Privacy Policy
Version 2026-09-11. Every factual claim below describes what the code actually does today — where something is planned rather than built, it says so.
The service is operated by WattScope Pty Ltd (ABN 26 702 095 743), Victoria, Australia. That company decides what is collected and holds everything described below, and we means it throughout.
1. What we hold about you
All of it is held for one purpose: to estimate the carbon footprint of the AI usage you report, attribute it to your organization and to a project, and report it back to you. We do not use it to build a profile of you, we do not train any model on it, and we do not use it for anything unrelated to producing those figures.
To identify you:
- Your email address, retrieved from our identity provider once, when you register.
- Your identity provider's subject identifier for you.
- Your display name, if your identity provider gives us one — some sign-in methods do not, and we do not invent one.
- When you last signed in. Not what you did afterwards: this records the moment a session started, nothing about the session.
- Your workspace, your role in it, and which workspace you last had selected.
- A dated record of which versions of these documents you accepted.
For each unit of AI usage reported to us:
- Token counts, the model identifier, and the region assumed for grid intensity.
- The energy and emissions figures we calculated, and the version of the factor table that produced them.
- A project name, a session identifier, and timestamps.
- Where it came from — self-reported, reconstructed from a chat conversation's shape, reconstructed from your own claude.ai data export, vendor billing data, or an instrumented client — and an identifier for the piece of work the record stands for, which is how we avoid counting the same piece of work twice. An instrumented client supplies the vendor's own request id and that is what we keep. The chat and export paths have no such id, so we derive one ourselves: for an export it is the message's own identifier, and for a chat it is a hash, never the words you wrote.
- An optional free-text note, if whoever reported the usage chose to attach one.
2. What we deliberately do not hold
We do not store your prompts or the model's responses. The instrumented-client path redacts them before they leave your machine, and our receiver rebuilds each record field by field from a fixed allowlist — anything not on that list is discarded at the edge rather than stored and filtered later. If you use the chat estimate tool, only character counts and a one-way digest of the conversation's opening words are recorded — never the words themselves. If you upload a claude.ai data export to bring older usage into your history, we do receive it: the file is read into memory to count what it contains, is never written to disk, and is discarded once the counts are stored. Nothing you or the model wrote — from any of these paths — is retained.
Telemetry from instrumented clients carries the end user's email address in plain text. We do not keep it. It is replaced at the ingest edge with a keyed digest, scoped per organization so the same address in two organizations produces two unrelated values, and today not even that digest is stored — usage from that path is attributed by the ingest token that sent it. When per-user attribution is built, the digest is what will be stored; the address itself still will not be.
We use no analytics, no advertising, and no third-party tracking. There
is one cookie: the session cookie that keeps you signed in. It is
HttpOnly, so scripts on this page cannot read it, and it
expires within the hour.
3. Who else processes it
- Stytch — authentication and email delivery for sign-in links and invitations. They hold your email address and your sign-in events.
- Railway — hosting and the database this service runs on. If you upload a data export, the file passes through Railway's infrastructure in memory on its way to being counted; it is never written to disk there or anywhere else.
We do not sell your data, and we do not share it with anyone else unless the law requires it — in which case we will tell you, unless we are forbidden from doing so.
Where it is processed. Both are United States companies, and neither offers hosting in Australia — so your data is stored and processed outside Australia, on infrastructure in the United States, the European Union or Singapore. Which of those applies can change if we move the deployment. Ask us and we will tell you where it is running at the time you ask.
4. Who can see it
Administrators of your workspace can see usage reported by every member of it, including yours, in reports and exports. Ordinary members see only their own. Nobody in another workspace can see any of it: every query that serves a customer is scoped to one organization, and no customer-facing view crosses that boundary.
WattScope Pty Ltd operates the service and holds the database, so we are able to see everything in section 1. We look at it only to operate the service, to answer a request you make — a support question, a deletion — or to keep it secure: never to profile you, and never to compare one workspace with another for any commercial purpose. The operator page we use day to day shows the list of accounts and workspaces and service-wide totals; it does not show any single workspace's usage.
5. How long we keep it
Usage records are kept for as long as your organization exists, because a footprint history is the product. Deleting an organization deletes its usage records with it. If you delete your own account instead, your usage records are deleted with it too — even where your organization continues without you, in which case its remaining administrators will see its historical total drop by what you contributed. Your consent records are deleted with your account as well — keeping a record of consent for someone who has asked to be forgotten would defeat the reason for keeping it.
6. What you can ask for
You can export your organization's usage totals from the dashboard, as CSV, at any time and without asking us — see the Terms of Service for exactly what that export contains. You can ask us to delete your account and its data; an operator processes the request, and the section above says precisely what is removed. We do not yet have a way to correct a stored record — if something in your history is wrong, tell us and we will look at what can be done. Depending on where you live, you may also have the right to object to processing or to complain to a data protection authority.
7. Changes to this policy
Each revision has a version, and you will be asked to accept the new version the next time you sign in. Continued use is not treated as agreement.
8. How to reach us
Write to support@wattscope.com.au — for anything in section 6, from the address on the account. For security vulnerabilities, write to that same address and see the support page for what to include and what we will do about it.
The entity answerable for all of it is WattScope Pty Ltd (ABN 26 702 095 743), registered in Victoria 3173, Australia. Email is the route that reaches us. If you need the registered office in full — to serve a formal notice, say — ask and we will give it to you.
See also the Terms of Service (version 2026-09-08.1), whose section 2 explains why every figure here is an estimate rather than a measurement.