Skip to main content

Privacy

Privacy policy

Version 2026-08-21, effective 21 August 2026. AI Stats parses your AI exports inside your browser and stores only normalized statistics. This policy states every category of data the service actually keeps, who processes it, how long it is held, and how to export or delete it.

Imported statistics

Provider, timestamps, durations, prompt and response counts, tool and agent counts, tokens where the source reports them, model names, project aliases, and a quality label on every metric.

Data that is never persisted

Raw prompts, responses, source files, attachments, local paths, and transcripts are discarded after transient browser parsing. The service has no file storage.

Account and sign-in records

Your name, email address, and a hashed password, plus one record per signed-in device holding its IP address and browser user agent. You can revoke any of them yourself.

Deletion and export

Settings gives you a complete JSON or CSV export and a self-service account deletion that removes your account and every record linked to it.

Who we are and how to reach us

Novus AI Stats is operated by Novus Stream Solutions, a sole proprietorship trading as Novus Stream Solutions in London, Ontario, Canada, at aistats.novusstreamsolutions.com. Novus Stream Solutions is the controller for the personal data described on this page. As a Canadian operator we handle personal information in line with PIPEDA and applicable Ontario law.

For any privacy question or request, including PIPEDA access or correction requests, email aistats@novusstreamsolutions.com. Requests about a specific account must come from the address registered to that account, because there is no other way to verify who is asking. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada.

Three classes of data, kept apart

Almost every privacy question about this product resolves once you separate three things.

  • Account data: your name, an email address, a password hash, role, session records, and preferences. Needed to sign you in and to scope every query to you.
  • Normalized statistics, the output of an import: provider, timestamps, prompt and response counts, tool and agent counts, model names, token fields where the source reports them, durations, project aliases, and the quality label attached to each metric. This is what the dashboard reads.
  • Raw source content: prompts, responses, code, attachments, file names, and local paths. This class is parsed in your browser and then discarded. It is not transmitted, not written to disk on the server, and not held in a queue or a log.

What an import actually sends

Selecting files does not upload them. A worker thread in the browser expands archives, detects the format, and reduces the content to counts, timestamps, and identifiers. The preview shows what was found. Only on confirmation are the normalized statistics transmitted, and the browser then releases the parsed content.

Two privacy modes control how much of that reaches the server. Stats-only sends numbers and identifiers with no human-readable text from your conversations. Stats-with-titles additionally includes session titles, because some people want to recognise their own sessions in a list. Titles are the only conversation-derived text that can ever be stored, and only when you choose that mode.

Repository names, where a coding agent reports one, are stored as a one-way hash rather than the name itself. Session notes and project aliases are stored exactly as you type them, so treat those two fields as text you are choosing to save to your account rather than as a private scratchpad.

Duplicate detection works on stable session identity and normalized content hashes rather than on the files themselves, which is why re-importing an overlapping export does not double your totals and does not require keeping the file.

Account, sign-in, and security records

AI Stats is a signed-in, multi-user product, so it necessarily keeps more than a static site would. The list below is complete.

  • Account record: your name, email address, a hashed password (never the password itself), an email-verified flag, your role, ban state, and creation and update timestamps.
  • Sign-in sessions: one record per signed-in device holding a session token, creation and expiry times, the IP address the request arrived from, and the browser user agent string. IP addresses are read from the cf-connecting-ip, x-real-ip, and x-forwarded-for headers set by the hosting and CDN layer. Settings, then Security and devices, shows these records and lets you revoke them.
  • Profile and preferences: display name, handle, avatar URL if set, timezone, locale, week start day, privacy mode, default share visibility, notification preferences, and the flags used for manual password recovery.
  • Terms acceptance: the terms version and privacy version you accepted at sign-up, with the acceptance timestamp.
  • Security audit log: a record of security-relevant actions such as password changes and session revocations, holding the event type, the affected record, a small metadata object, and a timestamp.
  • Rate-limit counters: request counts keyed by a scope name plus your account id, used to stop brute force and abuse. They hold no content and reset when their window elapses.
  • Import bookkeeping and derived records: import jobs with file counts, a file fingerprint, per-file summaries and outcome counts, plus the daily metrics, aggregates, projects, tags, achievements, recaps, share snapshots, and in-app notifications built from your sessions.

Cookies, analytics, and advertising

Necessary cookies are set by Better Auth to keep you signed in and to protect requests against cross-site request forgery. They are HTTP-only, SameSite=Lax, and Secure in production. Your cookie choices are not themselves a cookie: they live in this browser's local storage under the key ai-stats-consent-v1, and no copy is sent to or kept on our servers. Your appearance and reduced-motion choices are stored the same way, on your device only.

Google Analytics 4 is the only analytics product on this site and it is strictly opt-in, in every country, with nothing pre-ticked. A first-party Consent Mode command queues a denied analytics-storage default during document setup, but until you allow the analytics category no Google Analytics script is requested and no measurement cookie is written. Global Privacy Control overrides a stored analytics grant. When you do allow it, Google Analytics runs across the whole site, including signed-in pages, and receives the page address, the referrer, device and browser characteristics, and an approximate location that Google derives from your IP address. Because it runs on signed-in pages, the page address it receives can include the identifier of one of your sessions, projects, or share links. It never receives your prompts, responses, transcripts, session titles, project names, or email address.

Adsterra may show labelled ad units on eligible public content pages. In the EEA, United Kingdom, and Switzerland it loads only after you allow advertising; elsewhere it may load by default until you opt out. Declining reloads the page without Adsterra if its script already ran. Signed-in analytics screens, legal, consent, security and accessibility pages, the API, and public share pages carry no ad code.

AI Stats does not use Google AdSense, Infolinks, Vercel Analytics, Vercel Speed Insights, session recording, heatmaps, fingerprinting, or a product analytics SDK. Google Analytics and Adsterra are the only third parties allowed to execute script through this site, under the regional and category controls above.

Sharing

A share page is a snapshot, not a live window into your account. It reads from a stored copy of the fields you selected, it is unlisted and noindex by default, and it can be given an expiry or revoked outright. Revoking removes access to the snapshot rather than merely hiding a link, and public share pages never contain raw conversation content or internal database identifiers.

Share snapshots belong to your account, so deleting the account deletes them and their public links stop resolving. What deletion cannot reach is a copy that has already left the service: a file you exported yourself, or a page someone screenshotted or archived while it was public. If a share is sensitive, revoke it explicitly rather than relying on account deletion.

Where your data is processed

Three providers are involved and no others.

  • Turso (libSQL) hosts the application database, holding every record described above.
  • Vercel hosts and serves the application and keeps platform request logs under its own retention schedule. Vercel's analytics products are not enabled.
  • Google provides opt-in Google Analytics 4. Adsterra provides advertising under the regional consent and opt-out rules above.
  • These providers may process data outside your country, including in the United States. Where required, transfers rely on the providers' standard contractual clauses and equivalent safeguards.

Why we are allowed to process this data

Where data protection law asks for a lawful basis, these are ours.

  • Performance of a contract: account data, imported statistics, and everything derived from them exist so the service you asked for can work.
  • Legitimate interests: sign-in session records, the security audit log, and rate-limit counters exist to keep accounts secure and to prevent abuse.
  • Consent: analytics and advertising only. You can grant or withdraw either at any time without losing access to any feature.

Retention and your controls

Normalized statistics are retained while the account exists, because they are the product. Raw source content has no retention period because it is never stored. Individual sessions, projects, shares, and imports can be removed at any time from within the app.

Sign-in session records are removed when you revoke them, when you change your password (which revokes every other session), and when you delete your account. Expired session rows and security audit events are currently retained for the life of the account: no scheduled purge job runs yet. That is stated plainly rather than dressed up as a policy, and when a purge job ships this section will name the exact windows. Rate-limit counters reset when their time window elapses.

  • Access and portability: Settings, then Data export, produces a complete JSON export of your account records and every normalized session, or a CSV of all sessions. Exports exclude password hashes and auth secrets and are limited to ten downloads per hour.
  • Rectification: display name, timezone, week start, privacy mode, sharing default, and notification preferences are editable in settings. For anything you cannot change yourself, contact support.
  • Withdrawing consent: use the Cookie settings control in the site footer or in settings. Withdrawing is exactly as easy as granting.
  • Control over devices: review active sessions with their IP address and browser, revoke any one of them, or revoke every other session at once.
  • Objection, restriction, and complaint: email support to object to or restrict processing, or to ask anything about this policy. People in Canada may contact the Office of the Privacy Commissioner of Canada. If you are in the UK, the EEA, or another region with a data protection authority, you may also complain to it.

Deleting your account

Deletion is self-service and does not require contacting support. Open Settings, then Security and devices, scroll to Delete account, enter your current password, type DELETE in the confirmation field, and submit. Deletion is removal, not deactivation.

Deleting the account removes the account record, and every record linked to it goes with it: your profile and preferences, sign-in sessions, stored credentials, source connections, import jobs and batch receipts, staged import rows, AI sessions and their event summaries, projects and milestones, tags, daily metrics and aggregates, achievements, recaps, share snapshots, in-app notifications, notification preferences, the security audit log, and your terms-acceptance record.

Two things survive, and neither contains readable content: anti-abuse rate-limit counters keyed to your former account id, which reset when their window elapses, and hosting platform request logs held by Vercel under its own retention schedule. Deletion is immediate and cannot be undone, so download your export first if you want a copy.

Security

Traffic is served over HTTPS with HSTS in production. A content security policy restricts executable script to the application itself, Google Analytics, and the measured Adsterra delivery hosts. Session cookies are HTTP-only, SameSite=Lax, and Secure in production. Passwords are hashed, must be at least twelve characters, and changing a password revokes every other active session. Sign-in, sign-up, password change, account deletion, and export endpoints are rate limited. Authorization is enforced on the server; hiding a link is never the boundary.

No online service can promise perfect security. If you believe you have found a vulnerability, email support with high-level reproduction details first, and do not send raw exports or secrets.

Children

AI Stats is not directed to children and is not intended for anyone under 16. We do not knowingly create accounts for children. If you believe a child has created an account, contact support and it will be removed.

Email and changes to this policy

The application sends no email. There are no verification emails, no automated password-reset emails, and no marketing email; notifications are in-app records only. Account recovery is handled manually by a person after you write in from the registered address. Your email address is therefore used to identify your account and to answer support requests, and for nothing else.

This policy is versioned by date and the current version is 2026-08-21. The version you accepted at sign-up is recorded against your account and is included in your data export, so you can always see which text you agreed to. Material changes are published here with a new version and effective date before they take effect.

Privacy policy version 2026-08-21, effective 21 August 2026. Questions, requests, and complaints go to aistats@novusstreamsolutions.com. See also the terms of service and the cookie and consent policy.