Sign in, open the firm through TBR and check out with your code applied. Keep the order confirmation, submit it on your claims page, and the points land in your balance once the order is confirmed.
Privacy controls
This prototype stores only the data needed to operate education, purchase verification, rewards, security review and Discord delivery.
Account and rewards
We store your Discord identifier and display name, lesson progress, append-only point ledger, redemptions, in-app notification history and read state, and administrator audit records. Discord is used for sign-in, bot commands and private redemption status notifications. Public reward announcements remain optional and are sent only after you opt in.
Purchase verification
Purchase email addresses are encrypted and also converted to a keyed match value. Receipt files are encrypted by TBR before UploadThing stores the unreadable object; only authorised reviewers can ask the application to decrypt it. Public learning images and documents uploaded by administrators are served by UploadThing without receipt or account data. Do not upload payment-card details. Reviewed receipt files are targeted for deletion after 60 days; abandoned pending evidence after 90 days.
Evidence assistance
An administrator may run an advisory evidence review. Image text recognition and document parsing happen on the application server. When the optional DeepSeek review is enabled, only bounded lines relevant to the claim are sent to OpenCode Go after email addresses, order identifiers, URLs and payment-like numbers are redacted. Receipt files, Discord identities and device signals are not sent. The result cannot verify a purchase or make an eligibility decision.
Device security signals
A rotating keyed identifier may be derived from a first-party cookie and coarse browser properties only when you submit a claim. It is retained as a short-lived security hint, but claim frequency and legitimate purchases from the same device are not evidence-review concerns and never make an automated eligibility decision.
Optional Aurea analytics
When configured, Aurea can receive page views and bounded product events with an anonymous browser identifier. It does not receive purchase emails, receipts, order numbers or unverified purchase conversions. Analytics remain off until you allow them here.
Your data
Sign in to access your dataQuestions or manual requests: privacy@tbarblueprint.com.