Privacy policy · last updated 2026-09-29
Privacy
Short version: your score is computed on your machine. When you publish, we store aggregate numbers only, for up to a year, and you can delete them anytime.
Who is responsible
This site and the plugin are published by Camille Roux (camilleroux.com), who is the data controller for the data described below. Contact: contact form.
Hosting: Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Database: Upstash, Inc., in its European Union region.
This is an unofficial fan project, not affiliated with Anthropic.
On your machine (not collected)
The plugin reads your local Claude Code transcripts to compute the score. It only uses timestamps, message types, model names, tool names, token counts and error markers. It never reads or sends the text of your prompts or of Claude's answers, your code, file paths, project names or git branches. That processing happens on your computer and we receive none of it. The exact list of fields is in the README.
What we store when you publish
Running /claude-dependency-test:diagnose publishes your report, unless you add --no-publish. We then store one record containing:
- your score, stage and archetype, and the value and points of each of the 7 symptoms;
- counts: prompts, sessions, active days and hours, prompts per hour of day, per weekday and per day of the observation window (with its start and end dates);
- usage totals: tokens, tool calls per built-in tool (MCP tools grouped, no server names), subagents, interruptions, context compactions, longest turn, number of projects (a count, no names), latest and earliest prompt times;
- the share of responses per model family (Opus, Sonnet…);
- a hash of your deletion token, and the creation and update dates.
The server rejects any text that is not a number, a date or a value from a fixed list, so the record cannot contain anything you typed. It contains no name, email, account, IP address or device identifier. We don't know who you are unless you tell people the link is yours.
Your report is public to anyone who has the link. Result pages ask search engines not to index them, but a link you post can be seen and shared by others. Don't publish if you don't want your usage patterns (for example, the hours and days you worked) to be visible.
Security and abuse prevention
To limit abuse, each publication or update increments a counter keyed on a salted, irreversible hash of your IP address. The counter is deleted after one hour. Our hosting provider keeps technical request logs (including IP addresses) for a short period as part of running the service.
Why, and on what legal basis
| Purpose | Legal basis (GDPR) | Kept for |
|---|---|---|
| Publishing the report you asked for, its preview image and badge | Performance of the service you request, Art. 6(1)(b) | 365 days after your last update, then deleted automatically |
| Rate limiting with a salted IP hash | Legitimate interest in preventing abuse, Art. 6(1)(f) | 1 hour |
| Anonymous audience measurement (Vercel Web Analytics) | Legitimate interest in knowing how the site is used, Art. 6(1)(f) | Aggregated figures, per Vercel's retention |
| Hosting request logs | Legitimate interest in running and securing the site, Art. 6(1)(f) | Per the host's log retention (kept to the minimum available) |
The report is a joke about usage statistics. It is not health data and not a medical assessment.
Who receives it
Vercel (hosting and content delivery) and Upstash (database) process the data on our behalf as processors, under data processing agreements. Vercel is based in the United States. Transfers rely on the EU-U.S. Data Privacy Framework and the European Commission's standard contractual clauses. We don't sell or share data with anyone else, and we don't use advertising.
Cookies and audience measurement
No cookies, no advertising trackers, no third-party scripts. We count visits with Vercel Web Analytics, which works without cookies and doesn't store IP addresses: a visitor is recognized only by a hash of the request, discarded after 24 hours, and we only see aggregated figures (pages, referring sites, countries, device and browser types). Case file addresses are anonymized to /case/[id] before anything is sent, and query strings are dropped.
Your rights
- Delete your report anytime: run
/claude-dependency-test:diagnose --unpublishon the machine that published it. It is removed from our database immediately; cached copies of the page, preview image and badge expire within 5 minutes. Lost that machine? Send the link of your report through the contact form and we'll delete it. - Rectify: run the test again, it replaces the published numbers.
- Access and portability: your report page shows everything we store about it, and the plugin's
--jsonoutput gives it in a machine-readable format. - Object or restrict: use
--no-publish, or use the contact form.
Because we can't tell who owns a report, we may ask you to prove it (for example by publishing an update from your machine) before acting on a request. You can also complain to your data protection authority. In France, that's the CNIL.