Security verification privacy notice
This notice describes Emoluna's use of Cloudflare Turnstile for account security.
Emoluna uses Cloudflare Turnstile in Invisible mode to help prevent automated abuse when starting a new guest session, logging in with an email and password, or requesting a password recovery code. Existing sessions are reused without a new registration check when you open lessons.
Cloudflare processes technical browser and device signals for this verification. Please read the Cloudflare Turnstile Privacy Addendum for details of its processing.
The verification page receives a public sitekey and a random request identifier. On web, it also receives the app's origin to return the result safely. Emoluna does not send this page your name, email, password, lesson progress or Supabase session tokens.
A short-lived verification token is returned to Emoluna and sent with the account request to Supabase Auth for server-side validation. Emoluna does not store the verification token in its profile or lesson database. Cancelling or failing verification does not create an account or discard your existing lesson progress.