Privacy Policy
Hawser is a Windows desktop application built and operated by Cook Impact Software LLC ("we," "us," "our") that helps you stay focused by quietly observing what you're doing on your computer and gently reminding you when you drift off-task. This policy explains what we collect, why we collect it, and how it's stored.
Plain-English summary: Almost everything Hawser knows about you stays on your own computer, unless you switch on sync, which is off until you turn it on and asks you first. We collect the minimum needed to run your account and your subscription. Screen awareness is on by default and disclosed during setup: when Hawser needs to look, a compressed screenshot is analyzed in the moment and never stored. You can turn it off during setup or any time in Settings, and screenshots are never written to disk either way. We do not sell your data and we do not run ad tracking.
1. What we collect
1a. Information you give us directly
- Account email and password. Required to create an account. Your password is stored as a one-way PBKDF2 hash with a per-user random salt - we cannot see or recover your original password.
- Daily missions, chat messages, profile facts. When you talk to the in-app AI companion or set a daily mission, that content is processed to generate responses and may be retained locally in your app's database to provide context across sessions.
- Partner program application data. If you apply for the Partner Program, the information you submit (name, email, optional URL, why-you-want-to-join text) is stored so we can review your application.
- Support and feedback. When you send feedback or contact support, we receive whatever you choose to include.
1b. Information collected automatically
- App usage telemetry. Active window titles, app names, and approximate focus/distraction durations - kept locally in a SQLite database on your machine to power your daily summary. This data is not transmitted off your computer in normal operation.
- Screenshots (on by default, disclosed at setup, one click to turn off). Screen awareness is Hawser's core feature: when it needs to look, a compressed screenshot is sent to Anthropic for analysis as part of an API request. Screenshots are never stored by us, never written to disk, and are not retained beyond the duration of the request. Hawser automatically excludes windows and sites you mark sensitive, and you can disable screen awareness during setup or any time in Settings → Privacy.
- Voice transcription (optional). If you use cloud voice input, the short audio clip you record is sent through our backend to OpenAI for speech-to-text. It is not stored by us, and per OpenAI's API terms is not used to train their models. You can switch to on-device transcription in Settings so audio never leaves your computer.
- Crash and error reports. If Hawser crashes, a minimal error report (stack trace, app version, OS version) may be sent to help us diagnose the bug. We do not include screenshots or window titles in error reports.
- Session metadata. When you sign in on the website or in the app, we store a session token plus the approximate sign-in time so that we can keep you signed in and recognize unusual activity.
- Last-active date. When the app checks your account (at launch), we record the date of that check - one timestamp on your account, at most once per day. We use it to operate the service, spot accounts having trouble, and understand retention. It contains no information about what you did in the app.
- Synced work (only if you turn sync on). Sync is off until you switch it on, and the first time you do, Hawser lists exactly what will be uploaded and asks you to accept. If a later version of Hawser can sync more than you agreed to, it asks again rather than assuming. With it on, we copy the following to our server so your devices can see the same things: your brain dump captures; your notes; your daily missions (the goal, your reason, your energy rating, and the distraction rules you set for that day); your tasks, including whether each is done; your Roadmap goals and their notes; your reminders, including their text, times and whether they have fired; and your learning flashcards, including both sides, the deck name and the review schedule. Deleting any of it uploads a record of the deletion so your other devices delete it too. We store the content as an opaque blob and do not read, index or search inside it.
What sync never uploads: your activity history, window titles and focus statistics, or anything else Hawser observed rather than you wrote; screenshots; your settings, which describe one computer; your conversations with the companion, including anything you typed back to a nudge; and the audio attached to flashcards.
You can turn sync off at any time, delete the server copy without deleting your account, and both your export and your account deletion cover the synced copy. - Website usage counts (no cookies). When you visit gethawser.com, a first-party script of our own counts anonymous page views, how far down a page visitors scroll, and clicks on our download and sign-up buttons. It sends us only the page address with any query string stripped off, the name of the event, and for scroll depth a percentage. We keep daily totals per page and nothing else: no cookie is set, nothing is stored in your browser, no third-party analytics service is involved, and we hold no record of any individual visitor or session. The totals delete themselves automatically after 45 days. If your browser sends a Do Not Track or Global Privacy Control signal, we count nothing at all.
- Cloudflare Web Analytics. Our host, Cloudflare, also provides a privacy-first page-view measurement on gethawser.com. It sets no cookies, and it does not fingerprint visitors or follow them across other websites.
- Abuse prevention. To stop automated abuse of endpoints such as sign-in, sign-up and the website counts above, we briefly tally how many requests arrive from an IP address on a given day. Those tallies hold nothing else, are never joined to your account or to the website usage counts, and expire on their own within about a day and a half.
1c. Information collected by Stripe (payments)
Payment card data is collected directly by Stripe on Stripe-hosted pages. We never see your full card number. We receive only the Stripe customer ID, subscription status, last-four digits of the card on file, and billing email, which we use to manage your subscription.
2. Where your data lives
- On your computer: activity logs, screenshots are never stored anywhere; everything else, chat history, daily missions, profile facts. All in a SQLite database under your local Windows user profile.
- Cloudflare Workers KV (United States): account record (email + hashed password + metadata), active sessions, Stripe customer ID, license token, partner program applications, and the daily website usage counts described in section 1b.
- Cloudflare D1 (United States): if you turn sync on, the work described in section 1b (captures, notes, missions, tasks, goals, reminders and flashcards), stored against your account so your devices stay in step. Nothing is stored here until you switch sync on.
- Stripe (United States): payment details, billing history, subscription status.
- Resend (United States): outbound transactional emails (sign-in confirmations, magic links, partner approval notices).
- Anthropic (United States): chat messages and (if you opt in) screenshots, processed at the time of each API call. We do not opt into Anthropic's training data use; per Anthropic's commercial terms your data is not used to train their models.
- OpenAI (United States): voice-dictation audio, processed at the time of each transcription request when you use cloud voice input. Not retained beyond the request; not used to train their models per OpenAI's API terms.
International transfers. Our infrastructure and the vendors above are based in the United States. If you use Hawser from the European Economic Area or the United Kingdom, your personal data is transferred to the US under the Standard Contractual Clauses or another lawful transfer mechanism. If you would rather no data leave your device at all, use Fully Local AI mode in Settings, where chat and screenshots are processed entirely on your own machine.
3. Why we collect what we collect
- To run your account and subscription (email, password hash, Stripe customer ID, license token, session tokens).
- To give Hawser the context it needs to actually help you (daily missions, chat history, profile facts - kept locally on your machine).
- To respond to your messages (chat content sent to Anthropic in cloud mode).
- To fix bugs (crash reports).
- To review partner program applications (application data).
- To email you about Hawser itself (your account email). If you make an account, we may occasionally write to you about the product you signed up for: how to get started if you never did, what has changed since you last looked, and sometimes a direct question about what would make Hawser worth paying for. These come from a person, not a mailing machine, and they are rare. Every one has a one-click unsubscribe that we honour immediately, and unsubscribing never affects your account or your access. We do not send you anything about anyone else's product, and we never sell or share your address.
We do not sell personal data. We do not use it for advertising. We do not run ad-network tracking pixels on this website.
3a. Legal basis for processing (GDPR)
If you are in the EEA or UK, our legal bases under Article 6 GDPR are:
- Contract: running your account and subscription and providing the focus features you signed up for.
- Legitimate interests: keeping the service secure, preventing abuse, fixing bugs, the local activity monitoring that makes Hawser work - balanced against your privacy by keeping that data on your device by default - and writing to people who signed up for Hawser about Hawser, which you can stop with one click at any time.
- Consent: optional features you switch on yourself, such as sync of your notes and brain dump entries, cloud screenshot analysis, cloud voice transcription, and anonymous usage statistics. You can withdraw consent at any time in Settings.
- Legal obligation: keeping limited payment and tax records as required by law.
4. Third-party services
We rely on a small number of vendors to operate Hawser. Each has its own privacy practices:
- Stripe - payment processing
- Cloudflare - account storage (Workers KV), website hosting (Pages)
- Resend - transactional email delivery
- Anthropic - AI inference (cloud mode only)
- OpenAI - cloud voice transcription (when you use cloud voice input)
- Sentry - crash and error diagnostics (when crash reporting is enabled)
These vendors act as our data processors: each processes personal data only on our instructions, and may engage its own subprocessors as described in its policy. We do not sell personal data to any of them. A current list of subprocessors is available on request from [email protected].
5. How long we keep your data
- Account records: retained for as long as your account exists, plus a short retention window after deletion for legal and accounting purposes.
- Sessions: automatically expire (typically 30 days) and are deleted from our storage.
- Magic-link tokens: 15-minute expiry, deleted on use.
- Local SQLite data: stays on your computer until you delete it (in-app "Wipe all data" or by uninstalling Hawser).
- Synced work: kept until you delete it, delete the server copy, or delete your account. We do not expire it on a timer, because it is your working material and disappearing notes would be worse than useless. Daily missions follow the app's own local window of roughly the last 60 days.
- Partner program applications: kept indefinitely for record-keeping unless you request deletion.
6. Your rights
You can, at any time:
- See what's on your computer: open Hawser → Settings → Data & Privacy.
- Wipe local data: Settings → Data & Privacy → "Wipe all data."
- Delete your synced copy without deleting your account: if you turned sync on, Settings → Sync lets you delete everything we hold on the server while your notes and brain dump entries stay on your own computer.
- Stop hearing from us: use the unsubscribe link in any email we send you about the product, or reply and say so. We will still send the things your account needs, such as a sign-in link, a receipt, or a security notice, because those are not marketing and you cannot really opt out of your own receipts.
- Cancel your subscription: Account → Manage Subscription.
- Delete your account: in Hawser, open Settings → Account → "Delete my account." This immediately deletes your account from our servers, including anything you synced, and cancels your subscription, then offers to erase your on-device data too. You can also email [email protected] and we will delete your account record, sessions, and partner application within 30 days. Limited records we are legally required to keep (for example, tax records for completed payments) may be retained as required.
- Get a copy of your data: for the data on our servers, open Settings → Account → "Export my data" (downloads a JSON file, including anything you synced), or email support. For the data on your computer, use Settings → Data & Privacy → "Export My Data."
If you are in the European Economic Area, the United Kingdom, or California, you have additional rights under GDPR and CCPA, including the right to object to processing, the right to data portability, and the right to lodge a complaint with your local data protection authority. Email support to exercise any of these.
7. Security
Passwords are hashed with PBKDF2 (salted, many iterations) before storage - we cannot read your password. All connections between Hawser and our backend use HTTPS. Session tokens are stored in Windows Credential Manager on your device. For extra protection you can turn on at-rest encryption of your local Hawser data in Settings → Privacy (note: if you lose access to your Windows account, encrypted local data cannot be recovered). Despite this, no system is perfectly secure. If we ever become aware of a breach affecting your account, we will notify you by email without undue delay.
8. Children
Hawser is not directed at and is not intended for use by anyone under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected data from a child, contact us and we will delete it.
9. Changes to this policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top. If the changes are material, we will additionally notify you by email. Continuing to use Hawser after changes take effect means you accept the updated policy.
10. Cookies & tracking
Hawser uses no advertising, analytics, or cross-site tracking cookies. The website (gethawser.com) sets no cookies at all: if you sign in, your session token is kept in your browser's local storage to keep you signed in, and the desktop app stores its session token in Windows Credential Manager on your device. If you use the phone capture app at gethawser.com/app, that page also keeps your own content in local storage: anything you capture is written there before it is sent, so a dead zone cannot lose it, and a copy of your notes and recent captures is kept so the app still works with no signal. It stays on your device, it is only ever sent to your own Hawser account, and signing out of that page deletes it. Because we set no tracking cookies, there is no cookie banner. The website usage counts described in section 1b are cookieless as well: they store nothing in your browser and identify no one.
11. Contact & data controller
Hawser is operated by Cook Impact Software LLC (Idaho, USA), the data controller for the personal data described in this policy.
Questions about this policy, or to exercise any of your rights (access, deletion, portability, objection), email [email protected] with the subject "Data Rights Request." We respond within 30 days. If you are in the EEA or UK and are not satisfied with our response, you may lodge a complaint with your local data protection authority.