Archived product notice
Privacy at the HRA v0 archive.
The archive separates public browsing, signed-in coordination data, and local Mac authority. This notice describes what each boundary can process and where the archived product has no universal retention promise.
Last updated August 23, 2026
Public archive
Public browsing stays narrow.
Route-only analytics
On the exact Production archive origin, HRA v0 can send a cookieless, personless PostHog pageview from /, /download, /alternatives, and the exact published comparison pages. The event contains the canonical route, page kind, archive site ID, and comparison slug when applicable. It excludes query text, URL fragments, referrers, account and task data, commands, provider sessions, and custom events.
The analytics client uses memory-only persistence, creates no person profile, disables autocapture, replay, surveys, feature flags, exception capture, and performance capture, and respects the browser's Do Not Track setting. This privacy page, the release ledger, machine-readable files, and every signed-in route are outside the analytics allowlist.
Hosting requests
Vercel serves the archive and may process operational request data such as network and browser metadata under its privacy notice. PostHog processes allowed pageview requests under its privacy policy. HRA v0 adds no advertising tracker.
Signed-in control plane
Hosted data is coordination data.
WorkOS authenticates humans and organization membership. Convex stores the WorkOS subject, human name and email when supplied, organization and membership provider identifiers, role claims, and the authorized task graph with its related workspaces, agents, runner state, dependencies, claims, submissions, reviews, bounded display events, and human decisions. Those providers process data under the WorkOS privacy notice and Convex privacy policy.
The service can read accepted task descriptions, comments, reasoning summaries, assistant messages, and remote question text and choices. Structural validation limits their size and shape but cannot detect every secret in ordinary prose. Do not put credentials, private keys, sensitive local data, or personal data that the work does not require into those fields.
An optional Hraness suite-account link adds a bounded account and entitlement status to the signed-in human. It does not identify a Codex account, agent credential, local session, runner, or repository, and it does not grant an HRA role or task capability.
Paired Mac
Execution authority stays local.
Codex credentials, provider sessions, raw transcripts, raw reasoning, tool names and arguments, environment values, commands, diffs, command output, canonical filesystem paths, local repositories, worktrees, and local SQLite state remain on the paired Mac. Credential and key material uses macOS Keychain-backed custody where the feature requires it.
Optional cross-device session sync sends an end-to-end encrypted summary projection rather than prompts or transcripts. The relay still stores or observes traffic timing, bounded ciphertext sizes, opaque vault, device, and session identifiers, device names and public keys, enrollment state and one-time pairing metadata, boot and heartbeat presence, membership epochs and device membership, and session lifecycle event kinds and revisions. Accepted remote answers are encrypted to a boot-scoped desktop key and deleted from the relay after acknowledgement or expiry.
Retention and choices
The archive does not invent a retention promise.
Durable task and authorization records remain available for history, review, fencing, and recovery. Hosted data residency, backup retention, request-log retention, and incident handling depend on the deployed provider configuration. HRA v0 does not publish one fixed retention period that overrides those systems.
- Use Do Not Track to suppress the optional HRA pageview on analytics-eligible public routes.
- Do not use the signed-in control plane for content you do not want sent to the hosted service.
- Sign out and revoke task credentials when a human or agent should no longer have access.
- For a private data-access or deletion request, ask a maintainer to establish a private contact channel. Do not include personal data, credentials, or task content in the public issue.
Security and changes
Report sensitive defects privately.
Read the archived security policy and security architecture. Report a vulnerability through GitHub private vulnerability reporting. The standard contact file is available at /.well-known/security.txt.
HRA v0 is archived at v0.1.14. A material correction to this notice will update its date and the checked public source. Privacy information for the current HRA belongs at hra.sh.