inspect before trusting

Privacy

The raw prompt remains on your machine. Upload is disabled by default, and the report works without it.

01

Local event data

Batuta stores a salted prompt hash, character count, tokenized term count, route suggestions, activations, and outcomes. The salt is generated locally and is not part of the aggregate upload.

batuta privacy
02

Optional aggregate upload

When explicitly enabled, the client produces one daily aggregate per skill. The ingestion boundary rejects prompt text, prompt hashes, turn identifiers, and text fields at any nesting level.

batuta summary
batuta config upload yes
03

Deletion

There is no account or remote copy while upload remains disabled. Local state can be removed as one directory after you inspect it.

batuta privacy
rm -r -i "$HOME/.batuta"
04

Newsletter purpose and retention

Email is used only for requested Batuta measurement updates. It is encrypted at rest. Unconfirmed requests expire after 48 hours and are erased within five more days; delivery outbox and idempotency records are kept at most seven days, and rate windows two hours.

double opt-in · no advertising · no address sharing
05

Newsletter control and erasure

Every confirmed message carries a private management link. Unsubscribe stops future sends; delete also erases the encrypted address, linkable hashes, queued mail, request records and rate pseudonyms.

unsubscribe · delete