myproduct.life

Project SOR

Privacy

Project SOR needs scenario facts to calculate an estimate. It does not need a student's identity.

Effective October 6, 2026. Publisher: Tirath Chhatriwala, tirath@outlook.com.

What you provide

Calculator, REST API, and MCP requests may contain award year, grade level, enrollment credits, cost of attendance, other aid, paid history, and other scenario facts. The calculation endpoints process these facts to return a result or a request for more information. They are not designed to collect names, student IDs, Social Security numbers, birth dates, or account credentials. Do not enter them.

Storage and retention

The SOR calculation code does not intentionally write calculation request bodies to an application database. API rate limiting keeps a daily-salted hash derived from the connection address in worker memory; it is not a durable student record. The Compare page can save its form and result in your browser's local storage until you clear them or your browser data. Other local settings remember dismissed notices and lifecycle selections until you clear browser data.

A separate public lab uses a hashed visitor value for usage limits in a Supabase database. Its cleanup runs when new reservations are made and removes records older than roughly two days at that point; there is no guaranteed deletion time if the lab receives no later requests.

The hosting and security providers may process connection metadata, including IP address, request time, URL, and browser details. The active production logging settings and their retention period are being verified. This page will be updated with that period before a public plugin submission. Do not use Project SOR for identifiable student records in the meantime.

Cookies and service providers

The staff-site access gate uses an encrypted, HTTP-only session cookie. Cloudflare may set a security cookie such as __cf_bm to protect the site; Cloudflare states that this cookie expires after 30 minutes of inactivity. Cloudflare hosts and protects the site, Lovable manages publishing, and Supabase supports the separate lab quota. If you use the MCP server through ChatGPT or another AI client, that client also processes the scenario under its own privacy terms.

Your choices

Use fictional or de-identified scenario facts. You can clear this site's local storage and cookies in your browser. For a privacy question or a request about information you sent to support, emailtirath@outlook.com. I can address information in systems I control, but cannot erase records held independently by an AI client or infrastructure provider. See Support for contact details.