Locke Werks

Privacy Policy

Effective: August 8, 2026

This Privacy Policy applies to all software, websites, and services operated by Locke Werks ("we," "us," "our"), including but not limited to ARCHON, Attest, DeadLetter, and Witness (collectively, the "Services"). By using any of our Services, you agree to the collection and use of information as described here.

Not every Service collects the same information, and some collect none at all. Sections 1 and 2 describe the maximum scope of what we may collect across our Services. Section 3 states what each individual product actually does, and where a product collects nothing, that governs. DeadLetter is a locally installed desktop application with no backend service: it collects nothing and transmits nothing to us. See Sections 3 and 4.

1. Information We Collect

Information you provide directly:

  • Email address (when signing up for notifications, creating an account, or contacting us)
  • Account credentials (username, password hash — we never store plaintext passwords)
  • Content you create or upload through our Services (game progress, photos, audio, creative session data)
  • Communications you send to us (support requests, feedback)

Information collected automatically (server-backed Services only; never DeadLetter):

  • Device information (device type, operating system, browser type)
  • Usage data (features used, actions taken, session duration)
  • IP address and approximate location (country/region level only)
  • Crash reports and performance data

Information we do not collect:

  • We do not collect precise geolocation data unless a specific Service requires it and you explicitly consent
  • We do not collect financial information directly — payment processing is handled by third-party providers (e.g., Stripe, Apple, Google)
  • We do not use tracking cookies for advertising purposes

2. How We Use Your Information

  • To provide, maintain, and improve our Services
  • To communicate with you about updates, launches, and service-related notices
  • To process transactions and manage your account
  • To detect and prevent fraud, abuse, or security incidents
  • To comply with legal obligations
  • To generate aggregate, anonymized analytics to improve our products

We will never sell your personal information. We will never share your email address with third parties for marketing purposes.

3. Product-Specific Data Practices

ARCHON: Game progress, scores, and leaderboard entries are stored to provide gameplay features. Leaderboard data (display name, scores) is publicly visible by design.

Attest: Creative session data, audio fingerprints, and attestation manifests are stored to provide cryptographic provenance services. Manifests you choose to publish become publicly verifiable. Email addresses collected for launch notifications are used solely for that purpose and are never distributed or sold.

Witness: Photographs, cryptographic hashes, timestamps, and chain-of-custody records are stored to provide evidence integrity services. Your evidence data is encrypted in transit and at rest. We do not access, view, or analyze the content of your photographs except as required to provide the Service or as compelled by law.

DeadLetter: DeadLetter is a desktop email client that runs entirely on your own computer. It has no backend service. We collect nothing from it: no personal information, no mail content, no account details, no usage statistics, no crash reports, no analytics, and no install or launch pings. Your messages, attachments, search index, and settings are stored locally on your device. Account credentials and OAuth tokens are held by your operating system's credential store (Credential Manager on Windows, Keychain on macOS, Secret Service via libsecret on Linux). The application communicates only with the mail providers you choose to connect. None of the automatic collection described in Section 1 applies to DeadLetter, because DeadLetter transmits nothing to us. See Section 4 for how DeadLetter handles Google user data.

4. Google User Data (DeadLetter)

This section applies to DeadLetter when you connect a Gmail or Google Workspace account. It describes what DeadLetter accesses through Google APIs and what it does with it.

Permissions requested. DeadLetter requests two Google permissions, and only these two:

  • https://www.googleapis.com/auth/gmail.modify — to read your messages so they can be displayed, indexed for search, and cached for offline use; to send the messages you compose; and to apply the changes you make in the application, such as marking read or unread, starring, archiving, moving, and labeling. This permission does not allow permanent deletion of your mail, and is requested instead of full Gmail access for that reason.
  • https://www.googleapis.com/auth/calendar — to display the calendar attached to that account, render meeting invitations that arrive as email, and let you accept, decline, and create events from within the application. The full calendar permission is required because reading and writing calendar sharing settings is not possible with the narrower events-only permission.

Where the data goes. Google user data travels directly between Google's servers and the copy of DeadLetter installed on your computer. It is not sent to Locke Werks, is not routed through any server we operate, and is not stored by us in any form. We operate no infrastructure that touches it. Mail retrieved from Google is cached in a local database on your own disk to provide offline access and search.

Authentication. Sign-in uses OAuth 2.0 with PKCE and takes place on Google's own sign-in page in your browser. DeadLetter never receives, sees, or stores your Google password. The resulting access and refresh tokens are stored in your operating system's credential store.

Limited Use. DeadLetter's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • Google user data is used only to provide and improve the user-facing mail and calendar features of DeadLetter.
  • Google user data is never transferred to Locke Werks or to any third party, except where required by law.
  • Google user data is never used for advertising, marketing, profiling, or resale.
  • Google user data is never read by any human at Locke Werks. No mechanism exists for us to do so, as the data never reaches us.
  • Google user data is never used to develop, train, or improve any machine learning or artificial intelligence model.

Retention and revocation. Because we hold no Google user data, there is nothing for us to retain or delete. Data cached locally by DeadLetter is removed when you remove the account from the application or uninstall it. You may revoke DeadLetter's access to your Google account at any time at myaccount.google.com/permissions.

5. Data Sharing

We may share your information only in these circumstances:

  • Service providers: Third parties that help us operate our Services (hosting, payment processing, analytics) under strict data protection agreements
  • Legal requirements: When required by law, subpoena, or court order
  • Safety: To protect the rights, safety, or property of Locke Werks, our users, or the public
  • Business transfers: In connection with a merger, acquisition, or sale of assets, with prior notice to affected users
  • With your consent: When you explicitly direct us to share information (e.g., publishing an attestation, sharing evidence)

6. Data Security

We implement industry-standard security measures to protect your data, including encryption in transit (TLS), encryption at rest, access controls, and regular security assessments. However, no system is perfectly secure. We cannot guarantee absolute security, but we commit to promptly notifying affected users in the event of a data breach.

7. Data Retention

We retain your data for as long as your account is active or as needed to provide our Services. If you request deletion of your account, we will remove your personal data within 30 days, except where retention is required by law or necessary to fulfill our legal obligations. Anonymized, aggregate data may be retained indefinitely.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Request deletion of your data
  • Object to or restrict certain processing of your data
  • Export your data in a portable format
  • Withdraw consent where processing is based on consent

To exercise any of these rights, contact us at privacy@lockewerks.com.

9. Children's Privacy

Our Services are not directed at children under 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will delete it promptly. If you believe a child under 13 has provided us with personal information, please contact us.

10. Third-Party Services

Our Services may contain links to or integrate with third-party services (e.g., payment processors, analytics providers, AI generation platforms). These third parties have their own privacy policies, and we are not responsible for their practices. We encourage you to review their policies.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the effective date. Continued use of our Services after changes become effective constitutes acceptance of the revised policy.

12. Contact

If you have questions about this Privacy Policy or our data practices, contact us at:
privacy@lockewerks.com

Locke Werks
Colorado Springs, CO

Home Privacy Policy Terms of Service
© 2026 Locke Werks. All rights reserved.