Privacy
Last updated 23 September 2026
FaultGym stores as little as it can. There is no advertising, no third-party analytics and no tracking across other websites. This page describes exactly what is kept and why.
The short version
- You can use every incident without an account and without giving us an email address.
- We set one cookie, which identifies your session so your work is still there when you return.
- We record which steps you reached in an incident, so we can see where people get stuck.
- We do not sell data, do not run advertising, and load no third-party scripts.
What we store
| Data | Why | When |
|---|---|---|
| A session identifier, in a cookie | So your attempts, configuration and results are yours when you come back | First visit. Expires after 180 days |
| Your work: attempts, pipeline configurations, runs, traces, results, hints used, incident notes | To show your progress and grade your submissions | While you use an incident |
| Product events: incident started, baseline inspected, first change, run, submitted, completed, hint used | To measure where learners stop. Event names and timestamps only — never your configuration or answers | As you use the product |
| Email address and a hashed password | Only if you choose to create an account, so progress follows you across devices | On sign-up |
| Your bug report, and an email address if you typed one | To fix the problem and reply if you asked for one. The email field is optional | When you submit a report |
| Server logs: IP address, user agent, request path | Operating the service, diagnosing faults, blocking abuse | Every request. Deleted after 30 days |
What we do not do
- No advertising and no advertising identifiers.
- No Google Analytics or comparable third-party analytics. Usage figures come from our own database.
- No tracking of you across other websites, and no data sold or shared for marketing.
- No email unless you ask for one — we send no newsletters or announcements.
Cookies
One cookie, fg_session. It holds a random identifier, nothing about you. It is HTTP-only, so page scripts cannot read it, and it is sent only to faultgym.com. It exists to keep your progress attached to you; there is no advertising or measurement cookie to consent to.
Your browser also stores small preferences locally — theme, panel sizes, whether you have dismissed the first-run notice. These never leave your device.
Passwords
Passwords are hashed with scrypt and a per-account random salt. We cannot read your password and cannot recover it — only reset it.
Where the data lives
On Amazon Web Services in the Mumbai region (ap-south-1), in a database that is encrypted at rest and not reachable from the public internet. Backups are retained for seven days. We use no other processors: no analytics vendor, no customer-support platform, no marketing tool.
How long we keep it
- Your work and progress: until you delete it or ask us to.
- Server logs: 30 days.
- Backups: 7 days, after which deleted data is gone from them too.
- Bug reports: kept while the problem is open, then deleted periodically.
Deleting your data
Resetting an attempt inside the workspace erases that attempt’s runs, traces and configuration history immediately. To delete an account and everything attached to it, send a request through the Report a problem control on any page — say that you want your data deleted and include the email address on the account. We will delete it and confirm.
You may also ask for a copy of what we hold about you, or ask us to correct it, through the same route.
Children
FaultGym is aimed at working engineers and students of software engineering. It is not directed at children, and we do not knowingly collect data from anyone under 16.
Changes
If this page changes materially we will update the date at the top. The product is early and moving; where the description here and the product disagree, treat it as a bug and report it.
Who we are
FaultGym is operated by its individual founder. Contact us through the Report a problem control on any page, which reaches the person who builds and runs the service.