legal
Privacy policy
Last updated: August 23, 2026
This policy explains how whoburnedmore handles data across the website, command-line tool, and macOS app. Our guiding rule is simple: code, prompts, file names, project names, and generated text stay on your device.
Google sign-in data
When you choose Google sign-in, Google provides the OpenID Connect fields needed to identify your account: your Google account identifier (sub), verified email address, name, and profile image. We use these fields for identity only: to sign you in, keep your account connected between visits, show your chosen profile details, and prevent duplicate accounts.
We do not request or access your Google Contacts, calendars, Drive files, email contents, or other Google product data. Google sign-in is not used to sync contacts. You can also sign in with GitHub instead.
Usage and profile data
The local tools calculate aggregate usage data such as daily token totals, estimated cost, tool, model, and date. Only those aggregate totals are submitted when you choose to sync; raw prompts, code, chat history, file names, and repository names are not submitted.
You may add a public handle, profile image, social links, and board memberships. Public visibility controls determine whether your profile and aggregate totals appear on the public leaderboard. Friends and organization boards may show data to their members according to the board settings you join or manage.
Analytics and service processors
We collect limited website and product analytics, including page views, feature events, coarse paths, device/browser information, and service health data. We use this information to operate, secure, debug, and improve the service; we do not sell personal information.
Our processors may handle data only to provide their services: Google and GitHub for OAuth identity, Vercel for website hosting and traffic analytics, PostHog for product analytics, Microsoft Azure for the API, MongoDB for managed database storage, and Google Cloud Storage for uploaded profile and organization images. Their own privacy terms also apply when you use those services.
Retention and deletion
Account and aggregate usage records are retained while your account is active so the leaderboard and boards work. Operational logs and backups are retained only for limited security, reliability, and recovery periods, then expire or are overwritten under the relevant processor's normal retention cycle. Legal or abuse-prevention obligations may require limited records to be kept longer.
Delete your account: email hi@arhamamin.com from your account's verified address. After we verify the request, our deletion API removes your first-party account, profile, and submitted usage data, plus boards you own, friendships, connectors, first-party events tied to your account, and active authentication artifacts.
Some analytics and security logs or backups held by our processors may remain for the limited retention periods described above; account deletion does not promise immediate erasure from every processor. You may ask support for processor-linked deletion, and we will pass along or fulfill that request where the processor supports it and law permits.
You can revoke Google access at any time from your Google Account's third-party connections page. Revocation stops future sign-in access; it does not by itself delete data already stored by whoburnedmore, so contact us as well if you want erasure.
Security, children, and changes
We use access controls, encrypted connections, scoped service accounts, and restricted production credentials to protect data. No online service can promise absolute security, so please report suspected problems promptly.
The service is not directed to children under 13, and we do not knowingly collect their personal information. We may update this policy as the product or legal requirements change. Material changes will be posted here with a new effective date.
Contact
Questions, privacy requests, or deletion requests can be sent to hi@arhamamin.com. For a technical description of the local usage payload, see data and trust.