HALWorld Privacy Policy

Effective Date: September 11, 2026
Last Updated: September 11, 2026

Pre-launch staging policy. This page describes the privacy architecture HALWorld is being built to use at public launch. We will update it if the implemented service differs before launch.

HALWorld is a product of HALbot Project. This Privacy Policy explains what information HALWorld's central services need, what remains in your own HALWorld environment, and what may be handled by services you choose to connect.

The short version

HALWorld is designed so that your work stays yours.

Our central account and licensing services are intended to know who is licensed and whether that license is active. They do not need to know what your HAL is doing.

In particular:

1. Account and authentication information

When account registration is enabled, our authentication provider may process information such as your email address, authentication credentials, verification status, and security information needed to create and protect your account.

HALWorld's licensing service is intended to use an immutable identity-provider identifier rather than your email address as its primary customer key.

HALWorld does not need to receive or store your plaintext password. Password, passkey, verification, and account-recovery functions are handled by the authentication provider.

2. Information kept by the HALWorld licensing service

The central HALWorld licensing service is designed to keep only information reasonably required to determine entitlement and administer the commercial relationship. That may include:

We may also retain limited operational and security records needed to run, protect, diagnose, and audit the account and licensing services.

We do not add fields to the licensing database merely because they might someday be useful.

3. Payment information

Paid subscriptions are processed by an external subscription or payment provider.

That provider may collect billing information, payment-method information, transaction history, and other information required to process your purchase under its own privacy terms.

HALWorld is designed to receive only the subscription information needed to determine entitlement, such as a provider customer or subscription reference and the current subscription state.

HALWorld does not store complete payment-card numbers or card security codes in its licensing database.

4. Your local HALWorld data

Your local HALWorld environment may contain information such as:

That information is not collected into HALWorld's central licensing database merely because the local HALWorld software can use it.

If you explicitly choose to submit diagnostic information, a support request, or a defect report, the submission flow should show you what will be transmitted before it is sent. Credentials, authentication tokens, unrelated project files, Gmail contents, Drive contents, and conversation content should not be included by default.

5. Connected services

HALWorld can work with services that you choose to connect, such as Google services, AI providers, plugins, applications, APIs, or other systems.

Those services have their own privacy practices and may receive information when you direct HALWorld to use them.

For example, when you authorize Google access, Google handles the authorization process. HALWorld receives authorization tokens rather than your Google password. Those tokens are intended to remain in your local HALWorld installation rather than being copied into the central licensing database.

When you direct HALWorld to send information to an AI provider or another connected service, that provider may process the information necessary to perform your request according to its own terms and privacy practices.

6. Website and service logs

The HALbot Project and HALWorld websites, hosting provider, authentication provider, licensing infrastructure, and other service providers may create routine technical and security records. Depending on the service, these can include information such as IP address, browser or device information, request timestamps, error information, authentication events, and security events.

We use this information to operate, protect, troubleshoot, and improve the services and to investigate abuse or technical failures.

We do not use HALWorld customer information to operate a behavioral advertising network.

7. Cookies and similar technologies

The website or service providers may use cookies or similar technologies that are necessary for functions such as authentication, security, preferences, or session management.

If HALbot Project adds non-essential analytics, advertising technology, or materially different tracking before public launch, this policy will be updated to describe it and any legally required choices will be provided.

8. How we use personal information

We may use personal information to:

We do not use the central licensing database as a general-purpose store of customer activity.

9. When information may be disclosed

We may disclose information to service providers that perform functions on our behalf, such as authentication, hosting, infrastructure, payment processing, email delivery, security, and support.

We may also disclose information when reasonably necessary to comply with law, respond to valid legal process, protect rights or safety, investigate abuse, or complete a business transfer such as a merger or acquisition.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising.

10. Retention

We aim to keep centrally controlled personal information only for as long as reasonably necessary for the purpose for which it was collected, including account administration, licensing, security, legal obligations, dispute resolution, and legitimate operational needs.

Different third-party providers may apply their own retention periods to information they process.

Local HALWorld data remains subject to the user's own storage, backup, deletion, and connected-service choices unless it has been explicitly submitted to us.

11. Security

We use reasonable technical and organizational safeguards appropriate to the information we control.

No system can be guaranteed completely secure. Users are also responsible for protecting their devices, accounts, local credentials, and connected services.

12. Your choices and privacy requests

Depending on applicable law and the information we control, you may have rights to request access to, correction of, or deletion of personal information, or to receive information about how it is used or disclosed.

You can contact HALbot Project through the site's Contact page to make a privacy request. We may need to verify your identity before fulfilling a request.

Signing out of HALWorld, cancelling a paid subscription, deleting a HALWorld account, and deleting local HALWorld data are separate actions and may have different effects.

13. California privacy rights

California residents may have additional rights under California privacy law when those laws apply to HALbot Project and the information at issue.

Nothing in this policy is intended to limit rights that cannot legally be waived. If a law requires an additional request method, notice, opt-out mechanism, or disclosure, we will provide it when applicable.

14. Children

HALWorld is not designed as a service directed to young children. We do not knowingly use the central HALWorld licensing service to collect personal information from children in violation of applicable law.

If you believe information has been provided in circumstances that violate applicable law, contact us through the site's Contact page.

15. Changes to this policy

We may update this Privacy Policy as HALWorld changes. The current version will show its effective date and last-updated date.

If a material change requires notice or consent under applicable law, we will provide it as required.

16. Contact

Questions or requests concerning this policy may be submitted through the HALbot Project Contact page.


Design principle: Our server should know who you are licensed as. It does not need to know what your HAL is doing.