Privacy Policy

Your numbers, not your prompts.

BurnCap is built to monitor AI spend without ever reading what your AI does. This policy explains what we collect, why, what you control, and the choices you have.

Last updated July 18, 2026

Who we are

BurnCap (“BurnCap”, “we”, “us”) is an AI cost monitoring and budget-guardrail service for small teams, operated by Eastbase Studio. You can reach us about privacy or data requests at support@eastbase.studio.

What we collect

  • Account details. Your email address, an optional display name, and a securely hashed password. If you sign in with Google or GitHub, we receive the basic profile your provider shares (name, email, avatar) instead of a password.
  • Usage metadata. Token counts, computed or provider-billed costs, model and provider names, timestamps, and the identifiers and tags you choose to attach to each event — feature, customer_id, environment, request_id, session_id, budget_reservation_id, and an optional free-form metadata object. If you opt into a budget reservation, we also store its USD amount, scope, expiry, and consumption time. These power your dashboards, forecasts, budgets, and unit economics. We store these fields as you send them; see what not to send below.
  • Provider credentials. If you connect OpenAI or Anthropic, the admin API key you paste is encrypted at rest (AES-256-GCM) and used only to read your organization’s usage and cost totals. The full key is never shown again after you save it, and when you disconnect a provider we delete the stored key from our active database. To fully revoke a key, also revoke it in your AI provider’s dashboard.
  • Revenue you record. If you use unit economics, the per-customer revenue figures and plan labels you enter or import — used only to compute margins for your own workspace.
  • Billing details. Subscription plan and status. Payments are processed by Lemon Squeezy as merchant of record — we never see or store your card number.

We do not collect your prompts or model completions. BurnCap sits out-of-band: it is not a proxy, your model traffic never passes through it, and our APIs have no field for prompt or response content. We recommend using stable, pseudonymous identifiers (such as an internal account ID or a hashed value) rather than raw emails, names, or phone numbers in your tags.

What you should not send

You choose what goes into the identifier, tag, and metadata fields, and BurnCap stores them verbatim — it does not inspect, filter, or redact their contents. So please do not put any of the following in feature, customer_id, request_id, session_id, environment, CSV uploads, or the free-form metadata object:

  • Prompts, model completions, or any message content.
  • Secrets, API keys, passwords, or other credentials.
  • Raw personal data or sensitive information about your end users or customers.

Keep these fields to opaque identifiers and labels. If you need to attribute cost to a customer, use a stable internal or hashed ID rather than their name, email, or phone number.

How we use your data, and our legal bases

  • To run the product — show cost breakdowns, forecasts, alerts, budgets, and reports.
  • To send the emails you ask for — account, security, alert, and digest emails.
  • To enforce plan limits and process your subscription.
  • To keep the service secure, debug failures, and prevent abuse.

Where data-protection law such as the GDPR applies, we rely on these legal bases:

  • Performance of a contract — to provide your account, the service, and billing.
  • Legitimate interests — to secure the service, prevent abuse, and operate and improve the product (other than the non-essential analytics covered by consent below), balanced against your rights by the safeguards we apply (data minimization, no prompt content, internal IDs only).
  • Legal obligation — to keep billing, tax, and accounting records.
  • Consent — for non-essential product analytics (which load only after you accept, and which you can reject or withdraw at any time) and any other optional feature that asks for it.

We do not sell your data, and we do not use your usage data to train AI models.

Cookies & tracking

We keep cookies to the minimum below, use no third-party advertising trackers, and do not set non-essential analytics cookies or storage until you consent.

  • Essential cookies. A session cookie (better-auth.session_token, HTTP-only) keeps you signed in; an active-workspace cookie (burncap_ws) remembers which workspace you’re viewing; a UI cookie (sidebar_state) remembers whether your dashboard sidebar is expanded; and a consent cookie (burncap_analytics_consent) remembers your analytics choice. These are required for the app to work or to honor your preferences.
  • Product analytics (optional, consent-based). We do not load PostHog (our product-analytics tool) or set any analytics cookies or local storage in your browser until you accept. If you accept, PostHog records privacy-preserving pageviews and product events with no session recording, no autocapture, and no advertising cookies, keyed to an internal account id and workspace — never your email or name — and reset when you sign out. You can reject non-essential analytics, or change your choice any time, via “Cookie settings” in the footer. Reset and invite tokens are scrubbed from URLs before any event leaves your browser.
  • Aggregate measurement. Vercel Analytics and Speed Insights collect anonymous, cookieless traffic and performance measurements, and error monitoring (Sentry, when enabled) attaches only an internal id with personal information turned off. These run independently of your analytics choice and set no analytics cookies.

Checkout and the billing portal run on Lemon Squeezy’s own domain; any cookies set there are governed by Lemon Squeezy’s policy.

Service providers

We rely on a small set of subprocessors, each handling only what its function requires. Some are optional and receive data only if you enable them:

  • Lemon Squeezy — subscription billing, checkout, and the customer portal (merchant of record).
  • Resend — transactional, alert, digest, invite, and authentication email, sent from the eastbase.studio domain (used when email delivery is configured).
  • Vercel — application hosting, plus aggregate Analytics and Speed Insights.
  • PostHog — optional product analytics, loaded only after you consent (US region by default; can be configured for the EU).
  • Sentry — optional error and performance monitoring.
  • Upstash — optional rate limiting for our public API.
  • Neon — our managed Postgres database provider; stores your account and usage metadata.
  • OpenAI and Anthropic — contacted only with the admin API key you connect, to read your usage totals.
  • Slack — optional; alert title and body are sent to your Slack workspace only if you connect a Slack incoming webhook (Starter and Growth plans).

International data transfers

BurnCap is operated by Eastbase Studio from Vietnam, and we use the service providers listed above — some of which process data in the United States or other countries. Your data may therefore be transferred to and processed in countries other than the one you live in.

Where such transfers are subject to data-protection law, we rely on appropriate safeguards — such as data processing agreements (DPAs), Standard Contractual Clauses (SCCs), UK transfer mechanisms, or other lawful transfer mechanisms made available by our service providers.

Data retention & deletion

  • Delete usage data. The workspace owner can delete all usage data from Settings at any time. This immediately and permanently removes your usage events, daily aggregates, in-flight budget reservations, budget-threshold and alert-delivery records, import-job records, and the feature/customer labels auto-created from your data — for that workspace. Your budgets, alert rules, connected integrations, pricing overrides, projects, and API keys are kept.
  • History windows. Dashboards and imports cover the last 7 days on Free, 90 days on Starter, and 365 days on Growth. This is how far back history is shown and imported — an access window, not an automatic deletion schedule.
  • Account deletion. To delete your account, email support@eastbase.studio. We remove your personal data and owned workspaces from our active systems within 30 days.
  • Caveats. Residual copies may persist in encrypted backups and operational logs for a limited time until they rotate or expire, and we may retain records we are legally required to keep (for example billing, tax, accounting, and fraud/security records).

Security

Provider credentials are encrypted at rest with AES-256-GCM, API keys are stored only as SHA-256 hashes (we can never show a key again after it’s created), and passwords are hashed. Most importantly, the data we never collect — your prompts and completions — can’t leak from us, because we don’t hold it. No system is perfectly secure, but we minimize what we store precisely to reduce that risk.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to certain processing such as analytics. Email support@eastbase.studio and we’ll help.

Changes to this policy

We’ll update this page when our practices change — including material changes to the service providers listed above — and revise the date above. For material changes we’ll give notice in-app or by email. Questions? See our Terms of Service or reach out any time.