Privacy Policy — CP Word List Addendum
Summary: you sign in with Google and save your enrollment platform's address and API credentials, which we store encrypted. When your platform tells us about a new enrollment, we change that enrollment's passphrase and keep the old and new phrase for about five minutes so the enrollment page can show it. We keep an activity log for 90 days. You can delete your account yourself at any time.
Contents
What CP Word List is
CP Word List runs on Cloudflare's network. It has three parts:
- A dashboard, where you sign in, save your enrollment platform's details, see your activity log, and download a unit spreadsheet of generated passphrases.
- A webhook, which your enrollment platform calls when a device enrolls. CP Word List signs in to your platform with the credentials you saved, finds the passphrase for that enrollment, replaces it with three words from the EFF short word list, and writes it back to your platform.
- A lookup, which the enrollment page on your platform calls from the enrolling person's browser to fetch the new phrase and show it to them.
CP Word List is not a Model Context Protocol (MCP) product and sends nothing to any AI model.
Roles
You, the organisation that signs up, operate the Wi-Fi network and decide who enrolls in it. For the people who enroll on your network, you are responsible for the data your platform holds about them, and CP Word List handles that data only to carry out the passphrase change you set it up to make. For your own account, NeuralConfig is responsible for the data described here.
Data collected
1. Your account
You sign in with Google. We request the openid, email and profile scopes and store your Google account identifier, your email address and your name. We do not receive your Google password or ask Google for access to any other Google service.
Before an account is created you must accept the Terms and this Privacy Policy. Each time you accept, we record the versions you accepted, the time, your IP address and your browser's user agent. If you don't accept, your Google details are deleted within 15 minutes.
Some accounts set up by us before Google sign-in existed have a username and a hashed password instead.
2. Your enrollment platform details
- The platform's address (hostname)
- An API username and password, which are encrypted before they are stored and are never shown back to you or to us in the dashboard
- The Wi-Fi network name (SSID) shown on your enrollment page
- A shared secret we generate, which your platform sends with each webhook call so we know the call is yours. It is shown in your dashboard so you can copy it into your platform, and you can generate a new one at any time.
Accounts whose platform address is not on the platform vendor's hosted service are reviewed by us before they are switched on.
3. Passphrase changes
For each enrollment your platform reports, we store for about five minutes:
- the old passphrase and the new passphrase
- the passphrase record's identifier and name, as your platform reports them
- the enrollment identifier
The enrolling person's browser sends the old passphrase to our lookup to fetch the new one. After five minutes the lookup no longer answers, and the stored copy is deleted within the next five minutes. The passphrase in your platform stays the authoritative copy.
Depending on how you set up your platform, the passphrase record's name can include the enrolling person's name or email address.
4. Activity log
For each passphrase change your platform asks for, and each one that fails, we record the event, the time, the enrollment identifier, and details: the passphrase record's identifier and name on success, or the kind of error on failure. An error entry can include an error message returned by your platform. Passphrases and your shared secret are never written to the activity log.
5. Spreadsheet export
When you download a unit spreadsheet, the passphrases in it are generated for that download. We do not store them.
6. Feedback
The public feedback page stores the name you give (optional), your message and your IP address. Feedback is not linked to an account.
7. Operational logs
Our server writes operational events: event names, status codes and counts. These never include passphrases, enrollment identifiers, passphrase record identifiers or your shared secret. They are not stored; we can see them only while we are watching them live.
8. Cookies
The dashboard uses only the cookies it needs to work: a sign-in session cookie that lasts one hour, and two short-lived cookies used during Google sign-in that last ten minutes. The Cookies Policy has more.
How CP Word List uses this data
- To sign you in, keep you signed in, and record your acceptance of the Terms and this Privacy Policy
- To sign in to your enrollment platform and change the passphrase for each enrollment it reports
- To show the new passphrase to the person enrolling
- To show you, and us when you need support, the activity log of your passphrase changes
- To review accounts whose platform is self-hosted, and to answer feedback
We do not use this data for advertising or profiling, and we do not sell it.
Sharing
- Your enrollment platform: CP Word List sends your platform your API credentials to sign in, and the new passphrases it writes. It reads the passphrase record for each enrollment.
- Cloudflare: our server and database run on Cloudflare.
- Google: for sign-in.
- jsDelivr: the dashboard's Technical Reference page loads a diagram library from the jsDelivr content network, which exposes your IP address to jsDelivr when that page loads.
No data is sent to AI models, analytics services or advertisers.
Retention
| Data | Kept for |
|---|---|
| Account, platform details and encrypted credentials | Until you delete your account |
| Old and new passphrases, passphrase record identifier and name, enrollment identifier | About five minutes, deleted within ten |
| Activity log | 90 days |
| Feedback | 90 days |
| Sign-in sessions | One hour, then deleted by a daily cleanup |
| Google details before you accept the Terms | Up to 15 minutes |
| Records of your acceptance of the Terms and Privacy Policy | Kept as our legal record, including after you delete your account |
Cloudflare's database backups can hold deleted data for up to 30 days before it is gone from them too.
Security
- API credentials are encrypted with AES-256-GCM, using a key derived for your account and a fresh random value for each saved credential.
- Webhook calls must carry your shared secret. You can send it in the request body; sending it in the URL also works, but it then appears wherever your platform logs the URLs it calls, so the body is the better choice.
- Browsers may read the lookup's answer only on pages served from your own platform's address.
- The admin sign-in is rate-limited.
Your rights
- Delete your account: on the dashboard's Account page, type your account's email address to confirm. This immediately deletes your platform details and credentials, your activity log, any passphrases still held, pending sign-ins and your sessions. Your account record is cleared of your email, name, Google identifier and platform details and kept only so your acceptance records still point at something. Those acceptance records, including the IP address and user agent recorded with each, are kept. If you sign in with Google again later, you get a new, empty account.
- Remove your credentials: save new ones in the dashboard at any time, or delete your account.
- Feedback: to have feedback deleted before 90 days, email us.
- Other requests, such as a copy of your data: email us.
- The rights in the Master Privacy Policy apply.
Contact
For CP Word List privacy questions and requests: [email protected]. For general privacy questions: [email protected].
← Back to the Master Privacy Policy