How Dash handles your data
The other tools on kelvinct.com run entirely in your browser and send nothing anywhere. Dash cannot work that way, and it would be dishonest to imply otherwise.
Why Dash needs a server
Two reasons. Connecting WHOOP or Oura requires a secret that would be readable by anyone if it lived in your browser. And the display page has to render on devices too old to run the code that would fetch your data, so a server has to fetch it and send finished HTML.
What is stored
The complete list, table by table. If something is in the database it is named here.
- Your access and refresh tokens for each provider you connect, encrypted at rest with AES-256-GCM. They are never sent to your browser.
- Your user id at each provider, in the clear. It is how Dash recognises you when you reconnect, which is what lets connecting a provider work as signing in.
- Which scopes you granted, and when Dash last synced each provider.
- The text of the last sync failure for each provider, so the dashboard can say what went wrong. It is a sentence Dash wrote, and never contains a token.
- Your most recent value for each metric, and the one before it, so a display can say whether you are up or down on yesterday.
- A rolling four-week window of one value per metric per day, so a display can say whether today is normal for you: "61 ms, 28d median 57". Day labels only, never bedtimes or timestamps. Anything older than 28 days is deleted automatically every time Dash syncs, even when the provider does not answer, so a month from now the window is still exactly four weeks. This is the whole extent of history; Dash still keeps no archive.
- Your display links, and for each one the name you gave it, its light or dark setting, which metrics you chose, which one is the big number, and your refresh interval.
- Any pairing code that is currently live, with the display it hands over and how many failed attempts it has seen. Codes last ten minutes, work once, and are deleted when they are used or expire.
- When a pairing code is checked and is wrong, used or expired, or a sign-in fails as Dash confirms it with WHOOP or Oura, a salted hash of the IP address it came from and a count of failed tries, so one address cannot guess at everyone's codes or flood sign-in. It is never the address itself and is not linked to any account. For an IPv6 address the hash is of its /64 network, not the single address. Counts run in ten-minute windows. A row is deleted once its window and the next one have ended, the next time a pairing code is checked or WHOOP or Oura confirms a sign-in.
- Your timezone, an IANA name like
America/Detroit, captured from your browser so displays render in your clock rather than the server's.
No name, no email, no password. Connecting a provider is how you sign in, so there is no account to create.
What is not stored, sent, or logged
- No health values reach analytics. Dash does not run third-party analytics at all.
- No provider tokens appear in URLs or in logs. Display links do contain their own token, which is what the section below is about.
- Nothing is sold, shared, or used to train anything.
Cookies
Three, all first-party, none for tracking.
__Host-dash_session, set when you connect a provider. It is a signed record of which account you are, and it is what a signed-in page checks. Ninety days.__Host-dash_oauth, a random one-shot value that exists only while you are away at WHOOP's or Oura's consent screen, so the reply can be checked against the request. Ten minutes.dash_tz, your browser's timezone name, set by the page itself. It is read to fill in the timezone above.
Where it runs
Dash is hosted on Cloudflare Pages, and everything described above lives in Cloudflare D1, their SQLite database. Cloudflare therefore operates the server and the database on my behalf, and their infrastructure logs requests the way any host does. The provider tokens in that database are encrypted with a key Cloudflare stores as a secret; nobody else has a copy of it.
Deleting everything
There is a Delete everything button at the bottom of your dashboard. It empties everything listed above that belongs to your account, in one go: tokens, provider ids, metrics, the four-week history, display links, pairing codes, and the account row itself. There is no undo and no grace period. Disconnecting a single provider, described below, is the smaller version of the same thing.
Display links
A display link contains a random 32-byte token. It is a key, not a username: anyone holding the link sees those numbers, so treat it like a password. It is not guessable and never appears in search results. You can revoke any display from your dashboard, which kills that link immediately.
Disconnecting
Disconnect a provider from your dashboard and Dash deletes its tokens and its cached metrics. It also asks WHOOP or Oura to revoke the access you granted, so the token stops working at the source too. That request is best-effort: if the provider does not answer, everything is still deleted here. You can always revoke Dash's access from inside your WHOOP or Oura account, which has the same effect from the other direction. Delete everything does the same for every provider you connected.