visitor, so there is nothing in it to opt a person out of. Nothing is shown for a painting until enough points have been gathered that a map describes a crowd rather than a handful of individuals.

If abuse protection is enabled, Firebase App Check uses reCAPTCHA Enterprise to issue a short app-attestation token. Cabinet verifies that token but does not store it with the crowd count or use it to identify a visitor.

Measurement

Cabinet uses Vercel Web Analytics to count page views, so it knows which rooms people actually use. It sets no cookies, stores no device identifier, and does not follow you to other sites. Vercel derives an anonymous hash from the incoming request for the current day only, which cannot be reversed or used to recognise you tomorrow. The measurement is entirely separate from Firebase: it never receives your account identifier, your credit balance, your email address, or anything you marked, judged, or closed.

It records the page address, referrer, country, and general device type. Case pages are counted by their opaque reference, which does not name the painting.

Starter-credit protection

Starter credits are not offered in the current release. If they are introduced later, the server is designed to convert the connecting network address into a keyed, irreversible HMAC and store only that value with a rolling claim count. Cabinet would not store the raw address.

When you ask the oracle

The AI oracle is not offered in the current release. If it is introduced later, it will remain optional and explicit. Its existing design sends two reduced copies of the painting and up to three normalized mark coordinates to Cabinet's server and then to Google Gemini only after a visitor chooses to spend a credit. Images and generated readings are not stored in Firestore.

Payments

Payments are not offered in the current release. If paid oracle credits are introduced later, Stripe will process checkout and card information under its own privacy terms. Cabinet will receive payment status and Stripe transaction identifiers, never full card details.

Control and deletion

Clear this site's browser storage to erase the local play record. Because page measurement and painting point counts are aggregate and anonymous, there is no analytics record tied to you to delete. To ask a privacy question or request deletion of a future linked account, email vdocdev@googlegroups.com. Payment and security records may be retained where required for fraud prevention, tax, or legal duties.