Legal

Privacy

Last updated September 28, 2026.

This is what Mokxi collects about you, why, who else sees it and how to get it deleted. Mokxi is run by Mokxi LLC, of Colorado Springs, Colorado, which is the controller of this information. It is written by the people who wrote the code, from the code. There are no ads on this site; the measurement tools we use to see whether our own ads work are named below, they stay off until you allow them, and nothing about you is sold.

1. What the simulator sends out

Nothing. The simulation kernel, the CPU cores, every part and the compiler run in your browser. A circuit is never uploaded to be simulated or built. The only time a project leaves your machine is when you ask for it to: saving it to your account, sharing a link, opening a collaboration room, submitting it to a class, or asking a question in the Ask tab.

Ask runs on your own API key from the AI provider you pick (Anthropic, OpenAI, Google Gemini, OpenRouter, Mistral, or another service or a server on your own computer). Each question carries your circuit, the open code, recent serial output, compiler messages and live readings, and "What is sent" in the Ask tab shows exactly that text. Signed out, your key stays in your browser only and questions go straight from your browser to the provider; we never see either. Signed in, a key you save is kept on your account, encrypted, and no page ever shows it again, only its last four characters. Questions then pass through our Worker, which adds the key and passes the answer straight back; we do not keep or log the question, the answer or the key. A server on your own computer is always called straight from your browser, with no key. The provider handles your questions under your own account and terms with it, and bills you for them.

2. Using Mokxi with no account

You can use the editor, the lessons and every page signed out. Your browser keeps a few things locally so they survive a reload: your theme, the parts you placed recently, your learning progress and badges, and a token for any support conversation you start. None of that reaches us until you sign in and ask to keep it on your account. Our host, Cloudflare, keeps ordinary request logs (the address your connection came from, the page asked for, the browser) for a short time for security and to keep the service up. Whatever you choose about analytics, our server adds each page you open to a daily tally so we know roughly how many people visit: the number of pages opened that day, how many visits started, the website or campaign name that sent a visit, and the country Cloudflare reports. It uses no cookie and stores no address, browser details, page address or identifier, so nothing in it can tell one visitor from another or be linked back to you. Class pages and students in a class are never counted. If you allow cookies, we use Google Analytics to count page views. We also use the measurement tag of each place we advertise, to tell whether one of our ads brought anyone here: Google Ads conversion tracking when we advertise on Google, the Meta Pixel when we advertise on Facebook and Instagram, the Pinterest Tag when we advertise on Pinterest, and the LinkedIn Insight Tag when we advertise on LinkedIn. The ad platforms in use now: Google Ads, Meta and Pinterest. A platform that is not on that list receives nothing from Mokxi, from your browser or from our server. The tags in use are told about a page view, a press on a sign-up button, a new account (by which method), a checkout and a paid plan with its price. With a new account and a paid plan, Google Ads and Pinterest, when in use, also receive your email address as a hash (a one-way code made in your browser, never the address itself) so they can match the conversion to an ad. For a new account and a completed paid checkout, our server also sends each of Meta, Pinterest and LinkedIn that is in use a server-side copy of the same event, with the same event id, so each counts it once. A new account made with an email link is counted when the link is first followed, not when it is asked for. Those server-side copies are sent only for an account whose browser allowed cookies when it signed up or checked out, never for a student in a class, and they name you only by a hashed email address. None of these tags loads until you choose Allow cookies, and none of them is ever used for a student in a class. There is no other third-party tracker.

3. What an account stores

  • Sign-in: the id your provider gives us and the provider's name if you sign in with GitHub or Google, or your email address and a salted hash of your password if you sign in by email. Never the password itself.
  • Where you signed up from: we record the country (and US state) you sign up from, from your connection, to see where Mokxi is used. Never your IP address or city.
  • What brought you, if you allowed cookies: the campaign fields on the first link that brought your browser here (such as utm_source and utm_campaign), the ad click id on it if there was one (Google's gclid, gbraid or wbraid, Meta's fbclid or Microsoft's msclkid), the page you landed on and the site that linked to it. We keep it with your account, for our own use only, to see which ads and pages bring people who stay; it is not sent to Google, Meta or anyone else. We also note that you allowed cookies when you signed up, with the random event id of your sign-up, which is the only part shared with the ad platforms so they count the sign-up once. With Necessary only, none of it is kept, and it is never kept for a student in a class: joining a class as a student deletes it.
  • Profile: your name, email address and avatar as your provider gave them, and whatever you fill in on your account page: a handle, a short bio, links to your own pages, and whether your learning progress is shown publicly.
  • Projects: the circuits and code you save, their saved versions, whether each is public, and the projects you favorite.
  • Learning: which lessons you have done, your points, level, streak, daily quests and badges, a record of what earned each point (a short name for the action, such as a board you ran for the first time, and the day), and whether you have checked the box to be on the leaderboards or joined a weekly league. Only then are you shown, with a name or handle, your level and your XP, and never your email. Untick it and you are taken off.
  • Classes: for a teacher, the classes they made, the join codes, the roster of accounts that joined, the assignments and the submissions. For a student, which classes they are in and what they submitted.
  • Plan and billing: which plan you are on, and the customer and subscription ids Stripe gives us. Stripe holds your card details; we never see the card number.
  • Student discount: the school email address you verified with, when it was verified, and the outcome.
  • Invites: your invite link, which accounts signed up through it or which account invited you, whether that sign-up led to a reward, and the Pro days it earned. We never ask for or store the email addresses, phone numbers or contacts of people you invite, and we never email them on your behalf: the link is the whole invite. Accounts in a class as a student take no part.
  • Ask: any AI provider API keys you save, encrypted, with their last four characters and, for a custom server, its address. Never shown again, to you, your teacher or us.
  • Activity: a dated record of what your account does in Mokxi, kept in our own database so we can see which features people use, where they get stuck and what to build next. It lists actions, not content: that you signed up, signed in or out, confirmed your email, turned two-factor on or off, created, saved, shared or deleted a project, hit a plan limit, started a checkout or changed a plan, made or joined a class, handed in or reviewed work, made an API token, or sent a question in Ask (the provider's name only). In the editor and on the site it also lists that you opened the editor, pressed Run, whether a build worked or failed (the kind of error only), which board, parts, examples and guides you picked, which pages you opened, what you exported from the share sheet, settings you switched, and short words you typed into the parts search. Each entry holds your account id, the action, the time and a few short labels such as a board or part name. It never holds your code, your circuits, your messages, your keys, your IP address or your email address. It is not shared with anyone and not used for advertising.

4. Collaboration rooms

When you open a room on a project, the edits and cursors of everyone in it pass through our Worker so they reach each other. The room keeps the project's current state in memory while it is open and writes it to your saved project. We do not keep a log of who edited what once the room is closed. People in a room see each other's names or handles.

5. The newsletter

If you subscribe, we store your email address, which of our lists you chose and whether you confirmed. Nothing is sent until you follow the confirmation link. Every email carries an unsubscribe link, and the unsubscribe page lets you drop one list or all of them. The list is ours; the sending is done through Resend.

6. Support

When you write to us through the help panel or the support page, we store your message, the email address you gave and our replies, so that you can read the conversation later on any page of the site. Replies come to you by email, sent through Resend. A support thread is tied to a token in your browser, not to an account, so a signed-out person can use it.

7. Cookies

Two necessary cookies are ours and appear only when you use them: a signed session cookie that says which account you are signed in to, and a short-lived cookie that remembers which page to come back to after sign-in. If you arrive through an invite link, another cookie remembers the invite code for up to 30 days, until you sign up, so the invite can be counted for both of you. A cookie named mokxi_consent remembers your choice on the analytics bar. Analytics stays off until you choose Allow cookies. Then a first-party cookie named mokxi_src keeps the campaign fields and ad click id of the first link that brought you, for up to 90 days, so an account you make can record what brought you; Google Analytics sets cookies named _ga and _ga_ followed by an id; and each ad platform in use now (listed in section 2, and only those) may set its own: Google Ads conversion tracking may set _gcl_au and _gcl_aw to keep the Google ad click that brought you; the Meta Pixel may set _fbp and _fbc; the Pinterest Tag may set _pin_unauth and _epik; and the LinkedIn Insight Tag may set li_fat_id and other LinkedIn cookies. Right after you sign up, a cookie named mokxi_signup_eid holds your sign-up's random event id for up to 15 minutes, until the page reads and deletes it; after a sign-up by email link, a cookie named mokxi_signup_new tells the page you land on that the account is new, for up to 15 minutes, until the page reads and deletes it. When you sign up or buy a plan, the Meta values, the Pinterest _epik value and the LinkedIn li_fat_id value can be sent from our server, to those of Meta, Pinterest and LinkedIn in use, with a hashed email and account id, the browser name and connection address so each can match the sign-up or purchase to an ad without counting it twice. You can decline with Necessary only, and you can change your choice by clearing this site's data in your browser. None of these analytics or advertising tags is loaded on the class pages, on the sign-up that leads into a class, or on any page for an account that is in a class as a student.

8. Why we use it

To run Mokxi, sign you in, save and share your work, run your classes, bill you for a plan you chose, answer you when you write, send you what you subscribed to, keep the service up and keep it safe. The activity record in section 3 is for deciding what to fix and build next, and it stays with us. With your analytics choice, we also measure and improve Mokxi's own ads. We do not show third-party ads on Mokxi, and we do not sell or rent your information.

9. Who else sees it

The companies below process some of your information so that Mokxi can work. Each one is bound by its own privacy terms and by a contract with us that limits its use to running our service.

  • Cloudflare hosts the site, the Worker, the database and the file storage. Everything above is stored there.
  • Stripe handles payments. Your card details go to Stripe directly and we receive the plan, the customer id and the subscription id.
  • Resend sends our email: sign-in links, receipts, support replies and the newsletter.
  • GitHub and Google, only if you choose to sign in with them, tell us your id, name, email address and avatar.
  • The AI provider you pick for Ask receives your questions and the project text that goes with them, under your own account with that provider. It is your provider, not ours: we pass the question on and keep nothing.
  • The ad platforms in use now: Google Ads, Meta and Pinterest. A platform that is not on that list receives nothing from Mokxi, from your browser or from our server.
  • Google, only after you allow cookies, counts page views for us through Google Analytics and, when we advertise on Google, tells us which Google ads led to a sign-up or a paid plan through Google Ads conversion tracking. A sign-up and a paid plan are reported with your email address hashed in your browser (Google's Enhanced Conversions), which Google uses only to match them to an ad, and a paid plan also with its price and an order number. Google Tag Manager, which we also use, loads only after you allow cookies too. Google processes those under its own terms; you can opt out of Analytics with the browser add-on at tools.google.com/dlpage/gaoptout and limit ads at adssettings.google.com.
  • Meta (Facebook and Instagram), when we advertise there and only after you allow cookies, receives page events from the Meta Pixel (a page view, a new account, a checkout, a paid plan) and a server-side copy of the new account and of a completed paid checkout, for an account whose browser allowed cookies. The server reports include hashed email and account id, Meta cookie values when present, browser name and connection address, and for a purchase the value and plan. It never includes a circuit, project, class name or student data. Meta processes it under its own terms; you can limit it in your Facebook ad settings.
  • Pinterest, when we advertise there and only after you allow cookies, receives events from the Pinterest Tag (a page visit, a new account, a paid plan with its price and an order number), with your email address hashed in your browser while you are signed in (Pinterest's Enhanced Match), and a server-side copy of the new account and of a completed paid checkout, for an account whose browser allowed cookies. The server reports include hashed email and account id, the Pinterest cookie value when present, browser name and connection address, and for a purchase the value and plan. It never includes a circuit, project, class name or student data. Pinterest processes it under its own terms; you can limit it in your Pinterest privacy and data settings.
  • LinkedIn, when we advertise there and only after you allow cookies, receives events from the LinkedIn Insight Tag (a page view, a new account and a paid plan) so we can tell whether our LinkedIn ads reach teachers and schools, and a server-side copy of the new account and of a paid plan, for an account whose browser allowed cookies, with a hashed email address, the LinkedIn li_fat_id cookie value when present, and for a purchase its value. No circuit, project, class name or student data goes to it. LinkedIn processes it under its own terms; you can limit it in your LinkedIn ad settings.
  • None of the analytics or advertising tags above is ever loaded for a student in a class, on a class page or on the sign-up that leads into a class, whatever was chosen on the cookie bar.

Beyond that, we disclose information only when the law requires it, to protect someone's safety, or to protect Mokxi from attack or fraud. If Mokxi is ever sold or merged, your information goes with it under this same notice, and we tell you first.

10. What other people can see

A public project is visible to everyone, with your handle or name on it. Your profile page is public if you make it public. The public leaderboard at /leaderboard shows your name or handle, level and XP only if you check the box to be on it, and never shows a student in a class. A weekly league shows the others in it a nickname made up for you from two words and a number, your level and your XP that week, only if you join it; a student in a class cannot join one. A project you submit to a class is visible to that class's teacher. Everything else is private to you and to the people you share a link with.

11. Children and schools

Mokxi is not directed at children under 13, and we do not knowingly let a child under 13 make an account on their own. A child under 13 may have an account with consent: through school, the school gives it on the parents' behalf under its Student Data Privacy Agreement with us (or, until one is signed, through the teacher who sets up the class for the school) and stays in charge of the student's information; outside school, a parent or guardian gives it by writing to us, and we confirm it with them first. For such a child we collect only what the service needs, we never use it for advertising or anything commercial, the activity record keeps only account, class and billing actions (never how they use the editor), and the school or a parent can see it or have it deleted by asking us. If you believe a child has given us information without that consent, tell us and we delete it. Students in a school class are covered in full by the student data privacy notice at /privacy/students: what we collect, the companies that process it, how long it is kept, and how a school has it exported or deleted.

12. How long we keep it

For as long as your account exists. The activity record is the exception: each entry is deleted after 13 months. When you close your account from your account page, your profile, projects, learning progress, class memberships, referrals, saved Ask keys and activity record are deleted right away, and the copies in our backups go within 30 days. Billing records are kept for as long as tax law requires. A support conversation is kept for two years from the last message. A closed class's roster and submissions are deleted when it closes. A newsletter address is removed when you unsubscribe, apart from a note that says not to send to it again.

13. Your rights

Wherever you live, you can ask us what we hold about you, have it corrected, have it deleted, get a copy of it, or object to a use of it. Most of it you can see and change on your account page, and any project can be exported as a file. For the rest, write to us and we answer within 30 days; we may ask you to prove the account is yours. If you are in the European Economic Area, the United Kingdom or Switzerland, these are your rights under the GDPR and its UK and Swiss equivalents, our legal basis is the contract with you for the service and consent for analytics, and you can complain to your local data protection authority. California and other US state privacy laws may call ad measurement a sale or sharing even though no money changes hands. Choosing Necessary only prevents that measurement, and we do not discriminate against anyone for using that choice or another privacy right.

14. Security

Everything travels over TLS. Sessions are signed cookies. Passwords are salted and hashed and never stored in the clear. Card numbers never touch our systems. Secrets live in Cloudflare's secret store, never in our code. No system is perfectly secure, and if we learn that your information has been exposed we tell you and, where the law requires, the authorities, without undue delay. If you think your account has been compromised, tell us right away.

15. Where it is stored

We are in the United States and Cloudflare stores the data on its network, which spans many countries. If you are outside the United States, your information is transferred there and handled under this notice; for people in the EEA, the UK and Switzerland the transfer to our processors rests on the standard contractual clauses in their contracts with us.

16. Changes

When this notice changes, the date at the top changes. If a change means we collect something new or use something differently, account holders hear about it by email before it happens.

17. Contact

Questions about any of this go to the support page at /support, by email to support@mail.mokxi.com, or by phone on (719) 246-1726. A person answers.

By post:

Mokxi LLC
5142 N Academy Blvd PMB 1021
Colorado Springs, CO 80918
United States