HAOWEN LABS

Your work. Your information.

Privacy notice · Effective October 5, 2026

This notice describes the first early-access version of LocalDeploy, operated by Haowen Labs, an independent software project by Haowen Zhang.

Business information and drafts

You choose the business name, service details, contact information, page copy, and image URLs you enter. Use information you have permission to use. Avoid entering private customer records or other sensitive personal information.

Working drafts are kept in your browser’s local storage. If you sign in and choose Save, we store the project and your site-specific account identifier in our hosted database so you can reopen it. Templates and file exports can be used without signing in. Opening an untouched fictional sample does not overwrite your existing working draft.

Sign-in and hosting

Sign in with ChatGPT provides a site-specific account identifier, your email address, and a display name when available. We use these to identify your account and display your workspace. The application stores the identifier alongside saved projects; it does not copy your email or display name into the project database. ChatGPT Sites and its hosting infrastructure process requests and authentication needed to operate the service.

Optional AI generation

When you choose Generate AI copy, your supplied business brief is sent through our server to OpenRouter and the model provider you select. Their terms and data practices apply to that processing. Template generation does not send your brief to an AI provider.

Your OpenRouter API key is held in the current page’s memory and forwarded over HTTPS for the request. Our application does not save it in the database, local storage, project backups, or exported websites. Reloading or leaving the workspace clears the in-memory key. We store a short usage counter against your account identifier to limit repeated generation requests.

WordPress previews and delivery

Starting a WordPress preview sends your current page content to a temporary WordPress runtime in your browser at playground.wordpress.net. That service loads WordPress software and may contact its software distribution services. Edits made inside the temporary preview do not update your LocalDeploy project. Downloaded Playground Blueprints contain the business details and page content needed to rebuild that preview.

When you connect a client WordPress site, its address, username, and new Application Password are held in the current window’s memory and sent over HTTPS through our server for the connection check or transfer you request. The application does not save those credentials in projects, browser storage, database records, exports, or application logs. Closing this delivery window clears them; a completed transfer also clears the password. We check the target domain using Cloudflare DNS and keep a short account usage counter to limit repeated requests.

Sending pages creates drafts in your selected WordPress site. That site's operator and hosting provider control the resulting records and their retention. We return a transfer receipt with confirmed page IDs; it does not contain your password. Review your WordPress Pages list before repeating a transfer, because another transfer can create duplicate drafts.

Sharing and external images

Sharing is off until you enable a review link. Anyone who has an enabled link can view the saved website draft, including contact details and image URLs used on those pages. Saving new changes updates that shared draft. Disabling the link or deleting the project removes access through that link, but cannot recall copies or screenshots other people already made. Preview pages request that search engines do not index them.

Images use the HTTPS URLs you supply. Loading a preview or an exported site may contact the image host, which receives a normal web request from the visitor’s browser. We do not bundle those external images into the export.

Cookies and analytics

This version does not add advertising trackers or third-party marketing analytics. Browser storage is used for working drafts, and the hosting and sign-in services may use cookies necessary to provide access and authentication. Operational hosting logs may include normal request information, such as network addresses and error status.

Your controls

You can export a project backup, delete saved projects from the workspace, revoke review links, and clear the AI key in AI settings. Starting a new website clears the current working draft for that workspace after any unsaved-change confirmation. To remove all local drafts on a shared device, clear this site’s browser storage. Deleting a project removes the application’s active copy; copies in infrastructure backups, if any, follow the hosting provider’s retention processes.

This notice will be updated if the service’s data practices change. The revision date above identifies the current notice.