Privacy notice
Last changed 4 October 2026.
OpsQuest keeps as little as it can and uses it only to run the labs. There are no ads, no tracking cookies, and nothing is sold or shared for marketing.
Who runs this site
The operator has not published a contact address yet.
Reading lessons
Lessons, theory notes, and the library need no account. Your browser keeps your local progress and the light or dark theme in its own storage; they never leave your device unless you sign in.
If the operator turns on Cloudflare Web Analytics, page views are counted without cookies and without identifying you.
When you make an account
- Email address. To sign you in, and to send the confirm and reset-password links. We send nothing else.
- Password. Stored only as a salted PBKDF2 hash. Nobody can read it back.
- GitHub, if you sign in with it: your GitHub user ID, username, and verified primary email. We ask for nothing else and keep no GitHub token.
- Progress: labs you passed, bookmarks, notes, self-reviews, and how much lab time you used today.
- Profile: a display name and a handle, if you set them. The profile stays private until you tick "public".
On a lab machine
Each lab runs in its own disposable container with no internet access. The machine is deleted when the session ends. While it runs:
- Commands you type in the lab terminal are written to
~/.opsquest/commands.logon that machine. The server reads it to offer nudges and to build the report of a pass. A command typed with a leading space is not logged. - Checks, hints you open, and the diagnosis you write are recorded for the report and, in a study group or a live round, for the people running it.
What other people can see
- Reports of your passes are public to anyone with the link. They show your display name, times, checks, hints, and any postmortem you wrote. Your commands appear only if you choose to share them.
- Public profile: only if you turn it on.
- Study groups you join: the owner sees your name there, the labs you passed, the lab you are on, and the message of your last failed check.
- Live rounds: everyone watching sees the name you joined with and your progress in the round.
- Today's incident: your display name and time, if you pass it.
- Pair invites: whoever has the link sees your terminal; a "drive" link can type in it.
Guests
A guest gets a random ID in a cookie that lasts a day. Guest progress is deleted 30 days after it was last used.
Cookies
opsquest_auth: keeps you signed in (30 days) or marks you as a guest (1 day).opsquest_oauth: lives ten minutes during a GitHub sign-in.
Both are needed for the site to work. There are no others.
Services that handle your data for us
- Cloudflare hosts the site, the lab machines, and the stored data, and runs the Turnstile browser check. Its network keeps request logs, including your IP address, for a short time for security and debugging.
- Resend delivers the confirm and reset emails.
- GitHub, only if you choose to sign in with it.
How long we keep it
Account data stays until you delete the account. Counts used to run the site (sign-ups, lab starts and passes per day) hold no names. Problems you report on a lab stay with your email until we resolve them or you delete your account, after which they are kept without it.
Your choices
- Account settings let you download everything we keep about you as one file, change your password, sign out everywhere, and delete the account.
- Deleting the account removes its progress, notes, reports, profile, and group places.
- For anything else, write to the contact above.