Skip to content
DRAFT FOR REVIEW

Draft privacy notice

Account data

Locale stores your account name, email, password hash, session hashes, configured permissions, subscription selections and necessary security records. Passwords are hashed with Argon2id. Server secrets and recovery delivery payloads use authenticated encryption. This does not mean all account database fields or browser chats are encrypted.

Local work and connected services

Browser chats and workspace files remain in browser storage unless you choose a feature that transfers them. The Agent accesses the device resources you authorize. Selected remote model providers receive the request context you send to them. Analytics does not collect prompts, responses, filenames, document contents or API keys.

Traffic and model analytics

Optional usage analytics records page categories, a browser family, mobile or desktop category, guest or signed-in status, event time and reported model provider, execution category and duration. A random per-tab visit identifier is hashed with a server secret and rotated daily. These records are pseudonymous, not guaranteed anonymous. Locale does not store raw IP addresses or full user-agent strings in the analytics dataset. Network providers may process connection addresses for delivery and security.

Providers and retention

Cloudflare may receive pseudonymous analytics copies. Local analytics events are retained for up to 90 days; Cloudflare retention and sampling depend on its Analytics Engine service. DigitalOcean hosts the account service. Stripe handles test checkout directly; Locale does not collect card details. The configured email relay processes your email address and recovery link for delivery. Account and billing/security records may be retained as needed for service, legal obligations and abuse prevention.

Choices and requests

Use Analytics choices to disable optional telemetry in this browser. Locale also honors Do Not Track and Global Privacy Control for this telemetry. Disabling analytics does not disable essential authentication, security logs or account billing records. Contact accounts@uselocale.dev to request access, correction, deletion or a review of data handling, subject to applicable law and identity verification.

Before adoption

This is a draft. The operator's identity, legal bases where required, international transfer arrangements, retention schedules and regional rights need review before final publication as a binding policy.