Policies and standards

Privacy Policy

How Theory Commons handles information when people browse the site, submit requests, and—when enabled—use community features.

Effective
August 29, 2026
Last updated
August 29, 2026

Scope and current status

This policy applies to theorycommons.org and services operated under the Theory Commons name. The publicly identified operator is currently Theory Commons; the legal operator name and business entity are awaiting review before publication.

The public educational catalog, Requests form, and privacy-conscious first-party site analytics are operating features. The repository also contains community accounts and posting infrastructure, but those provisions apply only when the Commons is activated in production. Paid courses, subscriptions, advertising, and payment processing are planned possibilities and are not currently operating.

Information collected

Information you provide

The Requests form collects a request type, subject, optional description, and optional related Theory Commons URL. It does not ask for a name or email address. Requests are assigned an identifier and submission time.

Site use and engagement

Theory Commons uses a first-party browser script and Cloudflare Workers Analytics Engine to collect the requested page path and page category; academic field, subject, and topic when they can be determined from the page address; coarse primary browser language; broad device category; referring website hostname; country and state or region supplied by Cloudflare; estimated time actively engaged while the page is visible and focused; maximum page-scroll percentage; and limited interaction events. Interaction events include opening a page, using previous or next curriculum links, beginning a lab, selecting a lab challenge, using a request link, successfully submitting a request, and submitting a site search. For searches, Theory Commons records only the length of the search text—not the text itself.

The analytics dataset does not store an IP address, exact location, city, postal code, latitude or longitude, name, email address, account identifier, advertising identifier, persistent visitor identifier, lab answer, form contents, keystrokes, or session recording. The system does not attempt to follow people across websites or build individual visitor profiles. Cloudflare necessarily processes connection information, including IP addresses, while delivering and protecting the site, but Theory Commons does not write IP addresses into its custom analytics dataset.

Accounts and community, when activated

Registration will collect an email address, password credential handled by the authentication system, display name, confirmation that the member is at least 13, and account/security records. Contributions may include posts, replies, reactions, reports, moderation records, profile biography, and related taxonomy. Email addresses are not public.

Other technical information

Cloudflare may process browser and device information, timestamps, requested URLs, security signals, and diagnostic data to deliver, protect, and diagnose the service. Theory Commons does not currently use a separate third-party error-monitoring provider.

Cookies and similar technology

The custom analytics system does not use cookies, local storage, advertising identifiers, or fingerprinting. It honors a browser’s enabled Do Not Track signal. If accounts are activated, Better Auth uses necessary session cookies to keep members signed in and protect account access. Cloudflare may use necessary security mechanisms. Theory Commons does not currently use Google Analytics, personalized-advertising cookies, or Google AdSense.

If advertising or another analytics provider is introduced, this policy and any required consent controls will be updated before that processing begins.

How information is used

  • Deliver, secure, diagnose, and improve the site.
  • Understand which pages, fields, subjects, topics, labs, and curriculum routes are useful.
  • Estimate engaged reading and completion patterns, improve site navigation, and identify demand without tracking named individuals.
  • Measure searches and request conversions without retaining search text or request contents in analytics.
  • Review submitted requests and decide what to publish or improve.
  • When activated, create accounts, authenticate members, display contributions, send in-site notifications, prevent abuse, and moderate the Commons.
  • Comply with lawful obligations and protect users, Theory Commons, and the public.

Disclosure and service providers

Cloudflare hosts and protects the site and supplies Workers, static assets, Workers Analytics Engine, KV, D1, Turnstile, and configured email services. Request submissions are stored in Cloudflare KV and forwarded through Cloudflare Email to an administrator mailbox. Better Auth is application software used for account authentication when that feature is active; it does not by itself receive a separate copy as a hosted provider.

Information may also be disclosed when reasonably necessary to comply with law, address fraud or security, enforce policies, protect rights or safety, or complete a business reorganization with appropriate safeguards. Theory Commons does not sell personal information. No payment or advertising provider currently receives site data.

Retention and security

Cloudflare Workers Analytics Engine retains the custom aggregate analytics dataset for three months. Requests and other operational records are retained only as long as reasonably needed for editorial planning, service operation, security, dispute handling, and legal obligations; final periods for those records require operator approval. When community features are active, deleted material may remain temporarily in backups, audit records, or moderation records where needed for safety and integrity.

Theory Commons uses access controls, secure session practices, input validation, data minimization, and Cloudflare security services. No internet service can guarantee absolute security.

Your choices

The custom analytics script does not run when the browser presents an enabled Do Not Track signal. Browser privacy tools may also block the analytics request without preventing access to public educational content. You may request access to, correction of, or deletion of information associated with you through the Requests page. Because the analytics dataset has no account or persistent visitor identifier, Theory Commons generally cannot connect an analytics event to a named person. Browser controls can remove cookies; removing a necessary session cookie signs an account out.

Children and international visitors

The public site is general-audience educational content. Community accounts, when activated, are intended for people at least 13 years old. Theory Commons does not knowingly invite children under 13 to create accounts. A parent or guardian who believes a child supplied personal information should contact Theory Commons.

Visitors outside the United States should understand that information may be processed in the United States and other locations where Cloudflare operates infrastructure, subject to applicable safeguards and law.

External links and policy changes

External sites have their own privacy practices. Material policy changes will be dated here. If accounts are active and a change requires renewed acceptance, members will be asked to accept the identified policy version before the affected feature is used.

Contact

Policy questions, privacy requests, permission requests, and accessibility feedback may be submitted through the Theory Commons Requests page. A public legal or business mailing address has not yet been approved for publication.