Privacy Policy
Last updated: 25 September 2026
PhysicsHub is a free, open-source physics learning site used by students, many of them under 18. We collect as little as we can, never sell anything, and show no ads. This page explains exactly what happens to your data, in plain language.
1. Who is responsible
PhysicsHub is an open-source project run by its maintainer (the data controller). For anything about privacy or your data, write to mattqdevv@gmail.com. We aim to answer within 30 days.
2. Using the site without an account
Every simulation and article works without an account. If you never sign in, we do not know who you are. What still happens:
- Settings stored in your browser. Your theme, language, school curriculum and saved simulation parameters are kept in your browser's local storage. They never leave your device unless you sign in and press Save (see below). Your curriculum is guessed from your browser's time zone and language, on your device — no location lookup is made.
- Usage statistics. We use Google Analytics and Microsoft Clarity to understand which pages are used and where the site is confusing or broken. They record pages visited, clicks, scrolling, device and browser type and an approximate location derived from your IP address, and use cookies to recognise a returning browser. Clarity can replay how a page was used; fields with personal data (your email, nickname and account page) are masked so they are never recorded.
- Feedback. If you use "Leave feedback", your rating, your comment, the page you were on and your device type are posted to the maintainers' Discord server. Don't put personal information in the comment.
- Translation. Languages without a finished translation use the Google Translate widget, which sends the page text to Google and sets a
googtranscookie with the chosen language. - Hosting. Like any website, the servers that deliver the pages (GitHub Pages, and Vercel for some features) receive your IP address and browser details to do so, and may keep them in short-lived security logs. Your browser also asks GitHub for the project's star and contributor counts.
3. If you create an account
An account is optional. It only adds publishing community presets, liking presets and syncing your saved parameters across devices. We store:
- Your email address, or the GitHub account you sign in with — only to sign you in. There are no passwords. It is never shown to other users, sold, or used for marketing or newsletters. With GitHub sign-in we receive your public GitHub profile (username, name, avatar, email) from GitHub; we use only the username, as your default nickname.
- A public nickname, which you can change on your account page. Please don't use your full real name.
- What you publish: preset titles, descriptions and simulation parameters. These are public, with your nickname.
- Private activity: your likes, the presets you report and your saved simulation parameters. Only you can see them.
- Technical data the sign-in service keeps to protect accounts: sign-in times and the IP address of recent sign-ins, and anonymous counters that stop anyone from sending too many requests.
Your session is kept in your browser's local storage (not an advertising cookie) until you sign out.
4. Why we process it (legal basis)
- Running the account you asked for (sign-in, publishing, likes, syncing): performance of the service you requested — GDPR Art. 6(1)(b).
- Keeping the site safe (rate limits, reports, hiding abusive content, security logs): our legitimate interest in protecting users — Art. 6(1)(f).
- Usage statistics (Google Analytics, Microsoft Clarity): your consent where the law requires it — Art. 6(1)(a). You can refuse or withdraw it at any time without losing access to anything.
5. Children
PhysicsHub is built for school use and needs no account at all. If you are under 16 (or under the age of digital consent in your country, which is between 13 and 16 in the EU and 13 in the United States), please ask a parent, guardian or teacher before creating an account — where the law requires it, they must give consent for you. We don't knowingly create accounts for children under 13. If you are a parent and believe your child has an account without your consent, write to mattqdevv@gmail.com and we will delete it.
6. Who else processes data
We use these providers to run the site. Each processes data only for the purpose listed, under its own data protection terms:
| Provider | Used for | Data |
|---|---|---|
| Supabase | Accounts and the community database | Account and community data (section 3) |
| GitHub (Microsoft) | Hosting (GitHub Pages), GitHub sign-in, star counts | IP address, browser details; your GitHub profile if you sign in with it |
| Vercel | Hosting for the blog editor | IP address, browser details |
| Google Analytics, Google Translate widget | Usage data, page text, cookies | |
| Microsoft | Microsoft Clarity | Usage data, masked session recordings, cookies |
| Discord | Receiving feedback | Your rating, comment, page and device type |
| Email delivery service | Sending sign-in links | Your email address |
Some of these providers are based in the United States, so data may be transferred outside the European Union. Where that happens it is covered by the EU–US Data Privacy Framework or by the European Commission's Standard Contractual Clauses.
7. How long we keep it
- Account data and everything you published: until you delete it or delete your account. Deleting your account removes your profile, presets, likes, reports and saved parameters immediately.
- Presets hidden after reports: until a maintainer reviews them, then restored or deleted.
- Sign-in and security logs at our providers: for the short period they keep them (typically days to a few weeks).
- Usage statistics: Google Analytics keeps them for up to 14 months, Microsoft Clarity for up to 13 months (recordings for up to 30 days).
- Feedback messages: until the maintainers delete them.
8. Your rights
You can, at any time and free of charge: see the data we hold about you, correct it, download it, object to its use, restrict it, and delete it. Most of this is self-service on your account page: Download my data gives you everything in one file, and Delete my account erases it. For anything else, write to mattqdevv@gmail.com. If you think we have not handled your data properly, you can also complain to your national data protection authority (in Italy, the Garante per la protezione dei dati personali).
9. Security
Connections are encrypted (HTTPS). There are no passwords to leak. Access rules are enforced in the database itself, so one user can never read another user's private data, and every kind of write is rate-limited. The code is open source, so anyone can check how it works.
10. Changes
When this policy changes, we update the date at the top. Significant changes are also announced in the project's release notes on GitHub.