Legal
Privacy policy
Last updated: 25 August 2026
The short version
Your projects, notes and vault never leave your computer. We hold your email address, your subscription, and which devices are activated. That is all.
Who is responsible
FREEDOM LABS LTD, British Virgin Islands, is the data controller. Contact: support@alphaharness.xyz.
We are established outside the EU but serve customers inside it, so we apply the GDPR to everyone. The rights below are yours regardless of where you live.
What we collect
| Data | Why | Lawful basis |
|---|---|---|
| Email address | Sign in, and to match your purchase to your account | Contract |
| Subscription record | Plan, seats, renewal date, payment reference | Contract |
| Device fingerprint | Enforcing the 3-devices-per-seat limit | Legitimate interest (preventing licence sharing) |
| Activation timestamps | Spotting a single licence used by many people | Legitimate interest |
| Anonymous app diagnostics | Which guard rules fired and whether you overrode them, which health checks failed, which AI tools and operating system you have, which screens you opened, and how many milliseconds a guard took. Never the command, the file, or the project. | Legitimate interest (fixing rules that block real work) — on by default during the beta, and you can switch off any category, or all of them, at any time on any plan |
What we never collect
- The contents of your files, projects, notes or vault.
- Your prompts, or anything your AI tools generate.
- Your AI provider API keys — those stay on your machine.
- File names, folder names, paths, or the names of your projects and repositories.
- Commands you or your AI tools ran.
- Behavioural tracking, advertising identifiers, or third-party analytics.
The device fingerprint is a one-way hash used to tell machines apart. It is not a hardware serial number and cannot be reversed into one.
The diagnostics, in detail
The app writes diagnostics to a file on your machine and uploads them once a day. If you are offline it keeps them and tries tomorrow. Everything it may contain is a number, a true/false, or a short fixed word such as a rule name — an allow-list in the app drops anything shaped like a path, a file name, an email address, a URL or a sentence before it can be written, and the server applies the same allow-list again on arrival.
You can read the exact bytes. Open Alpha Harness, go to Privacy, and press Show me exactly what. That is the real payload, not a description of one. The same screen switches off any category, or all of them, and deletes anything already queued.
Every plan, the same controls. Diagnostics are on by default on every plan while Alpha Harness is in beta, because the rules that block real work can only be found on real machines. Switching them off is one click, it takes effect immediately, and it is identical whether or not you pay — what you pay for is workspaces, seats and support, never the ability to say no.
When everything is switched off, nothing is recorded at all: no diagnostics are written, nothing is uploaded, and no identifier for your machine appears in anything.
The identifier attached to diagnostics is deliberately not the device fingerprint we use for licensing. Both are derived from the same random value on your machine in ways that cannot be reversed into one another, so your diagnostics cannot be matched to your account.
Cookies
This website sets one cookie: the session cookie that keeps you signed in. It is strictly necessary, so no consent banner is required. There are no advertising or analytics cookies.
Who processes data for us
| Processor | What they handle | Where |
|---|---|---|
| Supabase | Account database and authentication | EU region |
| Paddle.com Market Ltd | Payments, invoicing and VAT — Merchant of Record | UK / EU |
| Vercel | Hosting this website | EU region |
We never see your full card number. Payment details go directly to Paddle and are never transmitted to or stored by us.
How long we keep it
- Account data: while your account exists, then deleted within 30 days of your request.
- Invoices and payment records: retained for 7 years to meet accounting and anti-money-laundering obligations. We cannot delete these early, even at your request — the obligation is legal, not commercial. Card payment records are held by Paddle as Merchant of Record under their own retention rules.
Your rights
Under the GDPR you may request access to your data, correction, deletion, a portable copy, or restriction of processing, and you may object to processing based on legitimate interest.
Email support@alphaharness.xyz. We respond within 30 days, and there is no charge.
You also have the right to complain to a data protection supervisory authority. If you are in the EU or UK, that is the authority in the country where you live or work — the EDPB member list has the contact details for each one.
Security
- All traffic is encrypted in transit (TLS).
- Database access is restricted per-user at the database level, so one customer's records are not readable by another.
- Your sign-in token is held in your operating system's secure storage, not in a plain file.
Children
This is a professional tool and is not directed at anyone under 16. We do not knowingly collect their data.
Changes
If we change this policy materially we will email the address on your account before it takes effect.