Longhand
Technical Leaders Inc.
Effective Date: May 12, 2026 | Last Updated: May 12, 2026
Longhand is designed with a local-first architecture. Your API Keys are stored exclusively in your operating system's secure credential store (e.g., macOS Keychain) and are never transmitted to or stored on our servers. The content of your AI interactions (API requests and responses) flows directly from your device to your chosen Model Provider — it never passes through our servers. We do collect product analytics (feature usage, errors, app version) via PostHog and provide in-app support via Intercom to improve the Service. This Privacy Policy ("Policy") explains what data we collect, how we use it, and your rights under GDPR, CCPA/CPRA, LGPD, PIPEDA, and other applicable privacy laws worldwide.
This Privacy Policy describes how Technical Leaders Inc., a Delaware corporation ("Company," "we," "us," or "our"), collects, uses, discloses, and protects your personal information when you install, access, or use Longhand and all related services (collectively, the "Service"). This Policy applies to all users worldwide and addresses specific regulatory requirements for users in the European Economic Area ("EEA"), United Kingdom ("UK"), California, Canada, Brazil, South Korea, and other jurisdictions with applicable data protection laws.
By installing, accessing, or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Service. This Policy should be read in conjunction with our Terms of Service.
For the purposes of applicable data protection laws, the data controller is:
Entity: Technical Leaders Inc.
Address: 1062 E Oaks Manor Dr., Fayetteville, AR 72703
Email: privacy@technical-leaders.com
Data Protection Officer: dpo@technical-leaders.com
The Company does not maintain an establishment in the European Economic Area (EEA) and does not engage in large-scale monitoring of EEA data subjects or large-scale processing of special categories of personal data. Accordingly, the Company relies on the exemption under Article 27(2) of the GDPR and has not appointed an EU representative at this time. If the Company's processing activities change such that an EU representative is required, this Policy will be updated to reflect that appointment.
We do NOT collect, transmit, store, or have access to your API Keys. All API Keys are stored exclusively in your operating system's secure credential store (e.g., macOS Keychain, Windows Credential Manager) and are processed entirely on your device. Our analytics systems do not collect API Key values, API request content, or API response content.
Our local-first architecture for API Keys operates as follows:
Because API Keys are stored locally on your device:
We strongly recommend that you:
We collect information that you voluntarily provide when you:
Although Longhand is a desktop application with a local-first architecture for AI processing, the Service does collect certain analytics and operational data during normal use:
cdn.crabnebula.app). Update checks transmit the current app version, OS family, and architecture; no user-identifying data is included. Update artifacts are signed with Minisign (which uses Ed25519 internally) and verified on your device before installation.
cdn.getlonghand.com.
To be explicitly clear, we do NOT collect:
The desktop application uses PostHog for product analytics (as described in Section 4.2), which maintains a local identifier for usage tracking. The desktop application does not use traditional browser cookies. If you interact with our website or web-based account management portal, we use the following categories of cookies:
| Category | Purpose | Duration |
|---|---|---|
| Essential | Authentication, security, core functionality | Session / 1 year |
| Functional | User preferences, language settings | 1 year |
| Analytics | Website usage patterns (anonymized, opt-in) | 2 years |
| Marketing | Only with explicit opt-in consent | 1 year |
You can manage your cookie preferences through our website's cookie consent banner or your browser settings.
For users in the EEA, UK, and Switzerland, we process your personal data based on the following legal bases:
| Legal Basis | Processing Activity | GDPR Article |
|---|---|---|
| Contract Performance | Account management, service delivery, support | Art. 6(1)(b) |
| Legitimate Interest | Security, fraud prevention, service improvement | Art. 6(1)(f) |
| Consent | Marketing, optional crash reports, analytics | Art. 6(1)(a) |
| Legal Obligation | Tax records, regulatory compliance | Art. 6(1)(c) |
We use the information we collect to:
We do NOT use your personal data, Content, Agent configurations, Skill definitions, or workflow data to train machine learning models. The Company does not collect this data during normal operation. Any anonymized, aggregated data used for service improvement (such as opt-in crash reports) will be de-identified in accordance with applicable regulations.
The Service does not use automated decision-making technology to make significant decisions about Users (as defined under the CCPA/CPRA) without human oversight. The AI capabilities within the Service are tools that augment human decision-making; they do not autonomously make decisions that produce legal or similarly significant effects on Users.
We may share your personal information with the following categories of recipients:
We will never:
If we transfer your personal data outside of your jurisdiction, we will implement appropriate safeguards, including:
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by applicable law. No indefinite data retention is permitted under our policies. Our general retention periods are:
| Data Type | Retention Period | Basis |
|---|---|---|
| Account Data | Duration of account + 30 days | Contract |
| Crash Reports (opt-in) | 12 months | Consent |
| Support Records | 36 months from resolution | Legitimate Interest |
| Transaction Records | As required by tax law (typically 7 years) | Legal Obligation |
| Marketing Consent | Until consent is withdrawn | Consent |
| Security/Auth Logs | 12 months | Legitimate Interest |
Upon account deletion, we will delete or anonymize your personal data within thirty (30) days, except where retention is required by law. API Keys and all locally-stored data (Agent configurations, Skills, workflows) reside on your device and are not affected by account deletion.
We implement industry-standard technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
In the event of a data breach affecting your personal data, we will notify affected users and relevant supervisory authorities within seventy-two (72) hours of becoming aware of the breach, in accordance with GDPR Article 33 and other applicable breach notification laws.
If you are located in the EEA, UK, or Switzerland, you have the following rights under the GDPR:
If you are a California resident, you have the following rights:
In compliance with the California Generative AI Training Data Transparency Act (AB 2013, effective January 1, 2026), we disclose that Longhand does not train or develop its own generative AI models. Longhand is a platform that enables users to interact with third-party Model Providers (Anthropic, OpenAI, Google, xAI, and locally-hosted models) using the user's own API Keys. We do not collect or use user data for AI model training. For information about each Model Provider's training data practices, please refer to their respective privacy policies and transparency disclosures.
The Company complies with applicable state comprehensive privacy laws, including those in effect in Delaware, Indiana, Iowa, Kentucky, Minnesota, Nebraska, New Hampshire, New Jersey, Rhode Island, Tennessee, Colorado, Connecticut, Virginia, Utah, Montana, Oregon, Texas, and Maryland. If you are a resident of any of these states, you generally have rights to access, correct, delete, and port your personal data. Contact us to exercise these rights.
If you are located in Brazil, you have rights under the Lei Geral de Protecao de Dados (LGPD), including the right to access, correct, delete, anonymize, or port your personal data, and to be informed about the entities with which your data has been shared. International transfers of your data are governed by Brazilian Standard Contractual Clauses (effective August 23, 2025).
If you are located in Canada, you have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA), including the right to access your personal information, challenge its accuracy, and withdraw consent.
If you are located in South Korea, the Basic AI Act (effective January 2026) provides additional transparency, risk assessment, and human oversight requirements for AI systems. As a platform that facilitates user interaction with AI models, we comply with applicable transparency and documentation obligations.
To exercise any of your privacy rights, please contact us at privacy@technical-leaders.com or dpo@technical-leaders.com. We will respond to all verifiable requests within the timeframes required by applicable law (generally within thirty (30) days for GDPR and forty-five (45) days for CCPA). We may request additional information to verify your identity before processing your request.
The Service is not directed to individuals under the age of 18 (or the applicable age of majority in your jurisdiction). We do not knowingly collect personal information from children. In compliance with the amended Children's Online Privacy Protection Act (COPPA, as amended April 22, 2025, compliance deadline April 22, 2026):
If we become aware that we have inadvertently collected personal data from a child, we will take steps to delete such information promptly. If you believe a child has provided us with personal information, please contact us at privacy@technical-leaders.com.
In compliance with the European Union Artificial Intelligence Act (EU AI Act), we provide the following transparency disclosures:
Longhand is an AI agent platform that enables users to build, configure, and deploy Agents, Skills, and workflows that interact with third-party Model Providers (Anthropic, OpenAI, Google Gemini, xAI Grok) using the user's own API Keys, or with locally-hosted models running on Longhand's bundled llama-server runtime or any user-managed OpenAI-compatible local endpoint. The AI processing is performed by the Model Providers, not by Technical Leaders Inc.. Longhand is a desktop application built with Tauri that runs locally on user devices. The Service includes a local smart routing system that selects the optimal model and provider for each request based on prompt complexity, without sending routing data to external servers.
As of the effective date of this Policy, the Service is classified as a general-purpose AI application tool (minimal risk) under the EU AI Act framework. The Service does not make autonomous decisions in high-risk domains (healthcare, law enforcement, critical infrastructure, etc.) without human oversight.
The Company provides documentation, training materials, and support resources to help Users understand the AI capabilities and limitations of the Service, in compliance with the AI literacy obligations under Article 4 of the EU AI Act.
In compliance with Article 50 of the EU AI Act (enforceable August 2, 2026):
The Service is designed to augment, not replace, human decision-making. Users maintain full control over whether to accept, modify, or reject AI-generated outputs. Agent outputs intended for customer-facing use should be subject to appropriate human review and quality assurance.
We respect Do Not Track ("DNT") browser settings on our website. The desktop application collects product analytics via PostHog as described in Section 4.2; PostHog session recording is disabled. Some third-party services integrated into our website may not respond to DNT signals.
The Service may facilitate interactions with third-party services, including Model Providers. This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any Model Provider or third-party service before providing them with your information. The Company is not responsible for the privacy practices of third-party services.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will provide notice of material changes by posting the updated Policy on the Service and updating the "Last Updated" date. For significant changes, we will provide at least thirty (30) days' advance notice via email or in-app notification. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
General Privacy Inquiries: privacy@technical-leaders.com
Data Protection Officer: dpo@technical-leaders.com
Legal Inquiries: legal@technical-leaders.com
Mailing Address: 1062 E Oaks Manor Dr., Fayetteville, AR 72703
EU Representative: Not applicable — see Section 2 for the Company's Article 27(2) exemption basis.
For GDPR-related inquiries, we will acknowledge receipt within forty-eight (48) hours and provide a substantive response within thirty (30) days. For CCPA-related requests, we will respond within forty-five (45) days as required by law.
By installing or using the Service, you acknowledge that you have read and understood this Privacy Policy.