kTLandauer Gap

Privacy Policy

Last updated 7 October 2026

This policy explains what Landauer Gap collects, why, and what you can do about it. Landauer Gap is run by Bharat Sharma ("we", "us").

What we collect

DataWhyWhere it is kept
Email address, and your password hash if you use oneTo create your account and sign you inSupabase Auth
Your GitHub or Google profile email, ID, name and profile picture address, if you sign in with themTo sign you in and show your name and picture in the appSupabase Auth
The display name and preferences (theme, currency, grid) you set in SettingsTo show them on every device you useSupabase Auth
Runs you choose to save: calculator inputs and resultsTo show them back to youSupabase database
API keys: name, first 12 characters and a SHA-256 fingerprintTo recognise your key. The full key is never stored.Supabase database
Counts of your API calls per month and per minuteTo apply plan limitsSupabase database
Leaderboard measurements you share: model, hardware, energy per token, speed, average power, joules versionTo publish the leaderboardSupabase database
Runs you track with joules --track (or joules proxy --track): project name, a short label (the program and script name, or your own label), hardware, time, energy, carbon, cost, operations and Landauer gapTo show your Tracking page and build energy reportsSupabase database
Teams: the team name, who is in it, invite email addresses, and which member's key sent each team runTo run team workspacesSupabase database
Alerts: your alert rules, the webhook address you give, and a record of each alert and whether it was deliveredTo tell you when a run uses much more energy than usualSupabase database
Stripe customer ID, subscription status and renewal dateTo run Pro billingSupabase database and Stripe

We do not collect card numbers. Payments are handled by Stripe, which has its own privacy policy.

joules sends nothing unless you ask it to: --share (or joules share) sends the leaderboard fields above, and --track sends the tracked-run fields above. It never sends prompts, outputs, command arguments, inline code, host names, file paths or file contents.

Teams. If you join a team, its members see your email address, your role, when you joined, and the team runs sent with keys you made. Your own runs, keys and settings stay private to you.

Alert webhooks. If you give a webhook address (for example a Slack or Discord channel), we send each alert to it: the project, the run's label, its energy and the usual energy. That service then handles the message under its own terms.

What we do not do

Your browser

The site uses your browser's local storage for your sign-in session, theme, calculator inputs, dismissed tips and a team invite link you opened before signing in. Nothing in local storage is used for tracking.

Services we use

ServiceWhat it does for us
SupabaseDatabase and sign-in
VercelWebsite and API hosting. Vercel keeps standard request logs (IP address, browser) for a short time.
StripePayments
jsDelivrServes the sign-in library
Google FontsServes the typefaces. Your browser fetches them from Google.
GitHub and GoogleShow your profile picture, if you signed in with them. Your browser fetches it from them.

These providers process data only to run their part of the service.

How long we keep data

Your choices and rights

Children

The service is not meant for anyone under 16.

Changes

We will post changes here and update the date below.

Contact

Open an issue at github.com/bsharma173860-oss/d3-research. For anything private, ask there for a private contact and we will reply by email.