typestar

Privacy

Last updated 26 August 2026.

typestar is a touch-typing trainer for code. This page says what it stores about you, why, for how long, and what you can do about it. The controller is typestar.io, operated by brendancol on GitHub; write to that account (an issue on the project, or a direct message) for anything below.

Typing as a guest

Without an account, everything about your typing lives in your browser: your settings, your progress and stars, your personal bests, and the keystroke timings of your best run on each snippet (the ghost you race against). None of it is sent to the server, and clearing your browser's site data removes it.

The server keeps one thing about guests: an anonymous funnel log for the first-visit flow. Your browser mints a random id and sends events from a fixed, closed vocabulary ("landed", "diagnostic finished", and the like). The page that referred you is reduced to a channel (search, direct, reddit) before it leaves the browser; the URL itself is never sent. This id is never joined to an account. These rows are deleted after 90 days.

Joining a live race as a guest is rate-limited by IP address. The address is held in the server's memory for that purpose only and is not written anywhere.

With an account

Signing in uses GitHub with the read:user scope. typestar stores your GitHub login and the times the account was created and last seen. GitHub also returns your public email; it is discarded, never stored.

Your preferences: theme, language of the interface, the languages you are interested in, a country you can declare yourself (never inferred from your address), and whether you appear on the leaderboards.

Every typing test you finish: speed, accuracy, duration, per-character error counts, the settings it was typed with, and when. These are what your profile, streak and history are made of.

Keystroke timings are kept in three places and nowhere else. Your best run on each snippet is stored so you can race your own ghost; it is served only to you. A run you share is frozen with its keystrokes until you unshare it, which deletes them. Each leg of a live race is kept for 30 days so an administrator can replay a disputed race; those are never public.

Outcomes of battles, arenas and races you took part in: who won and by how much.

Why

All of the above is needed to provide the service you signed up for: a profile that remembers your runs, a leaderboard that can be trusted, a ghost to race. The leaderboard ranks only numbers the server re-derives from keystrokes, which is why the keystrokes of a ranked run are worth keeping. The funnel log rests on our legitimate interest in knowing whether the first-visit flow works; it cannot identify you.

What is public

Your login and scores appear on the leaderboards and on your public profile page only while you are opted in (Profile, then Settings). Opting out unpublishes every board row at once. How you type, meaning keystroke timing, is never public; only a run you deliberately share carries its replay, and only to people holding that link.

Cookies and browser storage

One cookie, the session, keeps you signed in. It is HttpOnly and needed for the service, so there is no banner to click. Everything else lives in localStorage: your settings, and for guests the progress and bests described above. Signing out removes the account-derived part of it (bests, ghosts, interests, position) from that browser.

There are no third-party analytics, fonts, scripts or CDNs on any page.

Who else sees data

GitHub, for sign-in. Fly.io, which hosts the server and its database in the United States (Virginia); if you are in the EU, your data is transferred there to run the service. Nobody else.

How long

Results, preferences and ghosts: for the life of the account. Funnel events: 90 days. Race-leg keystrokes: 30 days. A shared run's keystrokes: until you unshare it.

Your rights

From Profile, then Settings, you can download everything stored about your account as JSON and delete the account. Deletion removes your user row, results, ghosts, progress, board standings and race legs in one act; it cannot be undone.

You can also ask the controller to correct, export or erase your data, or object to the funnel log, by contacting the account named above. If you are in the EU you have the right to complain to your supervisory authority.