Draft privacy notice
Account data
Locale stores your account name, email, password hash, session hashes, configured permissions, subscription selections and necessary security records. Passwords are hashed with Argon2id. Server secrets and recovery delivery payloads use authenticated encryption. This does not mean all account database fields or browser chats are encrypted.
Local work and connected services
Browser chats and workspace files remain in browser storage unless you choose a feature that transfers them. The Agent accesses the device resources you authorize. Selected remote model providers receive the request context you send to them. Analytics does not collect prompts, responses, filenames, document contents or API keys.
Traffic and model analytics
Optional usage analytics records page categories, a browser family, mobile or desktop category, guest or signed-in status, event time and reported model provider, execution category and duration. A random per-tab visit identifier is hashed with a server secret and rotated daily. These records are pseudonymous, not guaranteed anonymous. Locale does not store raw IP addresses or full user-agent strings in the analytics dataset. Network providers may process connection addresses for delivery and security.
Providers and retention
Cloudflare may receive pseudonymous analytics copies. Local analytics events are retained for up to 90 days; Cloudflare retention and sampling depend on its Analytics Engine service. DigitalOcean hosts the account service. Stripe handles test checkout directly; Locale does not collect card details. The configured email relay processes your email address and recovery link for delivery. Account and billing/security records may be retained as needed for service, legal obligations and abuse prevention.
Choices and requests
Use Analytics choices to disable optional telemetry in this browser. Locale also honors Do Not Track and Global Privacy Control for this telemetry. Disabling analytics does not disable essential authentication, security logs or account billing records. Contact accounts@uselocale.dev to request access, correction, deletion or a review of data handling, subject to applicable law and identity verification.
Before adoption
This is a draft. The operator's identity, legal bases where required, international transfer arrangements, retention schedules and regional rights need review before final publication as a binding policy.