Privacy Policy

Last updated: 12 May 2026

Gridbach is a non-commercial research project that distributes the verification of Goldbach's conjecture across the browsers of volunteers. Running the calculation involves a small amount of personal data, in the broad sense the EU General Data Protection Regulation (GDPR) gives that term. This page explains what is collected, why, and what choices you have. It is written for everyone, but the rights described under "Your rights" are the ones GDPR grants people in the EU and the EEA.

Who is responsible

Gridbach is run by an individual operator, not a company. Questions about this policy or about your data can be sent to jay@gridbach.com.

What data is collected

Stored in your browser only (localStorage and IndexedDB), never sent to the server: • a random identifier for this browser (a UUID, used so your contribution can be attributed without a login) • your running totals and recent results (numbers verified, supporting examples, counterexamples, processing times, recent and largest "Goldbach ridges"), a cached copy of the public statistics, a visit counter, and your display preferences such as language and verbose mode, plus a flag recording that you have seen the notice about this policy • the small table of prime numbers and the diagnostic log the calculation kernel keeps for itself Received by the server when your browser asks for or returns a verification job, reports a problem, or sets a display name: • the random browser identifier above, plus the kernel version and a coarse "platform" and "mobile or not" hint derived from your browser's user-agent string • an optional display name, if you choose to set one, which is then shown publicly next to your verification totals on the "Verification Frontier" page • your IP address — this is part of every web request; it is used in the moment to derive the two items below and is not written to our database • the ISO country code, network number (ASN) and network operator name that Cloudflare derives from your IP address • if a calculation fails on your machine, or our server stays unreachable for several minutes, a short error report — which job was being processed, the error message and stack, and the same browser identifier, kernel version and platform hints listed above — used only to find and fix kernel bugs and service outages No name (other than an optional display name you choose to enter), e-mail address, precise location, advertising identifier or third-party tracker is collected. There are no advertising or analytics cookies; the only cookie set is one that remembers your language choice.

Why it is collected

• To hand out verification jobs and record the results, which together extend the verified bound of Goldbach's conjecture — the purpose of the project. • To attribute each result to the browser that produced it, and to group results by network, country and kernel version, so that bad or duplicated results can be detected and excluded and the overall computation can be trusted. This trust-clustering use is the reason the country and network information is kept. • To show aggregate, non-identifying statistics (totals, recent results, leaderboards, active sessions, per-country diversity) on the public "Verification Frontier" page. • To diagnose and fix crashes in the calculation kernel and outages of the service, using the error reports described above. • To keep the service running and protect it from abuse, as part of Cloudflare's standard request handling.

Legal basis (GDPR)

The processing relies on legitimate interests (Article 6(1)(f) GDPR): running a public-interest mathematical computation and being able to trust its results. The data involved is minimal and pseudonymous and the project is non-commercial, so this interest is not overridden by your interests or rights. The language cookie and the data kept purely inside your own browser are strictly necessary for the feature you are using.

How long it is kept

Per-job attribution data (browser identifier, kernel version, country, network) is kept for as long as the corresponding computation needs to remain auditable — in practice, for the lifetime of the result corpus that supports the project's verified bound. When the project moves to a new computational baseline, the job records are wiped and the count restarts, so older attribution data is deleted at that point. Aggregate statistics may be retained indefinitely. Data stored in your browser stays there until you clear it (see "Data kept in your browser") or your browser discards it.

Who the data is shared with

Gridbach uses Cloudflare for hosting, request handling and storage (Workers, D1, Pages and R2). Cloudflare processes the data on Gridbach's behalf under its data-processing terms. The data is not sold, rented or shared with advertisers or data brokers, and is not used to build profiles of individuals. Aggregate, non-identifying statistics are public on this site. The project's verification results — the numbers and their Goldbach partitions — may be cited or published as supporting data alongside an academic paper; such a release does not include the per-browser attribution identifiers. Operational alerts, including the error reports above, are relayed to the operator through a webhook into a private channel on Discord, a messaging service that processes those messages under its own terms.

International data transfers

Cloudflare operates a global network, so requests and stored data may be processed on servers outside the EU/EEA, including in the United States. Where that happens, the transfer is covered by the data-protection safeguards in Cloudflare's terms, such as the EU Standard Contractual Clauses. Gridbach does not currently guarantee EU-only data residency.

Your rights

If you are in the EU or EEA, GDPR gives you the right to access the personal data held about you, to have it corrected or erased, to restrict or object to its processing, and to data portability. You also have the right to lodge a complaint with your national data protection authority. Because the only stable identifier is the random UUID stored in your browser, exercising most of these rights in practice means telling us that identifier — you can find it in your browser's developer tools under localStorage as "clientId". You can also erase all of your locally stored data yourself at any time (see below). To make a request, contact jay@gridbach.com.

Data kept in your browser

Everything Gridbach stores on your device — the random identifier, your totals and results, the cached statistics, the prime table and the diagnostic log — lives in your browser's localStorage and IndexedDB and can be removed at any time. Use the gear icon at the bottom of the page ("Erase my calculation data saved in the browser"), or clear site data for this site in your browser's settings. Doing so resets your contribution identifier; a new one is generated the next time you run the calculation.

Changes to this policy

This policy may be updated as the project evolves. The date at the top shows when it last changed; significant changes will be reflected there.

Contact

For any question about this policy or about your personal data, contact jay@gridbach.com.

© 2025 Gridbach
Privacy Policy