Privacy Policy
Hawser is a Windows desktop application, with an optional companion browser extension, built and operated by Cook Impact Software LLC ("we," "us," "our") that helps you stay focused by quietly observing what you're doing on your computer and gently reminding you when you drift off-task. This policy explains what we collect, why we collect it, and how it's stored.
Plain-English summary: Almost everything Hawser knows about you stays on your own computer, unless you switch on sync, which is off until you turn it on and asks you first. We collect the minimum needed to run your account and your subscription. Screen awareness is on by default and disclosed during setup: when Hawser needs to look, a compressed screenshot is analyzed in the moment and never stored. You can turn it off during setup or any time in Settings, and screenshots are never written to disk either way. If you install the Hawser browser extension, it tells Hawser the name of the site you are on and how long you were there, never the address of a page, and it sends that to the Hawser app on your own computer and nowhere else. Connecting it is a card Hawser shows you on your own screen, which you accept or turn down; there is no secret to copy. The extension can also show a nudge on the page you are reading, in the corner or in the middle of the screen, as you choose in Hawser. That needs your browser's permission to reach websites: installing the extension grants that for no website at all, your browser asks you only at the moment you switch that nudge on, and switching it off hands the access straight back. We do not sell your data and we do not run ad tracking.
1. What we collect
1a. Information you give us directly
- Account email and password. Required to create an account. Your password is stored as a one-way PBKDF2 hash with a per-user random salt - we cannot see or recover your original password.
- Daily missions, chat messages, profile facts. When you talk to the in-app AI companion or set a daily mission, that content is processed to generate responses and may be retained locally in your app's database to provide context across sessions.
- Support and feedback. When you send feedback or contact support, we receive whatever you choose to include.
1b. Information collected automatically
- App usage telemetry. Active window titles, app names, and approximate focus/distraction durations - kept locally in plain JSON files on your machine to power your daily summary. This data is not transmitted off your computer in normal operation.
- Browsing time, only if you install the Hawser browser extension. The name of the site you are on and how long you were on it, sent to the Hawser app on your own computer and nowhere else. Never the address of a page. Section 1d sets out exactly what it collects, what it never collects, and what each browser permission is for.
- Screenshots (on by default, disclosed at setup, one click to turn off). Screen awareness is Hawser's core feature: when it needs to look, a compressed screenshot is sent to Anthropic for analysis as part of an API request. Screenshots are never stored by us, never written to disk, and are not retained beyond the duration of the request. Hawser automatically excludes windows and sites you mark sensitive, and you can disable screen awareness during setup or any time in Settings → Privacy.
- Voice transcription (optional). If you use cloud voice input, the short audio clip you record is sent through our backend to OpenAI for speech-to-text. It is not stored by us, and per OpenAI's API terms is not used to train their models. You can switch to on-device transcription in Settings so audio never leaves your computer. The text of what you dictated is kept on your own computer so you can read it back later; it is never uploaded to us or to anyone else, it is deleted automatically after 30 days, and you can turn that history off or clear it at any time in Settings under Voice input.
- Crash and error reports. If Hawser crashes, a minimal error report (stack trace, app version, OS version) may be sent to help us diagnose the bug. We do not include screenshots or window titles in error reports.
- Session metadata. When you sign in on the website or in the app, we store a session token plus the approximate sign-in time so that we can keep you signed in and recognize unusual activity.
- Last-active date. When the app checks your account (at launch), we record the date of that check - one timestamp on your account, at most once per day. We use it to operate the service, spot accounts having trouble, and understand retention. It contains no information about what you did in the app.
- Synced work (only if you turn sync on). Sync is off until you switch it on, and the first time you do, Hawser lists exactly what will be uploaded and asks you to accept. If a later version of Hawser can sync more than you agreed to, it asks again rather than assuming. With it on, we copy the following to our server so your devices can see the same things: your brain dump captures; your notes; your daily missions (the goal, your reason, your energy rating, and the distraction rules you set for that day); your tasks, including whether each is done; your Roadmap goals and their notes; your reminders, including their text, times and whether they have fired; and your learning flashcards, including both sides, the deck name and the review schedule. Deleting any of it uploads a record of the deletion so your other devices delete it too. We store the content as an opaque blob and do not read, index or search inside it.
What sync never uploads: your activity history, window titles and focus statistics, or anything else Hawser observed rather than you wrote; screenshots; your settings, which describe one computer; your conversations with the companion, including anything you typed back to a nudge; and the audio attached to flashcards.
You can turn sync off at any time, delete the server copy without deleting your account, and both your export and your account deletion cover the synced copy. - Website usage counts (no cookies). When you visit gethawser.com, a first-party script of our own counts anonymous page views, how far down a page visitors scroll, and clicks on our download and sign-up buttons. It sends us only the page address with any query string stripped off, the name of the event, and for scroll depth a percentage. We keep daily totals per page and nothing else: no cookie is set, nothing is stored in your browser, no third-party analytics service is involved, and we hold no record of any individual visitor or session. The totals delete themselves automatically after 45 days. If your browser sends a Do Not Track or Global Privacy Control signal, we count nothing at all.
- Cloudflare Web Analytics. Our host, Cloudflare, also provides a privacy-first page-view measurement on gethawser.com. It sets no cookies, and it does not fingerprint visitors or follow them across other websites.
- Abuse prevention. To stop automated abuse of endpoints such as sign-in, sign-up and the website counts above, we briefly tally how many requests arrive from an IP address on a given day. Those tallies hold nothing else, are never joined to your account or to the website usage counts, and expire on their own within about a day and a half.
1c. Information collected by Stripe (payments)
Payment card data is collected directly by Stripe on Stripe-hosted pages. We never see your full card number. We receive only the Stripe customer ID, subscription status, last-four digits of the card on file, and billing email, which we use to manage your subscription.
1d. The Hawser browser extension (optional)
Hawser can see that your browser is in front of you, but not which tab, so eight hours of work and eight hours of drift look identical to it. The Hawser browser extension is the optional piece that tells them apart. We publish it in the Chrome Web Store, and it runs in Chrome and in the other browsers built on the same engine, such as Edge, Opera and Brave. It is a separate install, it does nothing at all until you connect it to the copy of Hawser on your computer, and everything in this section applies only if you choose to use it.
Everything the extension sends goes to the Hawser app on your own computer, and nowhere else. It reaches Hawser over a loopback connection to 127.0.0.1, which cannot leave the machine, and it contacts no other address at all. There are exactly two places in the extension that make a network request, one for the ordinary conversation with Hawser and one for connecting in the first place, and both of them go to 127.0.0.1 on your own machine. There is no remote server anywhere in it. Nothing about your browsing reaches us, and nothing about your browsing is ever sent to Anthropic or to any other AI. When a nudge names a site, that sentence is composed on your computer by Hawser's own code, and no AI model writes it or reads it.
How you connect it, and what that involves
Nobody types a secret. You press "Connect this browser" in the extension, it finds Hawser on your own machine and asks to be connected, and then Hawser shows you a card: it names the browser that asked and lists in plain words what that browser would be able to see and what it would not. Nothing happens unless you press Allow. Pressing "Not now", closing the card and pressing Escape are the same answer, and after a no that browser stops asking for a while. The key is issued at the moment you allow it, goes straight into the extension's own storage, and is never shown on screen. If you would rather do it by hand, Hawser's Settings can still hand you a code to paste into the extension, which is also the way in if you have moved Hawser off its usual port.
Asking, and then coming back to see whether you have answered, are the only two things Hawser's local connection will do without a key, because a browser that has never been connected has no key to offer. All that asking can do is leave the request for you to answer. It reads nothing about you, changes nothing, and answers with a request number and a clock and nothing else: not your mission, not your tasks, not your browsing totals, not whether anything else is connected. It also answers only to your own machine and to our own extension, so a website cannot put a card on your screen. If you turn a browser away, Hawser writes that down on your computer so it stops asking: a count and two timestamps against the random number that browser made up for itself, kept in Hawser's own config file alongside its settings, never sent anywhere. Settings has a button that clears it and lets browsers ask again.
Each browser is its own connection. Install the extension in two browsers and each one gets its own key, its own browsing totals, its own nudges, and its own entry in Hawser's Settings, where you can rename or disconnect either one on its own. A code from Hawser belongs to the first browser that uses it: a second browser presenting the same code is turned away rather than quietly sharing, or taking over, the first browser's connection.
What it collects
- The site name, and how long you were on it. A total per site, such as youtube.com, 12 minutes. Only the tab you are actually looking at counts, in the browser window that has your attention: background tabs, background windows, and a browser you have switched away from all count nothing.
- Which site is in front right now, sent alongside those totals, so Hawser knows where you are and not only where the day went.
- Which browser is asking. Every call to Hawser carries three small facts about the extension itself: a random number this copy makes up for itself and keeps, what the browser calls itself (Chrome, Opera, Edge and so on), and which version of the extension is running. The random number is not derived from your machine, your profile, your account or anything you do; it exists so that Hawser can tell two browsers apart, and the version exists so that a browser running an out of date copy can be told so. All three go to the Hawser app on your own computer and nowhere else.
- The extension's own switches, so Hawser can explain itself. When the extension asks Hawser whether there is anything to say, it sends along the state of its own on and off switches, whether your browser has granted it access to websites, and what became of the last card it tried to show. That is eight fixed fields, checked against a list on Hawser's side before anything is kept, and there is deliberately no free text field among them, so an address, a site name or a page title has nowhere to arrive. It is there so that "why did no nudge appear" has an answer without anybody reading files by hand.
What it never collects
- Never the address of a page. The extension reduces every address to a bare site name the moment it reads it: the scheme, the path, the query and the fragment are all dropped inside the extension, before anything is sent and before anything is stored. A watch page on YouTube becomes youtube.com and nothing more. Hawser is never told which video, which document, which search or which account, and it independently refuses any report that arrives carrying a path or a query, so the promise is enforced twice.
- Never a timeline. Reports are totals that add up, not a log of events. There is no minute by minute record of your day in the extension or in Hawser.
- Never the page you are reading. The extension can draw one card of its own on a page, and that card is the whole of its contact with the page. It reads nothing there: not the address, not the title, not the text, not what you type, and it adds nothing else, listens for nothing, and takes nothing away with it. The page cannot read the card either, because the card is sealed inside a closed shadow root that page code cannot reach into. Nothing about a page is sent anywhere as a result, and nothing is left behind: close the nudge, or move on to another page, and the page is exactly as it was.
- Never anything that is not a website. Browser settings pages, local files, blank tabs and extension pages all reduce to nothing and are never reported, and nothing is ever drawn on them either.
- Never your incognito browsing. We do not ask for access to incognito windows, and we ask you not to grant it.
The permissions it asks your browser for, and what each one is for
- storage. To remember, across restarts, the things it would otherwise lose: the key it was issued and the port Hawser listens on, the result of the last connection, the seconds counted but not yet sent, any nudge currently on screen and how it was drawn, the random number that identifies this copy, the on and off switches, and, while it is being connected, the number of the pairing request and when it is worth asking again. Your browser stops an extension whenever it is idle, so there is nowhere else to keep any of it. The full list is under "Where it is kept" below.
- tabs. To read the address of the active tab, which is the only way to know which site you are on, and to know that tab's number so a nudge can be drawn in the tab you are actually in. Only the site name survives that read, and only for the tab in the window you are actually using.
- scripting. To put the nudge card into the page you are reading. It happens only while Hawser has handed over a nudge that has not been shown yet, and only into the main part of the one tab in front of you. Usually that is the moment the nudge arrives; if you were not on a page it could be drawn on at that moment, for instance because you were in Hawser or on a browser settings page, it tries again on the once a minute timer until you are. Nothing is put into a page when a page loads, on a schedule, or in the background, and nothing stays behind afterwards.
- webNavigation. Sites like YouTube and Gmail move you to a new page without loading one, by rewriting the address themselves. Without this the extension would keep crediting the site you started on. It is used for the fact that something moved; the address it carries is not read.
- alarms. One timer, once a minute, and everything rides on it rather than on timers of its own. It banks the stretch in progress and sends what has been counted, it is when the extension asks Hawser whether there is anything to say, it is what puts a nudge on the page when there was nowhere to put it a minute ago, and before the browser is connected it is when the extension looks for Hawser again, so opening Hawser after installing the extension connects it without you pressing anything twice. Your browser stops an idle extension, so without it the totals would sit unsent, and a waiting nudge would sit undrawn, until you happened to switch tabs.
- Access to http://127.0.0.1, your own computer. This is the whole point of the extension: it is how it reaches Hawser running on your machine. It is also the only address the extension ever contacts, for connecting and for everything after it.
- Access to websites, optional and off until you ask for it. Drawing a card on a page needs permission to reach that page, and there is no way around that. What there is a way around is asking for it at install, so the extension does not: this permission is marked optional, which means installing the extension grants access to no website at all. Your browser asks you for it at the moment you tick "Show Hawser's nudges on the page I am on" in the extension's options page, and unticking that box hands the access straight back. You can also take it back yourself in your browser's own extensions page, under Site access, and the extension checks every time rather than assuming. With the access withheld or handed back, nothing is ever drawn on a page and the extension carries on as before: nudges land on the toolbar icon instead. It covers ordinary web pages only, so files on your own computer are never included. Worth saying plainly, because your browser does not spell it out: an access this broad would also let an extension send requests out to those websites. This one sends none. It uses the access for one thing, drawing its card, and both of its network requests go to your own computer.
It asks for nothing else. In particular it does not ask for the history permission, so it cannot read where you have been: it only ever sees the tab you are looking at now, and only the site name of it. It has no access to your bookmarks, and no ability to block or change anything on a page. The only thing it can put in a page is its own card, and only while you have that switched on.
Nudges, going the other way
Hawser cannot reach into your browser, so the extension asks it whether it has anything to say, and tells it what became of the last thing it said. That happens about once a minute while you are in the browser, less often when Hawser is quiet or you are away, and about twelve seconds after you land on a different site, which is the moment Hawser is most likely to have something to say. A nudge shows up as a mark on the toolbar icon, with the words in the panel behind it, and, if you have switched that on, on the page you are reading. Those words are Hawser's, written on your computer, and the extension keeps them only while the nudge is on screen: closing it clears them.
How the card appears is your choice, and you make it in Hawser, under Settings, About and advanced, Agent access, so there is one setting rather than two that could disagree. It can start as a small card in the corner and come to the middle of the screen if you have not closed it after a while, arrive in the middle every time, or stay in the corner. A card in the middle dims the page behind it and holds it until you close the card, which is the point of it: Escape always closes it, so does clicking the dimmed area, and so does the button on the card itself. None of that is website blocking. The extension cannot stop a page loading, cannot redirect you, and asks for no permission that would let it: what it can do is put its own card in front of a page you have already opened, until you close it.
The card is the only thing the extension ever puts in a page, it is put there only when Hawser has something to say, and it is never put there at all unless you ticked "Show Hawser's nudges on the page I am on" and your browser granted the access. Some pages cannot take it, such as the browser's own pages, the Chrome Web Store, local files and PDFs, and on those the toolbar icon carries the nudge instead.
Your own quiet settings still decide, so away mode, a pause, and quieted nudges hold a nudge back here exactly as they do on the desktop. Turning nudges off in the extension's options page stops it asking at all.
Where it is kept, and how to get rid of it
- In Hawser, on your computer, in a plain JSON file alongside its others, for 30 days, after which each day drops off on its own. You can read the whole of it under Settings, About and advanced, Agent access, as "Where your browsing time went today", and the Forget button there deletes every site and every minute of it at once. "Wipe all data" deletes it along with everything else. It is never uploaded and sync does not carry it, but you can take a copy away with you: "Download my data", under Settings, Backup and restore, puts it in the zip as declared_activity.json, and the README inside that zip names it alongside everything else.
- In Hawser's own settings file, one entry per connected browser: what it calls itself, the random number it made up for itself, which version of the extension it is running, when it last called, and the state of its own switches, so Settings can show you what is connected and say plainly when a browser is running an out of date copy. Plus, if you turned a browser away, the count and timestamps described above. Disconnecting that browser in Settings removes its entry, and the button beside it clears the record of any no.
- In your browser, the extension's own storage. In full, it holds: the key Hawser issued and the port it listens on, the result of the last connection and when a call last worked; the random number that identifies this copy; while it is being connected, the pairing request number and when it is worth asking again; the seconds counted but not yet sent and the stretch in progress, each held against a bare site name; a stamp saying that the site in front changed, never saying to what; any nudge currently on screen with the words, how Hawser asked for it to be drawn, and how it actually ended up drawn; the numbers of the tabs a card was drawn in, so it can be taken back off them; what Hawser last said about this copy's version; and your on and off switches. With them, the clocks and outcomes that go with all of that: which nudge those tabs are carrying, when the extension last tried to draw one and what happened, the ids it still owes Hawser as acknowledgements, when it may next ask, and the timestamps marking when it last sent and the window the counted seconds cover. No page address is kept there, because none is kept anywhere. Disconnecting throws all of it away with the key, and so does removing the extension. If Hawser cannot be reached, counted seconds wait for the next attempt; once they have waited twelve hours they are dropped rather than kept.
- The switches. Three in the extension's options page, and any of them can be turned off at any time. "Report where my browsing time goes" stops the counting. "Let Hawser nudge me here" stops the extension asking Hawser for anything to say. "Show Hawser's nudges on the page I am on" stops anything being drawn on a page, and hands the website access back as it goes. A fourth control, how the card is drawn, lives in Hawser rather than in the browser, under Settings, About and advanced, Agent access. Revoking a browser inside Hawser, under Settings, Agent access, stops it from the other end.
Limited Use. Our use of information received from the Hawser browser extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. The extension collects only what its single purpose needs, uses it for nothing else, transfers it to nobody, and sends it nowhere but the Hawser app on your own computer.
Installing the extension is between you and Google. Google tells us how many people have it installed, as a count, and nothing about who they are.
2. Where your data lives
- On your computer: activity logs, screenshots are never stored anywhere; everything else, chat history, daily missions, profile facts. All in plain JSON files under your local Windows user profile, which you can open and read in any text editor. The text of anything you have dictated is kept here too, in a file alongside them. It goes nowhere else on its own: the only way it leaves this computer is if you export your own data and choose to include it, which the export asks you about every time.
- On your computer, from the browser extension (only if you install it): the name of each site you spent time on and how long, per day, for 30 days. Another plain JSON file alongside the others, described in section 1d. It is never uploaded. Hawser's own settings file also holds one entry per connected browser: what it calls itself, the random number it made up for itself, its extension version, when it last called, and its own switches, so you can see what is connected and disconnect any of it on its own.
- In your browser (only if you install the extension): the extension's own storage holds the key Hawser issued it, the port and the last connection result, the random number that identifies this copy, any seconds counted but not yet sent, any nudge currently on screen with how it was drawn, the tabs a card was drawn in so it can be taken back off them, and your switches. Section 1d lists it in full. Disconnecting or removing the extension deletes all of it.
- Cloudflare Workers KV (United States): account record (email + hashed password + metadata), active sessions, Stripe customer ID, license token, and the daily website usage counts described in section 1b.
- Cloudflare D1 (United States): if you turn sync on, the work described in section 1b (captures, notes, missions, tasks, goals, reminders and flashcards), stored against your account so your devices stay in step. Nothing is stored here until you switch sync on.
- Stripe (United States): payment details, billing history, subscription status.
- Resend (United States): outbound transactional emails (sign-in confirmations, magic links, account notices).
- Anthropic (United States): chat messages and (if you opt in) screenshots, processed at the time of each API call. We do not opt into Anthropic's training data use; per Anthropic's commercial terms your data is not used to train their models.
- OpenAI (United States): voice-dictation audio, processed at the time of each transcription request when you use cloud voice input. Not retained beyond the request; not used to train their models per OpenAI's API terms.
International transfers. Our infrastructure and the vendors above are based in the United States. If you use Hawser from the European Economic Area or the United Kingdom, your personal data is transferred to the US under the Standard Contractual Clauses or another lawful transfer mechanism. If you would rather no data leave your device at all, use Fully Local AI mode in Settings, where chat and screenshots are processed entirely on your own machine.
3. Why we collect what we collect
- To run your account and subscription (email, password hash, Stripe customer ID, license token, session tokens).
- To give Hawser the context it needs to actually help you (daily missions, chat history, profile facts - kept locally on your machine).
- To respond to your messages (chat content sent to Anthropic in cloud mode).
- To tell focused browsing from drift (the site names and minutes the browser extension reports, if you install it, kept on your computer, along with the small facts that say which browser reported them and which version of the extension it is running).
- To fix bugs (crash reports).
- To email you about Hawser itself (your account email). If you make an account, we may occasionally write to you about the product you signed up for: how to get started if you never did, what has changed since you last looked, and sometimes a direct question about what would make Hawser worth paying for. These come from a person, not a mailing machine, and they are rare. Every one has a one-click unsubscribe that we honour immediately, and unsubscribing never affects your account or your access. We do not send you anything about anyone else's product, and we never sell or share your address.
We do not sell personal data. We do not use it for advertising. We do not run ad-network tracking pixels on this website.
3a. Legal basis for processing (GDPR)
If you are in the EEA or UK, our legal bases under Article 6 GDPR are:
- Contract: running your account and subscription and providing the focus features you signed up for.
- Legitimate interests: keeping the service secure, preventing abuse, fixing bugs, the local activity monitoring that makes Hawser work - balanced against your privacy by keeping that data on your device by default - and writing to people who signed up for Hawser about Hawser, which you can stop with one click at any time.
- Consent: optional features you switch on yourself, such as sync of your notes and brain dump entries, cloud screenshot analysis, cloud voice transcription, connecting the Hawser browser extension (which you allow on a card Hawser shows you, and can revoke per browser), letting that extension show a nudge on the page you are reading, and anonymous usage statistics. You can withdraw consent at any time in Settings, and for the extension's access to websites, in its options page or in your browser's extensions page.
- Legal obligation: keeping limited payment and tax records as required by law.
4. Third-party services
We rely on a small number of vendors to operate Hawser. Each has its own privacy practices:
- Stripe - payment processing
- Cloudflare - account storage (Workers KV), website hosting (Pages)
- Resend - transactional email delivery
- Anthropic - AI inference (cloud mode only)
- OpenAI - cloud voice transcription (when you use cloud voice input)
- Sentry - crash and error diagnostics (when crash reporting is enabled)
These vendors act as our data processors: each processes personal data only on our instructions, and may engage its own subprocessors as described in its policy. We do not sell personal data to any of them. A current list of subprocessors is available on request from support@gethawser.com.
5. How long we keep your data
- Account records: retained for as long as your account exists, plus a short retention window after deletion for legal and accounting purposes.
- Sessions: automatically expire (typically 30 days) and are deleted from our storage.
- Magic-link tokens: 15-minute expiry, deleted on use.
- Local data files: stay on your computer until you delete them (in-app "Wipe all data" or by uninstalling Hawser).
- Browsing totals from the browser extension: 30 days on your computer, then each day drops off on its own. The Forget button under Settings, About and advanced, Agent access deletes all of it at once.
- The record of a browser you turned away: a count and two timestamps, kept on your computer while that browser is in its waiting period and swept out once it is well past. The button in Hawser that lets browsers ask again clears every one of them at once.
- Synced work: kept until you delete it, delete the server copy, or delete your account. We do not expire it on a timer, because it is your working material and disappearing notes would be worse than useless. Daily missions follow the app's own local window of roughly the last 60 days.
6. Your rights
You can, at any time:
- See what's on your computer: open Hawser → Settings → Data & Privacy.
- Wipe local data: Settings → Data & Privacy → "Wipe all data."
- See, keep and delete where your browsing time went: if you use the browser extension, Settings → About and advanced → Agent access lists it and forgets all of it on one press. To keep a copy, Settings → Backup and restore → "Download my data" includes it in the zip.
- Disconnect a browser, one at a time: Settings → About and advanced → Agent access lists every browser you have connected and revokes any of them on its own, which stops that browser dead without touching the others.
- Take back the extension's access to websites: untick "Show Hawser's nudges on the page I am on" in the extension's options page, or use Site access in your browser's extensions page. Either hands the access back, takes down any card on screen, and leaves the rest of the extension working.
- Delete your synced copy without deleting your account: if you turned sync on, Settings → Sync lets you delete everything we hold on the server while your notes and brain dump entries stay on your own computer.
- Stop hearing from us: use the unsubscribe link in any email we send you about the product, or reply and say so. We will still send the things your account needs, such as a sign-in link, a receipt, or a security notice, because those are not marketing and you cannot really opt out of your own receipts.
- Cancel your subscription: Account → Manage Subscription.
- Delete your account: in Hawser, open Settings → Account → "Delete my account." This immediately deletes your account from our servers, including anything you synced, and cancels your subscription, then offers to erase your on-device data too. You can also email support@gethawser.com and we will delete your account record and sessions within 30 days. Limited records we are legally required to keep (for example, tax records for completed payments) may be retained as required.
- Get a copy of your data: for the data on our servers, open Settings → Account → "Export my data" (downloads a JSON file, including anything you synced), or email support. For the data on your computer, use Settings → Data & Privacy → "Export My Data," which asks each time whether to include the text of what you dictated and leaves it out if you say so, or Settings → Backup and restore → "Download my data" for a zip of the local files themselves, browsing totals included, with a README listing what is in it.
If you are in the European Economic Area, the United Kingdom, or California, you have additional rights under GDPR and CCPA, including the right to object to processing, the right to data portability, and the right to lodge a complaint with your local data protection authority. Email support to exercise any of these.
7. Security
Passwords are hashed with PBKDF2 (salted, many iterations) before storage - we cannot read your password. All connections between Hawser and our backend use HTTPS. Session tokens are stored in Windows Credential Manager on your device. For extra protection you can turn on at-rest encryption of your local Hawser data in Settings → Privacy (note: if you lose access to your Windows account, encrypted local data cannot be recovered). Despite this, no system is perfectly secure. If we ever become aware of a breach affecting your account, we will notify you by email without undue delay.
8. Children
Hawser is not directed at and is not intended for use by anyone under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected data from a child, contact us and we will delete it.
9. Changes to this policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top. If the changes are material, we will additionally notify you by email. Continuing to use Hawser after changes take effect means you accept the updated policy.
10. Cookies & tracking
Hawser uses no advertising, analytics, or cross-site tracking cookies. The website (gethawser.com) sets no cookies at all: if you sign in, your session token is kept in your browser's local storage to keep you signed in, and the desktop app stores its session token in Windows Credential Manager on your device. If you use the phone capture app at gethawser.com/app, that page also keeps your own content in local storage: anything you capture is written there before it is sent, so a dead zone cannot lose it, and a copy of your notes and recent captures is kept so the app still works with no signal. It stays on your device, it is only ever sent to your own Hawser account, and signing out of that page deletes it. The Hawser browser extension sets no cookies either, and its nudge card sets nothing in the pages it appears on: what it keeps, meaning its key, any seconds it has not sent yet, any nudge on screen, the random number that identifies that copy of it, and your switches, lives in the extension's own storage and is deleted when you disconnect it or remove it. Section 1d lists that storage in full. Because we set no tracking cookies, there is no cookie banner. The website usage counts described in section 1b are cookieless as well: they store nothing in your browser and identify no one.
11. Contact & data controller
Hawser is operated by Cook Impact Software LLC (Idaho, USA), the data controller for the personal data described in this policy.
Questions about this policy, or to exercise any of your rights (access, deletion, portability, objection), email support@gethawser.com with the subject "Data Rights Request." We respond within 30 days. If you are in the EEA or UK and are not satisfied with our response, you may lodge a complaint with your local data protection authority.