Overview
We built YoloSesh to score and rank builder activity using metadata only. We do not collect prompt text, source code, diffs, file paths, clipboard contents, or repository contents for analytics. We do not use prompt contents to train models — we do not have prompt contents.
Information we collect
Account and sign-in. When you sign in with GitHub, we receive profile and email data allowed by the OAuth scopes you grant (for example display name, avatar, and email addresses GitHub shares). We store employer/company from your GitHub profile for your account; it is shown publicly only if you opt in.
Usage metadata (from the app). After each session, the app sends compressed usage reports so we can score the leaderboard. This includes token counts, provider-reported cost, model and provider identifiers, tool-call counts and tool names, programming language tags (from an allowlist, not paths), plugin and automation ids, install and run counts, ship stats (commits, PRs, line counts — not diffs), coarse presence heartbeats, sign-in events, and timestamps. Prompt metadata is limited to aggregates such as counts and average character lengths — never the text of prompts.
What we do not collect in analytics. We do not put email addresses into analytics event streams. We strip forbidden fields (including prompt, code, diff, path, and secret-like keys) before storing event metadata.
Venice. Usage routed through Venice is excluded from tracking and leaderboard scoring.
Website. Standard hosting logs and security data from our providers (below) may include IP addresses and request metadata for the site and API.
How we use information
We use data to operate YoloSesh, enforce sign-in and entitlement gates, show leaderboards and badges, improve reliability, prevent abuse, and communicate with you about the service. We do not sell your personal information.
Sharing and subprocessors
We use service providers that process data on our behalf, including Cloudflare (Workers, D1, R2, and related infrastructure), Vercel (website hosting), GitHub (authentication and identity), OpenRouter (when you choose to call models through your own account), and Apple (Mac app distribution and notarization). They may only use data as needed to provide their services to us.
Retention
Analytics events used for scoring are retained for about two years (730 days), then deleted automatically. Support email and tickets may be kept for up to about one year after handled, per our retention settings. Auth tokens and short-lived codes expire on shorter schedules.
Security
We use industry-standard measures including encrypted transport, access controls, and signed entitlement passes for the desktop app. No system is perfectly secure; report concerns to jesse@leadmagic.io.
Your choices
You can opt out of public leaderboard display, control employer visibility, and sign out at any time. You may request access or deletion of account data by contacting us; some logs may persist briefly in backups or provider logs.
Referrals
If you use a referral link, we record which account invited you so we can grant access rules described on the site (for example one successful invite unlocking access for the inviter).
Children
YoloSesh is not directed at children under 13, and we do not knowingly collect personal information from children.
International users
We operate from the United States. By using YoloSesh, you understand that data may be processed in the U.S. and other locations where our providers operate.
Changes
We will update this policy when practices change. The “Last updated” date at the top reflects the current version.
Contact
Privacy questions: jesse@leadmagic.io.