Privacy Policy
Last updated 7 October 2026
This policy explains what Landauer Gap collects, why, and what you can do about it. Landauer Gap is run by Bharat Sharma ("we", "us").
What we collect
| Data | Why | Where it is kept |
|---|---|---|
| Email address, and your password hash if you use one | To create your account and sign you in | Supabase Auth |
| Your GitHub or Google profile email, ID, name and profile picture address, if you sign in with them | To sign you in and show your name and picture in the app | Supabase Auth |
| The display name and preferences (theme, currency, grid) you set in Settings | To show them on every device you use | Supabase Auth |
| Runs you choose to save: calculator inputs and results | To show them back to you | Supabase database |
| API keys: name, first 12 characters and a SHA-256 fingerprint | To recognise your key. The full key is never stored. | Supabase database |
| Counts of your API calls per month and per minute | To apply plan limits | Supabase database |
| Leaderboard measurements you share: model, hardware, energy per token, speed, average power, joules version | To publish the leaderboard | Supabase database |
Runs you track with joules --track (or joules proxy --track): project name, a short label (the program and script name, or your own label), hardware, time, energy, carbon, cost, operations and Landauer gap | To show your Tracking page and build energy reports | Supabase database |
| Teams: the team name, who is in it, invite email addresses, and which member's key sent each team run | To run team workspaces | Supabase database |
| Alerts: your alert rules, the webhook address you give, and a record of each alert and whether it was delivered | To tell you when a run uses much more energy than usual | Supabase database |
| Stripe customer ID, subscription status and renewal date | To run Pro billing | Supabase database and Stripe |
We do not collect card numbers. Payments are handled by Stripe, which has its own privacy policy.
joules sends nothing unless you ask it to: --share (or joules share) sends the leaderboard fields above, and --track sends the tracked-run fields above. It never sends prompts, outputs, command arguments, inline code, host names, file paths or file contents.
Teams. If you join a team, its members see your email address, your role, when you joined, and the team runs sent with keys you made. Your own runs, keys and settings stay private to you.
Alert webhooks. If you give a webhook address (for example a Slack or Discord channel), we send each alert to it: the project, the run's label, its energy and the usual energy. That service then handles the message under its own terms.
What we do not do
- No advertising, and no selling or renting of your data.
- No analytics or tracking scripts, and no third-party cookies.
- The leaderboard never shows names or emails. It only shows medians, run counts and the number of people. The public home page shows the three lowest-energy rows of it, the same way.
Your browser
The site uses your browser's local storage for your sign-in session, theme, calculator inputs, dismissed tips and a team invite link you opened before signing in. Nothing in local storage is used for tracking.
Services we use
| Service | What it does for us |
|---|---|
| Supabase | Database and sign-in |
| Vercel | Website and API hosting. Vercel keeps standard request logs (IP address, browser) for a short time. |
| Stripe | Payments |
| jsDelivr | Serves the sign-in library |
| Google Fonts | Serves the typefaces. Your browser fetches them from Google. |
| GitHub and Google | Show your profile picture, if you signed in with them. Your browser fetches it from them. |
These providers process data only to run their part of the service.
How long we keep data
- Your account data is kept until you delete your account.
- Usage counters older than the current month are kept only as monthly totals.
- Revoked API keys are kept as records, without the key itself, so that old usage still adds up.
- Billing records are kept as long as tax law requires.
Your choices and rights
- Saved runs: delete them on the Saved runs page.
- Tracked runs: remove them on the Tracking page.
- API keys: revoke them under Settings → API keys.
- Leaderboard measurements: remove them on the Leaderboard page.
- Teams: leave a team, or as its owner close it, under Settings → Team. Alerts: switch them off under Settings → Alerts.
- A copy of everything: download it under Settings → Your data.
- Your whole account: delete it under Settings → Delete account. Your saved runs, tracked runs, keys, usage, measurements, alerts and any team you own are deleted with it, and a paid subscription is cancelled first.
- Copy, correction or deletion: depending on where you live (for example under the GDPR, the UK GDPR, PIPEDA or the CCPA), you can ask for a copy of your data, a correction, or deletion. Contact us as below and we will reply within 30 days.
Children
The service is not meant for anyone under 16.
Changes
We will post changes here and update the date below.
Contact
Open an issue at github.com/bsharma173860-oss/d3-research. For anything private, ask there for a private contact and we will reply by email.