Security
We follow data minimization, explicit boundaries and reversible user actions.
On-device first
Destiny Slip encrypts charts, profiles and cases locally with SQLCipher.
Protected transport
The site and API use HTTPS. Sensitive configuration stays in deployment secrets, not source code.
Least privilege
The site has no sign-in and stores no Firebase credentials, chart data or formal learning progress.
Event isolation
Web practice events are isolated from formal Learning Review Events and cannot establish mastery.
Report a security issue
Do not post personal data or vulnerability details to public Feedback. Email us with reproducible steps.