ocw — privacy
you@open-code-war:~$ cat privacy.txt
← Leaderboard

Privacy Policy

Effective: August 10, 2026 (replaces the July 31, 2026 version)

The short version. Open Code War ranks how much you type into your coding agent (Claude Code, Codex, OpenCode, pi). We collect the minimum needed to build the leaderboard and never see or store the content of your prompts — only counts. The whole codebase is open source, so you can verify exactly what happens.
github.com/dodohankim/opencodewar ↗

01 What we collect

  • Anonymous device ID — a random identifier generated on your machine at install. Not linked to your name, email, or any account unless you choose to link Google (below).
  • Usage counts — the number of prompts you submit and the number of characters in them (numbers only), with the coding agent each came from (e.g. claude-code) and a timestamp.
  • Country & timezone — derived by Cloudflare from your IP. We store only the 2-letter code (e.g. KR) and the IANA timezone, never your IP.
  • Project label (optional) — if you link a folder with /ocw project link (or turn on auto-labeling yourself), prompts from that folder carry a label. We never receive folder paths — at most the label you chose or the folder's name.
  • Profile you choose to add — nickname, bio, role, company, city, links, projects. Optional and public.
  • Google account (optional) — if you link one with /ocw signup or sign in on the web, we store your Google account ID and email address for account recovery and merging usage across devices. Your email is private by default — it appears on your public profile only if you opt in with /ocw email public. We receive only your account ID and email (OpenID openid email scopes) — nothing else, and we never see your password.
  • Battles (optional) — which battle rooms you create or join, and when.
  • Website visits — via k-datafast, an analytics tool built and operated by the operator themselves (no third-party analytics company): a random visitor ID (cookie + localStorage), pages viewed, referral source (external referrer, UTM and ad-click parameters), browser and OS type (from User-Agent), and country/region/city estimated from your IP (the IP itself is not stored). We also use Cloudflare Web Analytics, which is cookieless.

02 What we never collect

  • The content of your prompts or Claude's responses.
  • Your code, files, or project data.
  • Your IP address — used transiently for country lookup and rate limiting, never stored.
  • Your name, phone number, or postal address.
  • Your password — Google sign-in is optional, handled entirely by Google.
  • Anything from your Google account beyond your account ID and email address.

03 Retention

We keep your data until you delete it (Section 04). Items with fixed technical lifetimes:

  • Web login session — up to 30 days (auto-expires).
  • Google-link temporary records — 10 minutes (link code) / 24 hours (completion record).
  • Share-card (OG image) cache — about 30 minutes.
  • Analytics visitor-ID cookie — up to 2 years (deletable in your browser anytime).
  • Raw per-prompt events (count, character count, timestamp) — kept until account deletion; they are needed to re-draw your profile graphs.

There are no payment features, so no data is retained under statutory bookkeeping obligations.

04 Deletion

  • Erase everything/ocw delete all confirm — immediately deletes your events, statistics, profile, and Google link from the database, and removes you from the leaderboard.
  • Clear profile only/ocw delete — removes bio, role, company, links, and projects; nickname and usage stay.
  • After full deletion, the only residuals are your web session record (auto-expires within 30 days; treated as logged-out immediately) and the share-card cache (within ~30 minutes).
  • Infrastructure backups (Cloudflare D1 Time Travel) may hold a restore copy for up to 7 days, after which it expires automatically.

05 Public information

Your nickname, bio, role, company, city, links, projects, and usage stats appear publicly on the leaderboard and profile pages. Don't add anything you don't want to be public. Outbound links you add are marked rel="nofollow". Your linked email is not public unless you explicitly enable /ocw email public.

06 No third-party sharing

We do not provide your personal data to third parties. We do not sell data and we do not run ads.

07 Processors & international data transfers

The service is operated from South Korea and your data is processed on the following infrastructure, which means it is stored and processed outside your own country:

  • Cloudflare, Inc. (USA / global network) — hosts the entire service (Workers, D1 database, KV, R2, Email Routing). All items in Section 01. Kept until you delete (backups up to 7 days). Contact: privacyquestions@cloudflare.com.
  • Operator's own server in Dallas, Texas, USA (a Hivelocity, Inc. data center; operated directly by the operator) — renders share-card images from public profile data only, and runs the k-datafast analytics backend. k-datafast is the operator's own software; its data is not shared with any other organization.
  • Google LLC (USA) — processes sign-in when you choose to link Google; we receive only your account ID and email. Google's own privacy policy applies to Google's processing.
  • South Korea holds an EU adequacy decision (2021), so EU/EEA personal data may be transferred there without additional safeguards.
  • Cloudflare provides a Data Processing Addendum and Standard Contractual Clauses for its processing.
  • If you do not want these transfers, stop using the plugin and delete your data (Section 04).

08 Your rights & how to exercise them

You can access, correct, delete, or stop the processing of your data at any time:

  • Access — /ocw status, /ocw whoami, or your web profile.
  • Correct — /ocw profile commands or web profile editing.
  • Stop collection — /ocw disable (takes effect immediately).
  • Hide your email — /ocw email private (this is the default).
  • Delete — Section 04.
  • If you can't use the CLI, email privacy@opencodewar.dev. Identity check: if you linked Google, your request must come from that linked email address. If you are anonymous, you must present the secret ID from ~/.open-code-war/config.json — we hold nothing else that could identify you, so an anonymous user who lost that ID cannot be individually verified or deleted; /ocw disable still stops all future collection.

09 Cookies & automatic collection — and how to refuse

  • ocw_sess — web sign-in session cookie (HttpOnly, 30 days). Set only when you sign in.
  • _kdf_vid — analytics visitor-ID cookie (2 years). Set on website visits.
  • localStorage — your language choice and a copy of the visitor ID.
  • No cross-site tracking or third-party advertising cookies of any kind.
  • To refuse: block or delete cookies in your browser (only web sign-in breaks; everything else works). To opt out of analytics permanently for a browser, open opencodewar.dev/#kdf_exclude once (#kdf_include undoes it); content-blocker extensions also work. CLI collection stops with /ocw disable.

10 Security measures

  • Minimal collection — no prompt content, no IP, no name or contact details.
  • Session cookies are HttpOnly · Secure · SameSite=Lax; state-changing requests are origin-checked.
  • Your secret ID is never sent to the browser; public pages use a separate public ID.
  • Google linking goes through CSRF nonces and an explicit confirmation page.
  • IP-based rate limiting against abuse; TLS encryption end to end.
  • The full source is open for verification.

11 Children

Open Code War is not directed to children under 14 and does not knowingly collect their data.

12 Open source — verify us

Don't just trust this page. The full source, including exactly what the plugin sends, is public:
github.com/dodohankim/opencodewar ↗

13 Privacy contact

Questions, requests, and complaints about personal data:

In South Korea you may also contact the Personal Information Infringement Report Center (privacy.kisa.or.kr, ☎118) or the Personal Information Dispute Mediation Committee (kopico.go.kr, ☎1833-6972).

14 Changes

This policy takes effect on August 10, 2026. Changes will be announced on this page at least 7 days before they take effect. Previous versions are available in the Git history ↗.