Privacy Policy
Draft for review by a lawyer. Not in force yet. Last updated: 12 October 2026.
The Astrolinks app ("the app") is a small app for Mac and Windows computers made by Astrolinks ("we", "us", "our"). In this policy, "Astrolinks" and "we" always mean the company, and "the app" always means the software on your computer. The app keeps a private log of what you work on, so it can write your end-of-day reports for you. This policy explains what the app records, where it is kept, what leaves your computer and when, who else can receive it, how long it is kept, and what your rights are.
The short version
- The app collects data about your work. While it runs, it records which app is in front, the window's title, when you started and stopped, and, in supported browsers, the address of the web page you're on (without anything after "?" or "#"; you can tell it not to keep addresses). It also keeps the notes you write, your clients and your profile.
- It starts only when you say so. Nothing is recorded until you accept the first welcome step.
- That log stays on your computer. We never receive it. There is no Astrolinks account that holds it and no copy of it on our servers.
- It never records keystrokes, screenshots or screen video, your clipboard, sound, or your camera.
- Nothing leaves without a click. The first time, the app asks whether you want to use AI at all. After that, when you press Write with AI or send a chat message, a summary of your day goes to Claude, an AI made by Anthropic, to write or change your report. When you press Send to Slack, your report goes to that client's Slack. Email draft opens your own email app. If you join a company's team, a report goes to its Team inbox only when you send it there, with your hours only if you choose to include them.
- Claude gets a summary, not your log. Web addresses are cut down to the site's name, emails and phone numbers are hidden unless you turn that off, and clients you mark Private are never sent at all.
- We don't sell your data. The app has no ads, no analytics, no tracking and no crash reporting.
- You can delete it. The app deletes daily entries after 14 days (you can choose 1 to 365) and hour totals after 13 months, and you can delete everything at any time.
What the app records on your computer
When it starts
The app records nothing, not even which app is in front, until you accept the first welcome step. That step says what the app records and that by continuing you agree to the Terms of Use and this policy. Until then the app's menu and today's log say "Not counting yet". If you finished the welcome steps in an earlier version, nothing changes for you.
After that, on a Mac the app records only app names until you allow window titles. On Windows, reading window titles needs no permission. The app reads web addresses only after the welcome steps are done or skipped. You can stop it at any time with Pause counting, in the app's menu (in the menu bar on a Mac, or in the notification area of the taskbar on Windows).
Your activity log
Every 5 seconds, while the app is running and not paused, it looks at the window in front and records:
- The app's name and an identifier for it. On a Mac that is its bundle identifier (for example
com.google.Chrome). On Windows it is the location of its program file (for exampleC:\Program Files\Google\Chrome\Application\chrome.exe), which can include your Windows user name. - The window's title. On a Mac, only once you allow window titles: macOS calls this permission Screen Recording, but the app only reads window titles and never captures your screen. Without it, only app names are recorded. On Windows, no permission is needed.
- The address of the page you're on, without anything after "?" or "#" (those parts can hold sign-in tokens and IDs), and only http and https addresses. On a Mac, in Chrome, Edge, Brave, Vivaldi, Chromium, Arc and Safari, once you have finished the welcome steps and allowed it for that browser. On Windows, in Chrome, Edge, Brave and Firefox (see "On Windows"). You can turn this off with Record web addresses, in Settings, Privacy and data. The app then keeps only a browser's window title. It still reads the address for a moment, to skip private windows and sites on your "Never record" list and to recognize calls, but doesn't keep it.
- When each entry started and ended, and which client it is for (your rules decide, or you choose).
Window titles and page addresses can contain names of people, document names, email subjects, chat names and other details. The app keeps them as they are, on your computer, so your summary can say what you did. You can delete any entry, and you can tell the app never to record an app, a website or a word.
On Windows
The Windows version is new. It differs from the Mac version in these ways:
- Web addresses. The app reads the address shown in the address bar of Chrome, Edge, Brave and Firefox through Windows' accessibility interface, the same one screen readers use, with a small helper program that comes with the app. Vivaldi and other browsers are recorded by their window title only. The helper never reads the address bar while the browser's toolbar has the keyboard focus, so it doesn't read what you are typing there. It reads only the window in front, only when the app asks, and makes no connections of its own. If it doesn't answer in time, or anything is unclear, the app keeps the window title and drops the address.
- Text left in the address bar. If you type something into the address bar and click back into the page without pressing Enter, the browser keeps showing what you typed. If that looks like a web address, the app may record it as the page's address until the page changes.
- Private windows. Incognito, InPrivate, Guest and private windows are skipped completely, title included, when the browser says so to screen readers or in the window title. When the app can't tell, it keeps the title and drops the address. Copies of the app built without the helper record browsers by their window title only, and then Chrome's incognito windows are recorded like any other window, because their title doesn't say so.
- Never record, for websites. In browsers that don't give the app their address, a website on your "Never record" list can only be recognized by a word in its window title. To be sure a site is skipped there, add a word from its title, such as your bank's name, to "Never record".
- Calls. Calls are recognized by their window title (for example a Zoom meeting or a Slack huddle), or by their web address in a browser that gives one. Time in other call apps is counted like any other time, so a long call without touching the keyboard or mouse can be taken back as time away.
- Start with Windows. The app's menu has Start with Windows. It is off until you turn it on.
- Where it is kept. See "Where it is kept". It depends on whether you installed the app from our website or from the Microsoft Store.
Reading a browser's address bar this way makes Chrome turn on its support for screen readers while the app runs, which costs Chrome a little memory and processor time.
What it checks but doesn't keep
(With the detailed breakdown on, the first of these is also kept per entry, as described below.)
- How long it has been since you last used the keyboard or mouse (never what you typed or clicked), so time away isn't counted. During calls it keeps counting, if you leave that setting on: on a Mac, calls in Zoom, Teams, Google Meet, Webex, FaceTime, Skype and RingCentral; on Windows, see "On Windows".
- Whether your screen is locked or your computer is asleep, and on a Mac whether another person has switched to their own account on it.
- Whether a browser window is private, so it can skip it.
Detailed breakdown (only if you turn it on)
The detailed breakdown is off until you turn it on in Settings, Privacy and data, and say yes to a question that lists what it adds. While it's on, the app checks every 2 seconds instead of 5, and for each entry keeps how much of the time had keyboard or mouse use in the last few seconds ("hands-on") and how much didn't ("reading"). That comes only from how long ago you last used the keyboard or mouse, which your computer already tells apps; never which keys, how many, or anything you typed. The breakdown's items, kinds of work, focus blocks and interruptions are worked out when you look, not stored. Hands-on and reading time never go into a report, to Claude or to a team. Items and times go into a report only when you tick "Include the detailed breakdown" for it. A company can't turn it on or see it. Turning it off stops it and offers to delete what it kept; it also goes with its day.
What it never records
- Keystrokes or anything you type in other apps
- Screenshots or screen video
- Your clipboard. The app never reads it. It only puts text on it when you press Copy or Copy as table, or when a report is too long for an email draft.
- Sound, your microphone or your camera. On a Mac, the mic button turns on Apple's Dictation, which works under Apple's terms. The app never receives the audio.
- Your location
- The contents of your files, emails or messages, beyond what their window titles show
- The app's own windows
- Apps, websites and words on your "Never record" list. It starts with password managers and many banking and payment sites, and you can change it in Settings, Privacy and data. Websites are recognized by their address, so only in browsers that give the app their address (the browsers above, after the welcome steps). In other browsers, add a word from the site's window title.
- On a Mac, private windows in Chrome, Edge, Brave, Vivaldi, Chromium and Arc (once you allow web addresses for that browser) and in Firefox (once window titles are on). If one of those browsers doesn't answer, the app skips that window. Safari doesn't tell the app when a window is private, so Safari private windows are recorded like any other window; pause the app first if you don't want that. On Windows, see "On Windows".
- On Windows, Incognito, InPrivate, Guest and private windows in Chrome, Edge, Brave and Firefox, when the browser says so (see "On Windows").
What you give it
- Your notes (quick notes, blockers, plans for tomorrow)
- About you: your name, your role, a sentence about your work, the tone and style of your reports, your language, your sign-off, and things to always or never mention
- Your clients: each one's name and rules, what you do for them, who reads their report, the report's sections, your instructions, whether they are Private, their email address, their Slack link, and an hourly rate and currency if you bill by the hour
- For a client, if you set them: their time zone, the language their report is written in, and a report they liked that you pasted for "Write like this one" (up to 3,000 characters)
- Your tasks and goals: each task's name, client, due date, keyword, when it was made and done, a note when it was done and the day you planned it for; each goal's kind, period and target. Time toward a task or goal is worked out from your log when you look; it isn't stored.
- Your invoice details, if you make invoices: your name or business, address, how clients pay you, each client's billing name and address, and the invoice numbers you used (number, client, dates, when). No amounts or work items are kept with them.
- Your settings (shift, shortcuts, what to never record, how long to keep things, the app's language, text size, break reminders and the morning plan)
- Your Anthropic key or your Pro license key, if you add one
- Your team, if you join one: the team's name, your name in it, the member key that lets this computer send to it, and a list of the reports you sent from this computer (the day, the client, the hours if you included them, and when you sent it)
Hour totals
Just before the app deletes an old day, it keeps that day's hours, so the Hours window can show older weeks and months: minutes for each client, and for each work item a short label from that day's summary (for example "Halcyon invoices Oct (Google Sheets)") with its minutes. Web and email addresses are taken out of the labels. Labels are often based on window titles. No entries, full window titles, web addresses or notes are kept. Hour totals are kept for 13 months. You can turn this off in Settings, Privacy and data, which deletes the totals already kept.
Where it is kept
- On a Mac, in
~/Library/Application Support/Astrolinks/. - On Windows, if you installed the app from our website, in
%APPDATA%\Astrolinks\. If you installed it from the Microsoft Store, Windows keeps it in the app's own package folder,%LOCALAPPDATA%\Packages\<the app's package>\LocalCache\Roaming\Astrolinks\. - Settings, Privacy and data has Open data folder, which opens the right folder in either case.
- It is a few plain files:
settings.json,clients.json,secrets.json,team.json(only if you joined a team),tasks.json(your tasks and goals),invoices.json(only if you make invoices),outbox.json(only while a report waits to send),window.json(the main window's size and place), one file per workday indays/(with a.detail.jsonbeside it while the detailed breakdown is on), and one file per month intotals/, plus folders such asCache/that the app's framework (Electron) keeps for itself. - Your Anthropic key, your license key, your Slack links and your team member key are encrypted with your operating system's protected storage (the Keychain on a Mac, DPAPI on Windows). The app's windows only ever show the last four characters of a key or link, and nothing at all of the team member key.
- Everything else is plain text that anyone who can use your computer account can read. We recommend turning on full-disk encryption (FileVault on a Mac, BitLocker or Device Encryption on Windows).
- Backups of your computer, such as Time Machine or File History, may include this folder.
- Files you save yourself (Save as file, Export CSV) go where you choose. They are yours, and the app never deletes them.
How long it is kept, and how to delete it
| What | How long |
|---|---|
| Activity entries and notes | 14 days, or the number of days you choose from 1 to 365 (Settings, Privacy and data). Older days are deleted automatically when the app starts and every hour while it runs. |
| Hour totals | 13 months, or not at all if you turn them off |
| Your profile, clients and settings | Until you change or delete them |
| Your keys and Slack links | Until you remove them. A client's Slack link is removed with the client. |
Your team and the list of reports you sent to it (team.json) |
Until you leave the team. Delete everything clears the list of sent reports; you stay in your team. |
To delete:
- One entry or note: delete it in today's log.
- Today: Delete today, in the log or in Settings, Privacy and data.
- Everything the app recorded: Delete everything removes every day, all hour totals, the words you added to the spelling dictionary, and the list of reports you sent to your team (you stay in your team, and reports already sent stay with it). Your settings and clients stay.
- All of it: Remove everything, in Settings, Privacy and data, Advanced, deletes the app's whole folder, after asking, and then quits. On a Mac it also deletes the key that unlocked your saved keys from the Keychain ("Astrolinks Safe Storage"). On Windows, that key is kept inside the folder, so it goes with it. You can also quit the app and delete its folder (above) yourself; on a Mac, then delete "Astrolinks Safe Storage" in Keychain Access too.
- Removing the app: on a Mac, removing the app does not delete its folder. On Windows, uninstalling the copy from our website removes the app and its Start with Windows entry but keeps the folder. Use Remove everything first, or delete the folder yourself. If you installed the app from the Microsoft Store, Windows deletes the folder when you uninstall it.
- Data from earlier test builds: builds made during development used the names Clockout, Dotfall and Astrolog, and the app copies the newest of their folders on its first run without deleting it. If those folders are on your computer, Settings, Privacy and data, Advanced shows them with their sizes and deletes them.
Because your log is only on your computer, we can't see it, recover it, or delete it for you.
What leaves your computer, and when
Only what you send, when you press a button:
| You press | What is sent | Where it goes |
|---|---|---|
| Write with AI | A summary of your day for that client, your profile and that client's context (see below) | Anthropic's Claude, either directly or through our AI service |
| A chat message | The same summary, the report as it is in the box, up to 12 earlier chat messages and your new message | The same |
| Test it | Your key or license and the name of the model, to check they work. No content. | The same |
| Send to Slack, then Send | The report | The Slack channel that client's Slack link was made for |
| Email draft | The report, the client's email address and a subject | Your own email app, as a draft. Nothing is sent until you send it there. |
| Join a team (in Settings) | The invite code and the name you give | Our Team service, run on Cloudflare |
| Send to your team, then Send | The report's text as you approved it, its client's name, the blockers read from it, and your hours only if you switch them on | Your company's Team inbox, on our Team service |
| Take back (a report sent to your team) | Which report to delete | Our Team service, which deletes it from the inbox |
| Leave team | That you're leaving, and whether to delete every report you sent | Our Team service |
| Report an AI answer (in the summary's More menu) | Opens an email draft to us with only the app's version, your system and a "What was wrong?" line. Your report isn't in it unless you add it. Nothing is sent until you send it. | Your own email app, then us |
| Send to Slack or Send to your team, while you're offline | The same report, later: it waits on this computer and goes by itself once the connection is back, for up to 24 hours, then the app tells you. You can cancel it while it waits. A report that was refused is never retried. | The same place |
| Mark done (a task your team gave you) | Which task, and your note if you write one | Our Team service, for your managers |
| Upgrade (on the Plan page) | A random claim code, in the web address of our pricing page, after the # so the website never receives it | Your web browser, then Paddle's checkout |
| Check again (after Upgrade), or the app waiting for your new license | The claim code | Our AI service, which hands back the new license once, within 24 hours |
| Manage plan | Your license key | Our AI service, which asks Paddle for your customer portal link |
| Opening the Plan page | A request for the plans' prices, with no key | Our AI service, which asks Paddle with your internet address and keeps nothing |
| Make invoice, then Save | Nothing leaves | A PDF or CSV file where you choose |
| Copy, Save as file, Export CSV | Nothing leaves | Your clipboard, or a file where you choose |
While you're in a team, the app also asks our Team service for tasks your managers gave you: when it starts, every 15 minutes, and when you come back to the app (at most once a minute). It sends only your member key, and gets back your tasks. This is one of two connections the app makes without a click, and only while you're in a team. The other: while a license is saved, the app asks our AI service about it at most once a day, sending only the license key, to know your plan and its renewal date (see "Buying a plan and your license"). After you press Upgrade, the app also asks for your new license every few seconds for up to 15 minutes.
Links you click in the app open in your web browser.
The app has no analytics, no crash reporting, no advertising and no tracking, and it doesn't check for updates by itself. Spelling is checked only on a Mac, with the Mac's own dictionaries; on Windows spell checking is off, so no dictionaries are downloaded. On Windows, the helper that reads browser addresses makes no connections. The app makes no other connections than the ones in the table above.
Your operating system may make its own connections about the app, for example when macOS checks that a download was approved by Apple, or when Microsoft SmartScreen or the Microsoft Store checks an installer. Those happen between you and Apple or Microsoft, under their terms.
Writing with AI
The app can write your reports with Claude, an AI made by Anthropic, PBC. Before anything about your day first goes to Claude, the app asks once whether you want that, and shows what Claude would see. If you say Not now, nothing goes. You can change your answer any time with Let Claude read a summary of your day, in Settings, AI. After you say yes, something is sent only when you press Write with AI or send a chat message. Without AI, the app still writes a summary on your computer.
What Claude gets
- Your day, already summarized on your computer: the date and your shift, the total time, and for that client the work items with their times (short labels that often come from window titles, such as "Updated the October invoices (Google Sheets)"), your calls, email and chat lines (which can include names of people from window titles), and your notes.
- About you: your name, role, the sentence about your work, tone, style, language, sign-off, and what to always or never mention.
- About the client: their name, what you do for them, who reads the report, your instructions and the sections you want; their time zone and report language if you set them; and the report they liked, if you pasted one for "Write like this one" (for its shape and tone only, with emails and phone numbers hidden).
- Your tasks, if the report includes them (it does unless you untick it): the names of tasks done that day and those still open, without times.
- The detailed breakdown, only if you ticked it for that report: each item and its times. Never hands-on or reading time.
- For a weekly recap: the same, for each day of the week you kept.
- For a chat message: also the report as it is now (with your own edits), up to 12 earlier messages in that chat, and your new message.
What Claude sees, in Settings and in the summary window, shows exactly this text before you send anything.
What Claude never gets
- Your activity log itself: no entries, no full window titles list, and no full web addresses. Any web address is cut down to the site's name, so
https://www.zillow.com/homedetails/...becomeszillow.com. A name and password written into an address are taken out, other kinds of addresses become just their host, and a local file's address becomes "a local file". In a folder path, your account's folder name is taken out, soC:\Users\Ana\Documents\plan.docxgoes as~\Documents\plan.docx; file and folder names after it can still be sent. - Emails and phone numbers, while "Mask emails and phone numbers" is on (it is on unless you turn it off). This includes emails written out in words ("maya at example dot com") and phone numbers with or without spaces, such as 0917 123 4567, 09171234567 or +1 415 555 0123. They become placeholders like
[email 1]and[phone 1], and the real ones are put back into the answer on your computer. - Anything about a client you mark Private. In a report for all clients, private clients are left out.
- Notes, window titles, your profile, a client's context, and the report in the box when they suggest you may be at risk of harming yourself (see "If something you write suggests you may be at risk"). A window title like that shows as "Personal browsing" in your summary and your hour totals.
Masking is not perfect. Names, street addresses, account numbers, file names and folder paths shown in window titles, or other details in your work items, notes or profile can still be sent. Check What Claude sees, mark sensitive clients Private, add words to "Never record", and use "Never mention" in Settings. If your work shows you patients' or other people's private records, mark that client Private unless your client has agreed otherwise (see our Terms of Use, section 3).
Two ways to connect
- Your own Anthropic key. Requests go straight from your computer to Anthropic, under your own agreement with Anthropic, and we never see them. As with any connection, Anthropic also receives your network (IP) address and the standard technical details the Anthropic software library sends with each request: your operating system, its processor type, and the versions of the library and of the framework the app is built on.
- AI included with Pro. Requests go to our AI service, a small program we run on Cloudflare Workers. It checks your license, rebuilds the request from only what the app sends, passes it to Anthropic under our Anthropic account, and streams Claude's answer back to you. It does not store or log what you send or what Claude writes. For each request it writes one line to a live log that is not kept: the result (for example "200") and the first 12 characters of a fingerprint of your license. It does not pass your network address, cookies or other details from your computer to Anthropic. With each request it sends Anthropic a pseudonymous code for your license (not your name, email, license key or network address), so that misuse can be traced to a license. To keep the service fair and safe, it limits how many requests one network can make, counting a keyed fingerprint of your network, in memory and in Cloudflare's rate limiter; it never keeps the address itself. For each license it keeps the plan, status, end date and daily limit, filed under a fingerprint of the key (never the key itself), and a counter that holds only the latest day (how many requests, roughly what they cost, and the requests running at that moment), this calendar month's number of AI writes and edits (for the fair use in our Terms, and Free's monthly reports), and when it was last used. Each new day replaces the last day, each new month the last month, and a counter not used for 35 days is deleted.
Anthropic
For the AI included with Pro, Anthropic processes your requests on our behalf, as our service provider, under Anthropic's Commercial Terms of Service. Under those terms, Anthropic does not use content sent through its API to train its models. Anthropic deletes API requests and answers within 30 days, unless it needs to keep them longer to enforce its Usage Policy (for example a request its safety systems flag, which it may keep for up to 2 years) or the law requires it. Anthropic's own privacy policy is at anthropic.com/legal/privacy.
What Claude writes
Claude's report is a draft. It can be wrong or leave things out. Read it, and fix it, before you send it to anyone. If Claude ever writes something harmful or inappropriate, use Report an AI answer, in the summary's More menu, or write to info@astrolinks.org. Add only what you are comfortable sharing.
If something you write suggests you may be at risk
If a chat message or a quick note suggests you may be thinking about suicide or hurting yourself, the app doesn't treat it as part of your report. This check happens on your computer.
- A chat message like that is not sent to Claude, even before you have said yes to AI. The app answers with a few kind words and crisis lines you can call any time: in the Philippines, the NCMH Crisis Hotline (1553 from a landline, or 0919 057 1553 or 0917 899 8727 from a mobile); in the US, the 988 Suicide and Crisis Lifeline (call or text 988); and your local emergency number (911 in the Philippines and the US). Your report stays as it was.
- A note like that is saved in your log on your computer like any other note, but it is left out of your summaries and out of anything sent to Claude.
- Earlier chat messages like that are left out when later messages are sent. If words like that are in your profile, a client's context or the report in the box, they are left out too, or, for the report, the chat answers with the same kind words and sends nothing.
- If something gets past this check and reaches Claude, Claude is asked to answer the same way and never to put it in your report.
The app doesn't log when this happens, and we are never told.
Slack and email
- Slack. When you press Send to Slack and confirm, the app posts the report to the Slack link (an "incoming webhook") you saved for that client. Only links that start with
https://hooks.slack.com/are accepted. The report then belongs to that Slack workspace, under Slack's terms and the workspace owner's rules. We don't receive it. - Email. Email draft opens your own email app with a new message to the client's email address, with the report in it. The app doesn't send email. When you send it, your email provider handles it.
Buying a plan and your license
- Checkout is handled by Paddle, in your web browser, never inside the app. Paddle receives your name, email address, country, billing details and card details, and is the seller. We never receive your card details.
- What we keep for each paid license, in our service on Cloudflare: a fingerprint of the license key (never the key itself), Paddle's subscription and customer ids, the plan, the number of seats, the subscription's status, the billing interval, when the paid period ends and when the plan is set to end, and the ids of Paddle notifications already handled (for 30 days). No name, email, address or card details: they are removed from Paddle's notifications before anything is kept, and notifications are never logged. Ninety days after a subscription ends, this is deleted.
- Your new license reaches the app by itself. The app makes a random claim code and puts it in checkout. When Paddle confirms the payment, our service keeps the new license key, sealed with that code, until the app (and once, the website's thank-you page) picks it up, for at most 24 hours. Then nothing of the key is kept.
- Manage plan sends your license key to our service, which asks Paddle for a link to your customer portal and passes only that link back.
- Prices where you are. The Plan page asks our service for the plans' prices; our service asks Paddle with your internet address so Paddle can show your country's price. We keep nothing of it and don't log your address.
- A free license. If you use the AI included with Pro without a license (during the trial, or on Free), the first Write with AI asks our service for a free license. Nothing about you is sent except, to limit misuse, your connection reaches our service like any request (see "Writing with AI"). Our service keeps the same kind of record as for any license: a fingerprint, the plan, its trial end date, and a count of this month's reports.
- Checking your plan. The app asks our service about your license, sending only the key, when you save or receive one, when you open Plan, and at most once a day while a license is saved. The answer includes this month's number of AI writes and edits, so Plan can show it. On your computer, the app keeps the last answer in
plan.json(plan, status, renewal or end date, interval, seats, whether it comes with a team seat, this month's AI writes and edits as our service counted them, when it was checked), this month's counts of reports and AI uses with the AI included with Pro, which plan reminders it has shown, and when Pro started. - Pro through your team. If you are in a Team or Business workspace, the app asks our AI service whether your company pays for your seat: when you join, when you leave, when you open Plan, and at most once a day. It sends your team member key (and your license key, if you have one). Our AI service passes the member key to the Team service only to ask which workspace you are in and whether it pays, and doesn't keep or log it. If it pays, your license is marked as that workspace's seat, with its plan, for a few days at a time; if not, the license is free again. Nothing about your log, reports or activity is sent. It also keeps when your 7-day trial ends (
trialEndsAtinsettings.json). Remove everything deletes all of it. - If you get the app from the Microsoft Store, Microsoft handles the download, and anything you buy there, under Microsoft's own terms and privacy statement. The app sends Microsoft nothing.
- If you email us, we keep the conversation so we can help you.
The Team plan
With the Team plan, a company pays for its workers' seats and gets a web inbox where its managers read reports.
- A worker's report reaches the company only when the worker presses Send to the team and then Send, after seeing exactly what goes. Joining sends the invite code and the name the worker gives. Taking a report back, and leaving, are calls to the same service.
- What the company gets with each report: its text as the worker approved it, its client's name, the blockers read from it, and the worker's hours only when the worker switches them on (they are off unless the worker chooses them).
- The company never sees the worker's activity log, entries, apps, websites, notes, hour totals, AI chat, or anything else the worker didn't send. The Team service has nowhere to store any of it.
- Managers can read, copy, export and delete the reports in their inbox, see who has sent a report that day, and remove people from the team.
- Before joining, a worker can read what the company will see on the Team service's own page for invited people.
What the Team service keeps, in a database we run on Cloudflare (D1) for the company:
- For each worker: the name they gave (and the same name in a simplified form, so two people in a team can't use names that look the same), when they joined, when they last sent a report, and a fingerprint of their member key (never the key) with when it was made. The app swaps the member key for a new one every 30 days; the old one's fingerprint is kept for up to 7 days after a swap, so a lost answer never locks anyone out.
- The reports they sent, with the time each was sent.
- For each manager: their email address, name, a slow fingerprint of their password (never the password), whether they must choose a new password, and when they last signed in. If they turn on two-step sign-in: the secret for their authenticator app, kept sealed (encrypted), when it was turned on, and the last code step used, so a code works only once; and a fingerprint of each unused recovery code. The secret and the codes are deleted when two-step sign-in is turned off, or with the workspace.
- A sign-in that is halfway (the password was right, the code is still to come): a fingerprint of its token, for 5 minutes at most.
- Signed-in browsers: for each one, for up to 7 days, a fingerprint of its token, a random id to sign it out by, when it started, was last used and ends, a short label such as "Chrome on macOS" (never the browser's full description), the two-letter country Cloudflare says the sign-in came from (never the network address), and whether it passed two-step sign-in.
- An activity log the managers can read, kept for 180 days: the time, what happened (for example a sign-in, a wrong password or code, an invite made, someone joining, leaving or removed, a report deleted, a setting changed, the CSV downloaded), who did it (the manager's email or the worker's name), a few details (such as an invite's note, or whose report for which day), the browser label and the country. Repeated wrong tries within 15 minutes are one entry with a count. It never holds what a report says or its client, and never a network address.
- Invite codes, as fingerprints only, with the note the manager adds.
- Tasks and goals managers give: kind, title, note, due day, client, who it's for (a person or everyone), the manager who made it, when it was made, changed or cancelled; and for each worker who marked it done, when and their note. Never time spent, progress or activity: the company sees only what the worker sends.
- To slow down guessing: counts of sign-in, two-step, join, setup and sending tries, kept under a keyed fingerprint of the network address, email, manager or member they count (never as written), plus a plain fingerprint of the email for counts about an email. They are deleted by the nightly cleanup once their waiting period (15 minutes, or longer for some, up to a day) is over. Cloudflare's rate limiter also counts requests from each network address for a minute.
How long, and who decides:
- How long: reports are kept for 90 days unless the company chooses another period (7 to 730 days). A cleanup runs every night and deletes reports past that period, workers who left and have no reports left (with their names), ended sessions and halfway sign-ins, used or expired invite codes, old counts, activity log entries older than 180 days, and old member key fingerprints. Deleting a report, a worker or the whole company's data in the inbox deletes it at once, and deleting the workspace also deletes its sessions, recovery codes and activity log.
- Cloudflare D1 also keeps its own restore history of the whole database for 30 days, which only our Cloudflare account can use to roll the database back. Deleted reports can stay in that history until it ends.
- Leaving: a worker who leaves can choose to delete every report they sent. Otherwise their reports stay with the company until it deletes them or its retention period ends.
- For the reports workers send, the company decides why they are used and is the controller of that data. We process it only for the company and on its instructions. Requests about those reports go to the company first; we help it answer them.
- What we see: for billing, our own admin view shows each workspace's name, when it was made, and how many people are in it. It can't show reports. We look at the database itself only to run and fix the service, when the company asks us to, or when the law requires it.
Our website
astrolinks.org uses no analytics and no advertising or tracking cookies. Our host keeps standard server logs (such as IP address, time and page) to keep the site running and secure.
The pricing page loads Paddle's checkout script (Paddle.js) from Paddle's servers, so it can show your country's prices and open checkout. Paddle receives your internet address from it and may set its own cookies, under Paddle's privacy notice. The other pages load nothing from other companies.
Who can receive your data
| Who | What | When |
|---|---|---|
| Anthropic, PBC | The summary and messages described in "Writing with AI" | Only when you press Write with AI or send a chat message |
| Cloudflare, Inc. | The same requests, passing through our AI service, and the license records it keeps. With the Team plan, the reports workers send and what the Team service keeps (see "The Team plan") | Only with the AI included with Pro, and with the Team plan |
| Your company, with the Team plan | The reports you send to it, with your hours only if you include them | Only when you send a report to your team |
| Slack (Salesforce) | Your report | Only when you press Send to Slack, for that client's workspace |
| Your email app and provider | Your report, as a draft | Only when you press Email draft and send it yourself |
| Paddle (merchant of record) | Your purchase and payment details; a license's Paddle customer id when you press Manage plan; your internet address when prices are shown | When you buy, renew or manage your plan, and on the pricing and Plan pages |
No one else. No analytics companies, no crash reporting services, no advertising networks and no data brokers. We don't sell your personal information or share it for advertising. If you get the app from the Microsoft Store, Microsoft has your download and any Store purchase under its own privacy statement, but the app sends Microsoft nothing.
We may disclose information we hold if the law requires it, for example a valid court order.
Transfers to other countries
Anthropic, Cloudflare and Slack are based in the United States and may process data in the United States and other countries. When data about you leaves your country, we rely on the safeguards the law requires.
Legal bases (EEA and UK)
| What we do | Why we may |
|---|---|
| Passing your AI requests to Anthropic (AI included with Pro) | To provide the service you asked for (contract) |
| Issuing and checking licenses, daily limits | Contract, and our legitimate interest in preventing misuse |
| Using network addresses briefly to limit requests | Our legitimate interest in keeping the services safe and available |
| Billing records | Contract, and the law (tax and accounting records) |
| Answering your emails | Contract, or our legitimate interest in helping you |
| Team reports | We act for the company, on its instructions |
Everything the app records on your computer is processed by the app on your computer for you. We never receive it.
Children
The app is for working adults. It is not meant for anyone under 18, and we don't knowingly collect personal information from anyone under 18. If you believe a child has given us their information, contact us and we will delete it.
Your rights
Most of your data never reaches us, so you can use your rights yourself, at any time:
- See it and take a copy: Settings, Privacy and data, Open data folder. The files are plain JSON, which any text editor can open and other software can read.
- Correct it: change your profile, clients and settings, reassign entries, or delete them.
- Delete it: see "How long it is kept, and how to delete it".
For the information we do hold (your license and purchase records, emails with us, and Team reports through your company), write to us at info@astrolinks.org. We will need to confirm it's you, usually from the email address you bought with or your license key. We answer within one month, or sooner where the law requires, and it is free.
Everyone
You can ask us what we hold about you and for a copy, to correct it, to delete it, and to stop using it for anything you object to. We won't treat you differently for asking.
European Economic Area, United Kingdom and Switzerland
Under the GDPR and the UK GDPR you have the right to access, rectification, erasure, restriction of processing, data portability and objection, and the right to withdraw consent where we rely on it. You can complain to your data protection authority (in the UK, the Information Commissioner's Office).
California
Under the CCPA, as amended by the CPRA, you have the right to know what personal information we collect, use and disclose, to delete it, to correct it, to opt out of its sale or sharing (we don't sell or share it), to limit the use of sensitive personal information (we don't use it to infer anything about you), and not to be discriminated against for using these rights. You can use an authorized agent.
In the last 12 months we collected these categories of personal information: identifiers (name, email address, license key, network address for a short time), commercial information (what you bought and when), and, only while passing through our AI service and without keeping it, the content of your AI requests. With the Team plan, we hold the reports you send for your company, as its service provider. We collect them from you, and we use them to provide the app, bill you and help you. We disclose them only to the service providers listed above.
Philippines
Under the Data Privacy Act of 2012 (Republic Act No. 10173), you have the right to be informed, to access, to object, to erasure or blocking, to rectification, to data portability, and to damages, and you can file a complaint with the National Privacy Commission. Our data protection officer can be reached at info@astrolinks.org.
Security
- Your keys and Slack links are encrypted on your computer.
- Every connection the app makes uses HTTPS: to Anthropic, to our AI service (the app only accepts an https address for it), to our Team service when you join, send to, take back from or leave a team, and to Slack (only
hooks.slack.com). - Our AI service never stores what you send or what Claude writes, and it keeps license keys only as fingerprints that can't be turned back into keys.
- The Team service keeps passwords, member keys, invite codes, recovery codes and sign-in sessions only as fingerprints, keeps authenticator secrets sealed, offers two-step sign-in to managers, and keeps no logs of what reports say.
- We keep no public storage. There are no public file buckets or public links to any data. The license store, and the Team database, are private to our Cloudflare account and can only be reached through our service's own checks.
- Release builds of the app ignore the switches we use to test it. Before the app launches, every release will also be signed, notarized by Apple on the Mac, and locked so it can't be started with debuggers or outside code; this draft build isn't yet.
- To report a security problem, write to info@astrolinks.org. Our security policy says what is in scope and how we answer, and the Team service publishes the same address at
/.well-known/security.txt.
No system is perfectly secure. If a breach affects your personal information, we will tell you and the authorities as the law requires.
Changes to this policy
When we change this policy, we update the date at the top. If a change matters, for example a new kind of data or a new company that receives data, we tell you in the app or by email before it takes effect.
Contact
Astrolinks
Privacy questions and requests: info@astrolinks.org
Data protection officer: info@astrolinks.org