Privacy notice
Controller
Carlos Garavito Quispe. Email carlos@cgaravito.dev.
What is stored
When you sign in with GitHub the service stores your GitHub login and
avatar URL from the OAuth profile, and your API key as a hash. The
service never stores the plaintext key: it travels once to /keys in the
60-second aiusage_new_key cookie, which the page deletes
when it shows the key.
The collector sends your machine identifiers and daily token-usage rows with your API key, and those rows are stored under your login.
Cookies
aiusage_oauth_state carries the OAuth state during sign-in.
It is scoped to /auth and expires after 10 minutes.
aiusage_new_key carries the freshly issued key to the
/keys page once. It is scoped to /keys and expires after 60 seconds.
Both are strictly necessary session cookies, HttpOnly and Secure. The service sets no analytics and no third-party cookies.
Public data
Usage summaries are public per login at /api/u/:login/summary. Signing in makes your login's summary readable by anyone with the URL.
Keys
Each sign-in revokes every existing key of your login on every machine and issues a new one.
Deletion and questions
Email carlos@cgaravito.dev to delete your account, your keys and your usage rows, or to ask anything about this data.
Your rights
You can complain to your data protection authority, the Spanish Data Protection Agency (AEPD), at https://www.aepd.es.
Hosting
The service runs on Cloudflare Workers and D1. Cloudflare delivers the requests and may process request data such as your IP address and headers as a processor.