dash.kelvinct.com

How Dash handles your data

The other tools on kelvinct.com run entirely in your browser and send nothing anywhere. Dash cannot work that way, and it would be dishonest to imply otherwise.

Why Dash needs a server

Two reasons. Connecting WHOOP or Oura requires a secret that would be readable by anyone if it lived in your browser. And the display page has to render on devices too old to run the code that would fetch your data, so a server has to fetch it and send finished HTML.

What is stored

The complete list, table by table. If something is in the database it is named here.

No name, no email, no password. Connecting a provider is how you sign in, so there is no account to create.

What is not stored, sent, or logged

Cookies

Three, all first-party, none for tracking.

Where it runs

Dash is hosted on Cloudflare Pages, and everything described above lives in Cloudflare D1, their SQLite database. Cloudflare therefore operates the server and the database on my behalf, and their infrastructure logs requests the way any host does. The provider tokens in that database are encrypted with a key Cloudflare stores as a secret; nobody else has a copy of it.

Deleting everything

There is a Delete everything button at the bottom of your dashboard. It empties everything listed above that belongs to your account, in one go: tokens, provider ids, metrics, the four-week history, display links, pairing codes, and the account row itself. There is no undo and no grace period. Disconnecting a single provider, described below, is the smaller version of the same thing.

Display links

A display link contains a random 32-byte token. It is a key, not a username: anyone holding the link sees those numbers, so treat it like a password. It is not guessable and never appears in search results. You can revoke any display from your dashboard, which kills that link immediately.

Disconnecting

Disconnect a provider from your dashboard and Dash deletes its tokens and its cached metrics. It also asks WHOOP or Oura to revoke the access you granted, so the token stops working at the source too. That request is best-effort: if the provider does not answer, everything is still deleted here. You can always revoke Dash's access from inside your WHOOP or Oura account, which has the same effect from the other direction. Delete everything does the same for every provider you connected.

Contact

hello@kelvinct.com