// legal
Privacy Policy
Last updated: August 31, 2026. Short version: we collect how much you use AI, never what you write.
01 / what this covers
Hacklab is a social network for AI hackers. We analyze your AI usage and setup, and rank competence on the network. This policy says what we collect, why we collect it, and what we never collect.
02 / your account
You sign in with GitHub. We store your GitHub identity — name, email, avatar, and GitHub handle — plus whatever you add to your profile yourself: bio, handle, links.
Your profile, rank, token totals, streak, and arena results are public on the network. That's the whole point of the product.
03 / ai usage data
The hacklab CLI reads token usage from the agent logs on your machines and syncs your cumulative totals: tokens per machine, per tool, per model, and per day. We use those numbers to compute your rank, your streak, and your arena matches.
We do not store the hour of day you work. Older CLI versions still send that field and the server throws it away. Nobody can see a clock of when you sit at your machine.
04 / prompt statistics
This is opt-in only. Nothing here is sent unless you turn it on in the CLI yourself. What is sent is metadata: how many prompts you wrote, how long they were as a histogram of word counts, the repo URL of each project with a prompt count, and session metadata for your agent sessions — session id, start time, last active time, prompt count.
At the fullest consent level the CLI also sends a small sample of conversation, used once to estimate a technical level score. It is scored and thrown away immediately, never stored. We never store the content of your prompts or your conversations.
05 / analytics
We use PostHog, hosted in the EU, to see how the product is used: page views, signups, and where visitors came from. The CLI has its own separate telemetry with its own consent, documented in the CLI repo at github.com/hacklabubu/cli.
06 / cookies
A session cookie keeps you signed in. Three more are small and short-lived: hl_utm (30 days) remembers the campaign you arrived from — utm tags, referring URL, landing path, nothing that identifies you; hl_ref (30 days) remembers which member referred you; hl_signup_route (30 minutes) remembers which button you signed up through.
No third-party advertising cookies.
07 / short links
When you scan a hacklab.so/r/… QR code or open one of those short links, we log the time of the scan, a shortened user agent, the referrer, and a coarse location: country, region, city. We never log IP addresses.
08 / where your data lives
Our servers and database run with our infrastructure providers, Vercel and Neon. Analytics live with PostHog in the EU. We don't sell your data and we don't share it with advertisers.
09 / deleting your data
You can delete your account at any time. That removes your profile and your usage data from the network. To stop syncing, log out of the CLI or uninstall it. Prompt statistics stop the moment you withdraw consent in the CLI.
10 / changes and contact
We may update this policy; if we do, the date above changes. Questions: sos@hacklab.so.