What this notice covers
This notice covers the Haowen Labs public website and the early-access version of LocalDeploy, an application operated under the Haowen Labs brand. References to “we” and “our” mean the operator of these services.
The public website is an application directory. The sections about projects, sign-in, AI generation, sharing, and WordPress apply when you use LocalDeploy. A future Haowen Labs application may have its own notice or supplement; this notice does not describe features or data practices that have not launched.
Business details and drafts
You choose the business name, service details, contact information, page copy, and image URLs you enter. Use information you have permission to use. Avoid entering private customer records or other sensitive personal information.
Working drafts are kept in your browser’s local storage. If you sign in and choose Save, we store the project and your account identifier in our hosted database so you can reopen it. Templates and file exports can be used without signing in. Opening an untouched fictional sample does not overwrite your existing working draft.
Browser drafts belong to the website address where you created them. Download a project backup before moving to a new address. Saved account projects are separate from those local drafts.
Accounts and hosting
LocalDeploy supports Google sign-in and, when enabled, verified email codes and email/password sign-in. Google supplies a stable account identifier, verified email address, and display name. Email sign-in verifies ownership before creating an account. We store account identity, profile, consent, activity, attribution, and subscription records in our own customer database. Saved projects use an immutable account identifier to keep each account’s work separate. Passwords are stored only as salted, memory-hard hashes. Verification codes are short-lived, attempt-limited, and stored as keyed hashes; they are never stored in plain text. Transactional email providers receive the address and verification message needed to complete sign-in.
That version runs in Haowen Labs’ Cloudflare account using Workers and a D1 database. Google and Cloudflare process the requests needed for sign-in and hosting. The provider authorization token is used during sign-in and is not saved by the application. A necessary, browser-inaccessible session cookie keeps you signed in; the database stores its hash rather than the cookie value. These sessions expire after 30 days or when you sign out.
During the hosting transition, the original ChatGPT Sites version may remain available. Its ChatGPT sign-in provides a site-specific account identifier, email address, and display name. The original application stores the identifier with projects, and does not copy the email or display name into its project database. ChatGPT Sites processes requests and authentication for that version.
Existing projects are transferred between those account systems only after ownership is verified. Matching an email address alone does not grant access to an old project. Authorized administrators can inspect account records and work through audited support tools; they do not receive customer passwords or session tokens. Marketing consent is optional and defaults to off. A configured marketing provider receives only the contact details needed for an explicitly requested sync, and changes to consent are recorded.
Optional AI generation
When you explicitly request AI generation, approved business facts and requested page content are sent through our server to the configured model provider. Standard plans currently use Google Gemini. Those providers’ data practices apply. Template creation, editing, and file exports do not require a model request. When you request a live AI search audit, OpenAI and Perplexity receive the public business name, category, location, and optional website for independent search-backed checks. An audit records the API responses and cited sources at that time; it does not represent every answer in a consumer application. A separately configured search-evidence audit can use Serper results analyzed by Gemini. Audit results and source references are saved in your workspace; a report becomes public only when you choose to publish it on a preview.
Unlimited Agency requires your own supported Gemini, OpenAI, or OpenRouter text key and a Replicate token. Unlimited prospect discovery and dual-engine audits require separate customer-owned Serper, OpenAI audit, and Perplexity connections. Workspace provider keys are encrypted with AES-256-GCM before storage in Cloudflare D1. They are decrypted only on the server for authorized operations and are never returned by the key settings API, saved in browser storage, or included in project backups and exports. Standard-plan provider credentials are server secrets.
We store generation status, idempotency references, credit and quota mutations, cost reservations, and available token counts to control access, prevent duplicate processing, and audit usage. A failed paid provider attempt can use the AI budget even when a product credit is refunded.
Prospect lists and LeadGen previews
When you explicitly import a LeadGen batch, we store the original CSV columns and prospect records in your account’s Cloudflare D1 database. Background queue messages contain job references, rather than prospect records or model credentials. Original email addresses, owner names, and current website URLs are available only through your authenticated account and enriched CSV export.
Preview generation sends only the imported business name, category, city, and state to the workspace’s configured model provider. Standard plans use a server-managed provider credential; Unlimited Agency uses the workspace’s encrypted provider connection. The public preview uses the supplied business name, location, phone, and optional imported rating. Ratings are imported listing data, not independently verified.
Importing a batch requests public preview publication as each valid homepage becomes ready. Anyone with a published link can open it; those pages request that search engines do not index them. The one-time Free Sandbox preview is watermarked and expires seven days after publication unless upgraded. Paid previews pause when the agency subscription ends, becomes unpaid, or loses its paid access period. A claim link instructs the prospect to reply to the agency and does not transfer account ownership. Enriched CSV export does not send email or connect to an outreach platform.
Full-site upgrades store the approved business intake and completed site state in your account, together with job status and a credit transaction record. For requests about imported prospect records or a public preview, contact Haowen Labs using the address below.
WordPress preview and delivery
Starting a WordPress preview sends your current page content to a temporary WordPress runtime in your browser at playground.wordpress.net. That service loads WordPress software and may contact its software distribution services. Edits made inside the temporary preview do not update your LocalDeploy project. Downloaded Playground Blueprints contain the business details and page content needed to rebuild that preview.
When you connect a client WordPress site, its address, username, and new Application Password are held in the current window’s memory and sent over HTTPS through our server for the connection check or transfer you request. The application does not save those credentials in projects, browser storage, database records, exports, or application logs. Closing this delivery window clears them; a completed transfer also clears the password. We check the target domain using Cloudflare DNS and keep a short account usage counter to limit repeated requests.
Sending pages creates drafts in your selected WordPress site. That site’s operator and hosting provider control those records and their retention. The transfer receipt contains confirmed page IDs and does not contain your password. Review your WordPress Pages list before repeating a transfer, because another transfer can create duplicate drafts.
Billing and onboarding
If you choose a paid plan, Stripe processes checkout and billing details. We store Stripe customer, subscription, invoice, and event identifiers with plan status and monthly allowances; we do not receive or store your full card number. Signed webhook events reconcile billing changes. Managed client hosting has separate subscription records and does not share the agency credit balance.
Unlimited onboarding currently uses our public contact email. If a Cal.com booking link is configured, its booking page loads only after you open the onboarding modal; Cal.com then processes the details you submit under its own policies. Upcoming features do not process data before they are released.
Your controls
You can export a project backup, delete saved projects from the workspace, revoke review links, and clear the AI key in AI settings. Starting a new website clears the current working draft for that workspace after any unsaved-change confirmation. To remove all local drafts on a shared device, clear this site’s browser storage.
Deleting a project removes the application’s active copy. Copies in infrastructure backups, if any, follow the hosting provider’s retention processes. Content you sent to a WordPress site or downloaded to your device is controlled at that destination.
Contact Haowen Labs
For privacy questions or requests about your information, email haowenapps@gmail.com. Describe the request and the account or project involved. Do not send passwords, API keys, or WordPress Application Passwords.
Changes to this notice
We update this notice when the services’ data practices change. The date at the top identifies the current revision. A material change will be described in the updated notice and, when appropriate, announced in the application.
