Trust note 02

Privacy

Usage evidence should not require handing your work to another company.

Launch data

What Burnbook collects

Burnbook accepts timestamps, bounded model and assistant identifiers, session and message identifiers, and provider-reported token counters. It also stores account, device, consent, integrity, and aggregate profile records needed to operate the service.

Optional sponsorship

Burnbook never stores card data

Stripe-hosted Checkout processes sponsorship payments. Burnbook stores Stripe object identifiers, exact payment/refund/dispute amounts, placement state, and aggregate impressions and clicks. It does not store card numbers or fingerprint viewers for promotion analytics.

Hard boundary

What Burnbook does not collect

Launch ingestion has no fields for prompts, responses, chain-of-thought or reasoning content, source code, file paths, diffs, commands, tool payloads, repository content, MCP credentials, or secrets. It may record a provider-reported reasoning-token count, never the reasoning itself. Unknown fields are rejected rather than ignored.

Your controls

Public is reversible

After your first successful sync, your profile is public by default and the product explains that before authorization. Leaderboard participation always requires a separate opt-in. You can unpublish your profile, leave the leaderboard, revoke a device, export your information, or delete your active Burnbook account data. Deletion immediately makes existing browser sessions and device credentials unauthorized, including sessions open on another device.

Private analytics retain exact totals; public heatmaps use coarse activity levels rather than exact daily values.

Deletion and retention

Active data is deleted before backup copies expire

Account deletion immediately removes your active account, evidence, snapshots, device credentials, settings, and public projections. It does not remove files stored locally on your devices.

The managed production database retains encrypted point-in-time restore history for seven days, the maximum available on Burnbook's current Neon plan. Backup copies are not available through the product and are used only for disaster recovery. After account deletion, an older copy can therefore remain in that restore history for no more than seven days before it expires.