centrailYancy Collective LLC
Sign inStart free
Trust / Privacy policy

Privacy policy

What we collect, what we store, and what never leaves your machine.

Centrail is built so the sensitive parts never leave your machine.

What we collect

  • Per-event token counts, model names, and timestamps
  • Optional: commit shas, line counts, branch names, and repo names (for attribution and ship status)
  • Your account email (for sign-in)

What we never collect

Source code, prompts, completions, git diffs, or commit messages.

Public aggregate numbers

We publish running site-wide totals — tokens tracked, and the estimated energy, water, and CO₂ behind them — summed across all accounts (including imported chat history) and shown on our homepage. These are single combined figures: they contain no per-user, per-project, or otherwise identifying data, and nothing about you can be recovered from them. Deleting your data removes your share from future totals.

Storage & deletion

Usage is stored in your private account. You can wipe all events, sources, and identities from your Profile at any time, and revoke any paired machine's token.

Teams

Joining a team is opt-in and consent-first. When you accept a team invite you see — and must accept — exactly what your team will get: your team will see only the work you assign into its team projects — usage totals, model mix, commits, and environmental footprint for that work — never see your folder paths, repo names, personal projects, unassigned usage, prompts, or code. You can leave at any time, which removes your data from all team views.

Nothing from before you joined a team ever appears to that team — unless you choose to include a folder or repo's earlier history when assigning it to a team project (Settings → Projects; off by default, and re-saving unchecked stops sharing). Sharing still reveals only the work assigned to that team project.

Team projects are plain names your team admins create (for example "Platform"). You choose which of your folders or repos count toward each one, and that mapping — the folder paths and repo names themselves — stays visible only to you; your team sees only the team-project totals. Work you haven't mapped into a team project is invisible to the team — it never appears in team totals, dashboards, or the public pledge card.

Team dashboards are live aggregations over current members only. If you leave a team (or are removed), that removes your usage from all team views immediately — there is no retained team copy. Everything you track remains your personal data that you chose to share; team visibility policies (set by team admins) can further limit per-member breakdowns, down to aggregate-only. A team's public pledge card shows the team name, member count, and aggregate footprint only — never member names or per-member numbers.

Monthly recaps

Nothing about your month is public unless you share it. The "Share my month" card is created only when you explicitly choose to share, contains a frozen snapshot of that month's totals (tokens, estimated spend, commits, footprint) — never your folder paths, repo names, or project names — and you can stop sharing at any time, which takes the card offline. The monthly recap email is private and shows only your own data; it's on by default and every email carries a one-click unsubscribe link, with the same switch available under Settings → Emails.

A team's billing status never affects your personal account or data — non-payment pauses the team dashboard, nothing else.

Questions about data handling? We're glad to help — email support@centrail.org anytime.