FLS Harness is a private operator console for the Fidelity Ladder System, run by
Metatoy LLC (Minnesota, USA) at harness.n8plusus.com. It is not a
consumer product and not open to the public. Access is limited to a small allow-list of named
operators.
This policy describes what the service collects about the people who sign in to it, why, and
what happens to it.
What we collect
Sign-in information. Signing in is handled by
Clerk, our identity provider. You may sign in with a Google
account, a GitHub account, or an email address. Clerk passes us a small, fixed set of claims about
you:
- a stable account identifier (
subject);
- your username or login, where the provider issues one;
- your display name;
- your email address;
- the URL of your profile picture, where the provider issues one;
- which provider you used.
We request only the standard openid, profile and email
scopes. We never receive your password, and we never receive an access token that would let us read
your Google or GitHub account, your files, your repositories, your mail, or your contacts.
A session cookie. After you sign in we set one cookie holding the claims above,
signed with a secret key so it cannot be altered. It is HttpOnly,
SameSite=Lax and Secure, and it expires after 12 hours. It is the only
cookie this service sets. There is no analytics, advertising, or tracking cookie of any kind.
An operational record. Actions you take in the console — approving, rejecting,
or stopping work — are written into the system's own record, attributed to your login or display
name. That attribution is the point of the service: it is a system whose purpose is recording who
decided what.
Web server logs. Our web server records the time, IP address, browser
user-agent, and requested path of each request, to operate and secure the service. Authentication
codes and state parameters are redacted before they are written. These logs rotate automatically
and are typically retained for about a month.
What we do with it
Only three things: to authenticate you, to check you against the operator allow-list, and to
attribute your decisions in the system's record.
We do not sell or rent your information. We do not share it with advertisers.
We do not use it to build a profile of you, to train machine-learning models, or for any
advertising purpose. We do not send you marketing.
Google user data
If you sign in with Google, our use of information received from Google APIs adheres to the
Google API Services
User Data Policy, including its Limited Use requirements. Concretely: the name, email address
and profile picture we receive from Google are used only to sign you in and attribute your actions
in this console. They are not transferred to anyone else except as described below, not used for
advertising, and not read by a human except where necessary to operate or secure the service, or
where you have asked us to.
Who else touches it
Three service providers process this data on our behalf, and no one else:
- Clerk — authentication. Clerk stores your account record and applies its own
privacy policy.
- Google or GitHub — only the one you chose to sign in with, and only to
perform that sign-in.
- Our hosting provider — the server the service runs on.
We may also disclose information where we are legally required to.
How long we keep it
Your session cookie expires after 12 hours, or immediately when you sign out. Your Clerk account
record persists until it is deleted. Entries in the operational record are permanent by design —
they are the audit trail the system exists to keep — and identify you by login or display name.
Server logs age out on the schedule above.
Security
All traffic is served over HTTPS. Sessions are signed and scoped to a short lifetime. Access is
denied by default: every route requires an authenticated, allow-listed operator unless it has been
explicitly published, as these policy pages have been. Secrets are held in the server's environment
and are never rendered into any page or status response.
Your choices
You can sign out at any time, which invalidates your session immediately. To see what we hold
about you, to correct it, to have your account and its personal data deleted, or to have your
access withdrawn, email deals@metatoy.com. We will respond
within 30 days. Because the operator record is an audit trail, we may retain the attribution of
past decisions after deleting your account.
Children
This is an internal engineering tool. It is not directed to children and we do not knowingly
collect information from anyone under 16.
Changes
If this policy changes materially we will update the date at the top of this page and notify
current operators by email.
Contact
Metatoy LLC, Minnesota, USA ·
deals@metatoy.com