randal
Legal

Privacy Policy

Last updated: July 8, 2026

This policy explains what Hassion Studio, Inc. ("we", "us") collects when you use the Randal application, randal.bot, and Randal's managed subscription service — and what we deliberately do not collect.

The short version

  • Your work stays on your computer. Randal runs locally with its own embedded database. Your projects, files, chat history, and memories are stored on your machine — we have no access to them.
  • Zero data retention, baked in. On managed plans, requests pass through our metering proxy to the model provider and back. The proxy records usage metadata only — model name, token counts, cost, timestamps, request IDs — never prompt or response content. Model routing only uses provider endpoints that don't store your data or train on it.
  • Self-hosting sends us nothing. If you run Randal with your own keys and no account, no data reaches us at all.

What we collect on managed plans

  • Account data. Your email address and authentication records, stored with our authentication provider (Supabase).
  • Billing data. Payments are processed by Stripe. We store your plan tier and Stripe customer/subscription identifiers; we never see or store your card number. Stripe's own privacy policy applies to payment processing.
  • Usage metadata. For each metered model request: the model used, provider, input/output token counts, computed cost, timestamps, and internal identifiers (organization, session, request). This is what makes usage-based billing and the in-app usage view work.
  • Support correspondence. Emails you send us.

What happens to your prompts

To fulfill a request on a managed plan, the prompt and the model's response transit our proxy so the request can be authenticated, routed, and metered. They are processed in memory and not written to our databases or logs. Model routing runs with a zero-data-retention policy baked in: requests are only sent to provider endpoints that neither store your data nor train on it, and requests that would require data retention are rejected rather than routed. Your prompts are never stored by the providers and never used to train models.

Website and application telemetry

randal.bot serves no advertising trackers. Standard web server logs (IP address, user agent, request path) are kept briefly by our hosting provider (Vercel) for security and reliability. The desktop application checks GitHub for updates, which exposes your IP address to GitHub the way any download does. The application sends us no analytics or crash reports.

Who we share data with

We share data only with the processors needed to run the Service:

  • Stripe — payments and subscription management
  • Supabase — authentication and billing database
  • Vercel — website and proxy hosting
  • OpenRouter and underlying model providers — processing the model requests you make
  • GitHub — application downloads and updates

We do not sell your data, and we do not share it with anyone for advertising.

Retention

Account and usage-metadata records are kept while your account is active and for as long as needed for tax, accounting, and dispute obligations after it closes. Everything stored on your own computer is yours — deleting the app's data directory removes it.

Your rights

You can request a copy of the data we hold about you, correction of it, or deletion of your account and its records by emailing hi@hassion.studio. Depending on where you live (for example the EU/EEA, UK, or California), you may have additional statutory rights; we honor verified requests regardless of jurisdiction.

Security

Managed-plan traffic is encrypted in transit (TLS). Billing records are protected by row-level security scoped to your organization. Payment credentials never touch our systems.

Children

The Service is not directed to children under 13, and we do not knowingly collect their data.

Changes

If we change this policy in a material way, we will give notice in the app or by email before the change takes effect.

Contact

Hassion Studio, Inc. — hi@hassion.studio