Skip to main content
DEPT. OF AI OVERSIGHTFOR OFFICIAL USE ONLY
DossierLeaderboardAchievementsTeams
HomeLeaderboardDossierPrivacyTerms
Q1 2026 · EndedUNCLASSIFIED

DEPT. OF AI OVERSIGHT - PRIVACY DIVISION

PRIVACY POLICY

UNCLASSIFIEDEffective: February 2026
OFFICIAL NOTICE

1. Overview

Existential Burn (“the Service”) is a free tool for Claude Code users to visualize usage statistics and compete on anonymous leaderboards. This policy explains what data we collect, how we use it, and your rights regarding that data.

2. Data We Collect

We collect only the Claude Code usage statistics you voluntarily upload. This includes:

  • Session counts and durations
  • Message and conversation counts
  • Tool call statistics (counts by tool type)
  • Model usage breakdown (tokens per model)
  • Hourly activity distribution
  • Token consumption (input/output)
  • Estimated cost calculations
  • Project names and git branch names, unless you choose the paranoid redaction level (see section 5)
  • Facets data: session goals, outcomes, and satisfaction ratings (no conversation content)

3. Data We Do NOT Collect

  • Real names, email addresses, or personal identifiers
  • Conversation content or prompts
  • Source code or file contents
  • Passwords or authentication credentials
  • Browser fingerprints or cross-site tracking identifiers

4. Anonymous Authentication

We use a functional cookie (eb_token) to identify your anonymous account. This is a UUID stored as an httpOnly, secure cookie with SameSite=Lax and a one-year expiry. No registration, email, or personal information is required. Your display name is auto-generated (e.g., “Anxious Debugger”). Section 7 lists every cookie the Service sets.

5. Data Redaction

You choose one of three redaction levels before upload, and what gets stripped depends on which one you pick. Standard is the default, and you can preview the redacted result before you submit.

Redaction governs what is stored, not just what is shown. The file you upload is processed to compute your stats and produce the redacted copy, then discarded; nothing beyond what redaction leaves in place is retained. Deleting your data from your profile removes that stored copy.

  • Minimal: API keys and obvious secrets only
  • Standard (default): the above, plus file paths and usernames. Project names and git branch names are kept
  • Paranoid: the above, plus project names, git branch names, URLs, and session IDs

6. How We Use Your Data

  • Display your usage statistics on your personal dashboard
  • Calculate and display anonymous leaderboard rankings
  • Aggregate team statistics for team features
  • Generate competition rankings, and record which season each upload falls in

We do not sell, share, or monetize your data. We do not use it for advertising or profiling.

7. Storage & Cookies

Your data is stored in Vercel Postgres (powered by Neon), hosted in the United States. The Service sets two functional cookies, both HttpOnly, Secure and SameSite=Lax:

  • eb_token: an anonymous session identifier (UUID) that stands in for an account, expiring after 1 year.
  • eb_ref: set only if you arrive through a link carrying a recognised ?ref= source, such as ?ref=hackernews. It stores that one word so we can see which channel brought you, is not overwritten if you later arrive through a different link, and expires after 30 days.

Deleting your data from your profile page clears both. Dismissing the cookie notice also records that choice in your browser's local storage (eb_cookie_consent) so the notice does not reappear. We use no advertising cookies and no third-party cookies. Page views are measured separately and without cookies, described in section 9.

8. Sharing & Your Rights

Leaderboard rankings display your anonymous display name and aggregated statistics only. Share links expose only the data you chose to make public. Team membership is visible to other team members.

  • Data deletion: Delete all your data at any time from your profile page.
  • Data portability: View your uploaded data in your dashboard at any time.
  • Opt out: Stop using the Service and delete your cookies to disassociate from your account.

9. Third-Party Services & Children

We use Vercel (hosting), Neon (database), and Vercel Web Analytics (page view measurement). Vercel Web Analytics sets no cookies. For each page view it records the time, the URL and its route pattern, the referring site, filtered query parameters, an approximate location derived from the request (country, region, city), and your device type, operating system and browser version. Visitors are counted using a hash derived from the incoming request rather than a stored identifier, and that session is discarded after 24 hours. Vercel states that it collects no identifiers that would link your visits here to your activity on other websites. These services have their own privacy policies. We do not share user-identifiable data beyond what is necessary for the Service to function. The Service is not directed at children under 13.

10. Deleting your data, and getting in touch

Delete everything from your profile page. The control there removes your account, your uploads, your earned achievements, and your team memberships, and it recalculates the leaderboard so you are off it straight away. You do not need to ask us, and we cannot be slow about it.

If you cannot reach that control, or you want to know what we hold rather than remove it, email privacy@existentialburn.com.

We may update this policy. Significant changes will be noted here with a new effective date.

Last updated: August 11, 2026

PRIVACY DIVISION