Plain statement first: Anthropic hosts your board, inside your own Claude account. The maintainers of this project have no account on it and this build sends them nothing from it. Two optional things can leave your machine, and you choose both.
| Place | What is there | Who controls it |
|---|---|---|
| Your board's database on claude.ai | Your profile, items, dates, notes, leave, conditions, contacts, notices | You, and anyone you share the page with. Anthropic hosts it under its consumer terms. |
| Your Claude conversations and Claude Code transcripts | Whatever you and the assistant said, including anything you pasted | You, through your Claude account settings; Anthropic's retention rules apply |
| This folder on your laptop | my/board.json: the board URL, pack, version, and the date it was made. my/receipt.json: your count choice and its random install id. my/pending.json: the same pointer fields plus a setup stage, only while a setup is unfinished. None of them holds your name, dates, grade, path, leave, or anything medical. | You |
| Your browser | Tab and filter preferences; the plan itself only if you used the board as a local file before publishing | You |
| The Ask box | When you press Ask, the page sends your board (items, notes, dates, condition list, regulation excerpts) to Claude on your account for that one answer | Your account |
The board page itself is a generic template. A copy of the page carries none of your data.
We do not restate Anthropic's privacy or training settings here because they change; read them in your Claude account settings before you put medical detail on the board.
Nothing unless you say yes.
service, path (resign, retire, eas), grade (the grade group), version (the product version), and id, a random install id so a repeated setup is not counted twice. The install id is random, is kept in my/receipt.json in your folder, and does not link to your name or account. Your choice is saved in that file before anything is sent, so a retry or a reset reuses the same id and you are not asked again. The endpoint also records the time it received the count and a salted hash of the internet address it came from, used for rate limiting; it keeps no name, date, unit, or board data. Say skip and nothing is sent.Both land in a database the maintainer reads only in aggregate. The welcome page carries Cloudflare Web Analytics, a cookieless page counter that records no personal data; the lesson carries no analytics script at all.
{"ok":true} means nothing remains under that key. The study token is the only key to a lesson result, and the install id is the only key to the count.For a lesson result, put your study token in place of YOUR-STUDY-TOKEN:
curl -X POST "https://vfozrzohrdrbohjqkghk.supabase.co/functions/v1/ingest" -H "content-type: application/json" -d '{"kind": "delete", "token": "YOUR-STUDY-TOKEN"}'
For the count, put the installId from my/receipt.json in place of YOUR-INSTALL-ID:
curl -X POST "https://vfozrzohrdrbohjqkghk.supabase.co/functions/v1/ingest" -H "content-type: application/json" -d '{"kind": "delete", "id": "YOUR-INSTALL-ID"}'
The address is ingest_url in config.json. If either fails, email [email protected] with the token or the id and the maintainer deletes the row by hand.
Other people's personal information, anything classified or controlled unclassified, a password, a CAC PIN, a Social Security number. The assistant will not ask for them and you should not paste them.
This page is rendered from PRIVACY.md in the repository, pilot build 0.1.0.