Device-local drafts

IndexedDB stores guest project snapshots, command recovery data, preferences, and pending claim state. Clearing site data can remove these drafts.

Authentication

Configured Supabase authentication uses same-origin cookie-based SSR state. Production cookies must follow current provider guidance and secure transport requirements.

Analytics

Only privacy-minimized product events without project geometry are permitted. Consent and applicable privacy signals must be respected.

Gallery abuse prevention

When a signed-out visitor submits a gallery report, the server can use a secret-keyed, one-way network and browser fingerprint to prevent duplicate abuse. It is an essential safety control, not an advertising identifier, and it is not written to browser storage by that flow.

Advertising

AdSense stays disabled until account/site approval, policy review, and a region-aware consent path are complete. The editor remains functional when optional scripts are absent or blocked.