Privacy Policy
Version 2026-08-25. Not legally reviewed. Every factual claim below describes what the code actually does today — where something is planned rather than built, it says so.
1. What we hold about you
To identify you:
- Your email address, retrieved from our identity provider once, when you register.
- Your identity provider's subject identifier for you.
- Your workspace, your role in it, and which workspace you last had selected.
- A dated record of which versions of these documents you accepted.
For each unit of AI usage reported to us:
- Token counts, the model identifier, and the region assumed for grid intensity.
- The energy and emissions figures we calculated, and the version of the factor table that produced them.
- A project name, a session identifier, and timestamps.
- Where it came from — self-reported, vendor billing data, or an instrumented client — and, where the vendor supplied one, that vendor's request identifier.
- An optional free-text note, if whoever reported the usage chose to attach one.
2. What we deliberately do not hold
We do not receive or store your prompts or the model's responses. The instrumented-client path redacts them before they leave your machine, and our receiver rebuilds each record field by field from a fixed allowlist — anything not on that list is discarded at the edge rather than stored and filtered later.
Telemetry from instrumented clients carries the end user's email address in plain text. We do not keep it. It is replaced at the ingest edge with a keyed digest, scoped per organization so the same address in two organizations produces two unrelated values, and today not even that digest is stored — usage from that path is attributed by the ingest token that sent it. When per-user attribution is built, the digest is what will be stored; the address itself still will not be.
We use no analytics, no advertising, and no third-party tracking. There
is one cookie: the session cookie that keeps you signed in. It is
HttpOnly, so scripts on this page cannot read it, and it
expires within the hour.
3. Who else processes it
- Stytch — authentication and email delivery for sign-in links and invitations. They hold your email address and your sign-in events.
- Railway — hosting and the database this service runs on.
We do not sell your data, and we do not share it with anyone else unless the law requires it — in which case we will tell you, unless we are forbidden from doing so.
4. Who inside your organization can see it
Administrators of your workspace can see usage reported by every member of it, including yours, in reports and exports. Ordinary members see only their own. Nobody outside your workspace can see any of it: every query this service makes is scoped to one organization, and there is no view that crosses that boundary.
5. How long we keep it
Usage records are kept for as long as your organization exists, because a footprint history is the product. Deleting an organization deletes its usage records with it. Your consent records are deleted with your account — keeping a record of consent for someone who has asked to be forgotten would defeat the reason for keeping it.
6. What you can ask for
You can export everything we hold about your organization from the dashboard, as CSV, at any time and without asking us. You can ask us to correct or delete your account and its data. Depending on where you live, you may also have the right to object to processing or to complain to a data protection authority.
7. Changes to this policy
Each revision has a version, and you will be asked to accept the new version the next time you sign in. Continued use is not treated as agreement.
8. How to reach us
No contact address is configured on this deployment. That is a defect, not a policy: see the support page.
See also the Terms of Service (version 2026-08-21), whose section 2 explains why every figure here is an estimate rather than a measurement.