Privacy Overview
A clear description of the identity, learning and operational data needed to run CWL.
Account data
CWL stores your Google provider subject, email, display name, session records and the exact policy versions accepted during registration.
Learning data
Mission progress, hint use, evidence metadata, report content and certificate status remain in the control plane. CWL does not need browser history or unrelated local files.
Lab telemetry
Validators record objective events and resulting target state. Authorization headers, passwords, proxy history, exploit payloads and static flags must not be exported to CRM or analytics providers.
Your controls
You can withdraw marketing consent without deleting your account, revoke VPN devices and choose whether your name appears on public credential verification. Operational account or security messages are separate from marketing preferences.