last updated: 2026-05-23

Privacy

The short version: we collect the minimum data needed to show per-company meeting averages on a public leaderboard. Nothing more. This page tells you exactly what that means.

What we store about you

  • An HMAC-SHA256 hash of your email address. The raw email is never written to the database.
  • The company you belong to, derived from your email domain.
  • An opaque, deterministic alias (e.g. quiet-fox-4821) that hides your identity on public pages.
  • Two timestamps: when you first registered, and when you were last seen.
  • Your weekly meeting count and total hours, indexed by ISO week.

What we do not store

  • Your raw email address. Ever. Anywhere.
  • Your name, job title, team, department, location, or any free-form profile field.
  • Cookies for tracking. We use one signed session cookie, strictly necessary, no analytics cookies.
  • An audit history of past submissions. Re-submitting a week overwrites — there is nothing to subpoena.

How verification works

When you enter your work email, we send a one-time 6-digit code to that address. The pending code lives in a memory cache for up to 10 minutes, then evaporates. After you enter the code, the only thing that survives is the HMAC hash and the company derived from the domain.

k=5 anonymity

A company is never shown on the public leaderboard or company page until at least 5 verified employees from that company have registered. With fewer than 5, the data is statistically too easy to re-identify.

Cookies

One signed, HttpOnly, SameSite-Lax session cookie. It contains your user ID and company ID, signed with our server secret. It expires after 30 days. That is the only cookie this site sets. Web analytics (if enabled) are cookieless.

Your rights

Under GDPR (and equivalents) you can:

  • Erase your data — one click. Your user row is deleted; all your submissions cascade-delete with it. We retain nothing.
  • Access what we hold about you — there isn't much; this page tells you the complete list.
  • Object to anything — email hello@recurring.fyi.

Data location

The database (Cloudflare D1) is pinned to Western Europe. Edge caching is global, but no personal data is included in cached HTML — only aggregated per-company numbers.

Contact

hello@recurring.fyi