What we hold, and how to get rid of it.

Two kinds of thing, and they are worth keeping apart: what your machine sends when you publish, and what you type into a form afterwards. Neither is bought, looked up or inferred.

What your machine sends

The analysis runs on your computer. What reaches us is the shape of your sessions: session records, event stream, commit metadata. Never your code, your prompts, file names, commit messages, transcripts. Sent, but hashed on your machine first so the values are gone before the upload is built: commands, file paths, project id, author email, branch names.

A hash is not anonymity and this page will not pretend otherwise: a short list of candidate strings can be hashed and compared. It is listed separately from “never” because calling it never would be false.

You can check all of this before anything is uploaded. builder publish prints the exact counts it is about to send along with three real sample events, and stops to ask. Prompts are read from the terminal directly, so piping the installer into a shell cannot answer them for you, and --yes cannot answer that last one.

What you type

Shown on your profile, to anyone: handle, public name, bio, beside your score, your rank, your archetype, the coding tools you use and the evidence counts behind the number. Your public name is usually your first name, and it is yours to change to anything you want shown.

Shown only if you choose to: github (optional), x (optional), instagram (optional), linkedin (optional). The ones you give when you claim a score, or when you bring an earlier score onto your sign-in, show on your profile for anyone to follow — the form says so where you type them. After that, each one shows only while “show on my profile” is ticked for it; untick it and it is private again. Nothing else above or below becomes public this way.

Held but never shown on your profile: full name (required), email (optional), company (optional), website (optional). These are not on the page, not in the public API, and not on the shareable card. The guarantee is structural rather than a promise about our conduct: the query that builds every public surface does not select them, and the one query that reads your socials returns only the ones you ticked.

We do not look you up. There is no data vendor here, nothing is scraped from LinkedIn or anywhere else, and no profile is built for anyone who leaves a field empty. If you tell us where you work, we know; if you do not, we do not. Your X and LinkedIn are held here only because you typed them into a box.

Two boxes are prefilled with a guess, and a guess is not a record: nothing is stored until you have seen it and saved it, and clearing one leaves nothing behind. Give a work address and the company box is filled in from its domain, which happens on our own server with no request to anybody. Connect GitHub and, if your GitHub profile publishes a website or an X handle, those two boxes are offered to you filled in — read from your own account, with your own authorization, on a request we were already making. We ask GitHub about nobody but you, and only when you connect it.

Signing in is optional. If you sign in to the website, we keep the address you signed in with so we can mail you sign-in links. It is not shown anywhere, it is not your profile’s email above, and it is never given to a hiring company. Signing in does not by itself give you a profile: a score is still claimed from your terminal, and it is attached to your sign-in only when you finish that claim (or open builder profile) in the signed-in browser.

Hiring companies, and what they pay for

This is the part that is a sale, so it is worth being exact about. A company that pays us can be given every held field listed above, including the socials whether or not you chose to show them, so that they can contact you about work. That sentence used to name the fields a second time, which is how a page like this goes quietly out of date: the list above is generated from the same source the database is, and this one was typed. Your score and your public name are free for anyone to look at; reaching you is not.

Only if you said yes. The claim form asks, in those words, and you can change the answer at any time with builder profile. Turn it off and nobody can be given anything, ever — your profile, score and rank stay exactly as they are. Builders who claimed before this existed were never asked, so they are all switched off until they say otherwise.

We do not sell your score, your evidence or anything your machine sent. There is no advertising here, and no third party receives any of this except a company you allowed to contact you.

GitHub

Connecting a GitHub account is optional, and it is not shown on your profile unless you tick it — it sits with the socials above. We ask GitHub for no permissions at all and read only what is already public: your public repositories, your organisations and the languages you use. The access token is discarded inside the request that obtains it and is never written down. It is a link on your profile and nothing more — it does not sign you in, and nothing in the product treats it as proof of who you are. Remove it any time with builder profile disconnect.

Addresses, cookies and models

Your IP address is never stored. It is put through a keyed hash with a key that rotates daily, and only the result is kept, for rate limiting; once the day’s key is gone the value cannot be turned back into an address.

Visits to this site are counted with DataFast, in its cookieless mode. It sees the page you opened, the site that sent you, your browser, device and screen size, and a country worked out from your address, and it tells one visit from another with an anonymous hash of that address whose key changes daily. It never sees a query string or anything after a #: those are removed on our server before anything is sent, so sign-in links and email addresses never reach it. It sets no cookies. A content blocker stops it, and so does running localStorage.datafast_ignore = "true" in your browser’s console.

There are two cookies, and each exists only once you sign in: one if you sign in to your profile, one if a hiring company signs in to hire. Each holds a signed session and nothing else, and signing out removes it. You never need to sign in to publish, claim or rank. Nothing is sent to Claude, to GPT or to any model, ours or anybody else’s — your score is arithmetic, and nothing we hold contains your work.

How long it is kept

A score that is published and never claimed is deleted after 30 days, automatically. A claimed profile is kept until you remove it.

Removing it

From the machine you published on, these take effect immediately:

  • builder forget — deletes this machine’s evidence and score. If it was the last machine on your profile, the profile goes too: handle, address, name, company, website, socials, bio, GitHub link and rank history. A sign-in account, if you made one, stays unless you ask us to remove it at the address below.
  • builder unlink — takes the machine off your profile and keeps the evidence.
  • builder profile disconnect — removes a connected GitHub account on its own.
  • builder profile set --not-contactable — stops any company being given your details, without removing anything else.
  • builder profile set --company "" — clears one optional field without touching anything else. Your name cannot be cleared, because it is required.

If that machine is gone — reimaged, lost, thrown away — none of the commands above can reach it, because each of them proves who you are using the machine itself. That case is handled by hand, and this deployment has not published an address for it yet.

Same address for anything else on this page, including a profile you believe should not be there.

Privacy and removal · Macintosh 128K photograph by Grm wnr, from an All About Apple Museum original, CC BY-SA 3.0, modified. Departure Mono and Overused Grotesk, SIL OFL. Homebrew logo © Homebrew contributors, BSD 2-Clause. Windows is a trademark of Microsoft Corporation. Claude is a trademark of Anthropic, PBC. X and GitHub marks are used under their owners’ brand guidelines to link to a profile.