Open learner accounts

Ages 16–24 are recommended, not required.

The program is designed around the first years of adult independence, but learners outside that range are welcome and no age-range confirmation is collected. The service is not designed for children under 13.

Privacy & account security · Updated September 2026

Your learning record
is not the product.

This notice explains the service as it works today, including the protections in place and the account features that are not active yet.

Plain-language promise

Collect what the experience needs. Keep private data private. Never sell learner data.

Accounts exist to open the eight-week workspace and save progress, checks, projects, and optional follow-ups. Sponsorship never gives a sponsor access to a learner’s email, password record, private work, or individual activity.

01 · Data map

What the system stores.

Account

Name or preferred name, email, unique private username, and daily goal. We store a salted one-way password verifier—not the password you typed.

Learning record

Completed lessons, last-opened lesson, course progress, points, streaks, and badges so your work can continue across devices.

Program record

When you create an account, the starting and final checks, weekly projects, rubric responses, program events, and optional 30/90-day follow-ups used to run your eight-week workspace.

Partnership inquiries

A contact name, work email, organization, selected opportunity, and optional note when someone asks us to consider a partnership. Inquiries are not displayed publicly.

02 · Visibility

Learner identities are not published.

The Life Starter does not operate a public learner directory, leaderboard, or public profile. Display names, usernames, emails, points, badges, progress checks, projects, and individual activity stay off the public site. Your username remains a private sign-in identifier and must be unique.

Authorized program staff may receive a minimum-necessary learner view only when a real support role is assigned. Ordinary accounts cannot grant themselves staff access.

03 · Passwords

One-way protection, not reversible encryption.

Passwords are normalized and processed with PBKDF2-HMAC-SHA-256 using a unique 128-bit random salt and a 100,000-iteration work factor supported by the current runtime. Only the verifier, salt, algorithm, and work factor are stored. Sign-in sessions use random tokens; the database stores only a SHA-256 hash of each token.

Production cookies are HTTP-only, same-site, secure over HTTPS, and expire after 30 days. Repeated failed sign-ins are temporarily throttled. Independent security review remains part of the ongoing production-hardening plan.

Current account limitation

Email verification and password recovery are not active yet.

The database can record email-verification status, but no verification or recovery message is sent today. Use an email address you control, choose a unique password, and save it in a trusted password manager. Verified email and secure recovery are planned account improvements.

04 · Purpose limits

How information may be used.

  1. 1
    Deliver the experience

    Authenticate accounts, save progress, operate the program workspace, support learners, and prevent abuse.

  2. 2
    Improve the product

    Understand whether features work, find errors, improve lesson clarity, and keep different progress signals accurately labeled.

  3. 3
    Report responsibly

    Share aggregate or de-identified activity where appropriate. Individual records are not sponsor inventory and results are not manufactured.

05 · Implementation references

Security decisions have a source.

The current build applies practical safeguards supported by its host. It has not received an independent security certification, and the account design should be reviewed again before high-risk or large-scale use.

NIST SP 800-63BPassword length, weak-password blocking, and rate limiting

The account policy accepts 8–128 characters and blocks common or identity-based choices. An independent review should reassess the minimum against the final risk profile.

OWASPPassword storage guidance

Informs the use of salted one-way verification and the plan to keep reviewing the work factor as the host runtime changes.

Cloudflare D1Hosted database protection

The database provider documents automatic AES-256 encryption at rest and TLS protection in transit.

Apple DeveloperPassword AutoFill rules

The registration inputs expose password-manager and strong-password-generation semantics supported by Apple devices.

Retention and requests

Your account stays available until you ask for a change.

Account and learning records remain available while the account is active so progress can be restored. Operational records may be retained as needed for security, reliability, and lawful obligations. To request access, correction, or deletion, use the contact form and choose the privacy-request topic. Identity must be verified before private records are disclosed, changed, or deleted.

Open the privacy-request form
Free learner account

Start the program and keep your progress together.

Start the free program Sign in to your accountRead the Terms of Use