Account
Name or preferred name, email, unique private username, and daily goal. We store a salted one-way password verifier—not the password you typed.
The program is designed around the first years of adult independence, but learners outside that range are welcome and no age-range confirmation is collected. The service is not designed for children under 13.
This notice explains the service as it works today, including the protections in place and the account features that are not active yet.
Accounts exist to open the eight-week workspace and save progress, checks, projects, and optional follow-ups. Sponsorship never gives a sponsor access to a learner’s email, password record, private work, or individual activity.
Name or preferred name, email, unique private username, and daily goal. We store a salted one-way password verifier—not the password you typed.
Completed lessons, last-opened lesson, course progress, points, streaks, and badges so your work can continue across devices.
When you create an account, the starting and final checks, weekly projects, rubric responses, program events, and optional 30/90-day follow-ups used to run your eight-week workspace.
A contact name, work email, organization, selected opportunity, and optional note when someone asks us to consider a partnership. Inquiries are not displayed publicly.
The Life Starter does not operate a public learner directory, leaderboard, or public profile. Display names, usernames, emails, points, badges, progress checks, projects, and individual activity stay off the public site. Your username remains a private sign-in identifier and must be unique.
Authorized program staff may receive a minimum-necessary learner view only when a real support role is assigned. Ordinary accounts cannot grant themselves staff access.
Passwords are normalized and processed with PBKDF2-HMAC-SHA-256 using a unique 128-bit random salt and a 100,000-iteration work factor supported by the current runtime. Only the verifier, salt, algorithm, and work factor are stored. Sign-in sessions use random tokens; the database stores only a SHA-256 hash of each token.
Production cookies are HTTP-only, same-site, secure over HTTPS, and expire after 30 days. Repeated failed sign-ins are temporarily throttled. Independent security review remains part of the ongoing production-hardening plan.
The database can record email-verification status, but no verification or recovery message is sent today. Use an email address you control, choose a unique password, and save it in a trusted password manager. Verified email and secure recovery are planned account improvements.
Authenticate accounts, save progress, operate the program workspace, support learners, and prevent abuse.
Understand whether features work, find errors, improve lesson clarity, and keep different progress signals accurately labeled.
Share aggregate or de-identified activity where appropriate. Individual records are not sponsor inventory and results are not manufactured.
The current build applies practical safeguards supported by its host. It has not received an independent security certification, and the account design should be reviewed again before high-risk or large-scale use.
The account policy accepts 8–128 characters and blocks common or identity-based choices. An independent review should reassess the minimum against the final risk profile.
OWASPPassword storage guidanceInforms the use of salted one-way verification and the plan to keep reviewing the work factor as the host runtime changes.
Cloudflare D1Hosted database protectionThe database provider documents automatic AES-256 encryption at rest and TLS protection in transit.
Apple DeveloperPassword AutoFill rulesThe registration inputs expose password-manager and strong-password-generation semantics supported by Apple devices.
Account and learning records remain available while the account is active so progress can be restored. Operational records may be retained as needed for security, reliability, and lawful obligations. To request access, correction, or deletion, use the contact form and choose the privacy-request topic. Identity must be verified before private records are disclosed, changed, or deleted.
Open the privacy-request form