← Back to HammerLock AI

Privacy Policy

Last updated: August 11, 2026

HammerLock AI is built on the principle that your data belongs to you. We designed our architecture from the ground up to minimize data collection and maximize your privacy. This policy explains what we collect, what we do not collect, and how your information is protected.

1. What We Collect

We collect the minimum amount of information necessary to provide the Service:

  • Email address — only when you contact us, request support, or subscribe to product updates
  • Deployment records — only for managed support or custom environments where those records are needed
  • Website analytics — the public website may use Vercel Analytics and Speed Insights; the Electron app does not load them

2. What We Do NOT Collect

This is the most important section of our privacy policy. HammerLock AI does not collect:

  • Your stored chat history — HammerLock does not upload a copy of your local vault or history to a HammerLock account
  • Your vault data — all encrypted vault contents remain on your machine
  • Your full local document library — documents remain local unless you explicitly send document content to a connected provider
  • Desktop usage telemetry — the Electron app does not load Vercel Analytics or Speed Insights
  • Keystrokes, clipboard data, or screen content — the application does not monitor your system activity
  • IP-based location tracking — we do not log or store IP addresses for profiling

3. Local-First Architecture

HammerLock AI uses a local-first architecture. This means:

  • All AI processing can happen entirely on your device using local models (via Ollama)
  • Your encrypted vault, chat history, personas, and settings are stored locally
  • The application works fully offline when using local AI models
  • No data is sent to our servers during normal application use

When you choose a cloud AI provider (OpenAI, Anthropic, Google, etc.), the prompt, relevant conversation context, and any document text included in the request are sent to that provider under its privacy policy. HammerLock does not operate a hosted model proxy for those requests.

4. Encryption

HammerLock AI encrypts your vault data using AES-256-GCM, a military-grade encryption standard. Your encryption key is derived from your password using a secure key derivation function and is never transmitted or stored outside your device.

We cannot access your vault contents. If you lose your encryption password, we cannot recover your data. This is by design — true privacy means only you hold the keys.

5. Third-Party Services

HammerLock AI integrates with the following third-party services:

  • Cloud AI providers (optional) — if you choose to use cloud-based AI models (OpenAI, Anthropic, Google, Groq, Mistral, DeepSeek), your prompts are sent to those providers. Each provider has its own privacy policy and data handling practices. Use of cloud providers is entirely optional; local models via Ollama provide a fully private alternative.
  • Vercel (website only) — hosts the public website and may provide aggregate web performance and traffic analytics. These scripts are disabled in the Electron app.

6. PII Anonymization

HammerLock AI includes a built-in PII (Personally Identifiable Information) anonymization feature. When enabled, this feature automatically detects and redacts sensitive information — such as names, email addresses, phone numbers, social security numbers, and other personal data — before it is sent to a cloud AI provider. Automated redaction is a risk-reduction feature, not a guarantee: review sensitive prompts and provider settings before sending them.

7. Data Retention

Since HammerLock AI is local-first, you control your own data retention. You can delete chats, vault contents, and application data at any time directly from your device.

For the minimal server-side data we hold (such as support email or managed-deployment records), we retain this information only as long as needed to provide the requested service. If you request deletion, we will remove your information from our systems within 30 days, except where retention is required by law or for legitimate business purposes such as fraud prevention.

8. Children's Privacy

HammerLock AI is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected data from a child under 13, we will take steps to delete that information promptly. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at info@hammerlockai.com.

9. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify users through the application or via email. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the Service after changes constitutes acceptance of the updated policy.

10. Contact

If you have questions about this Privacy Policy or how your data is handled, please contact us at info@hammerlockai.com.

HomeTerms of Service