TitleDesk Agent
Policy version 1.0 · Effective August 8, 2026

Privacy Policy

TitleDesk Agent is professional desktop software offered under The Harness Lab name by Spencer Teague. This policy covers the desktop application, its licensing and activation service, and these TitleDesk web pages.

Title-project data stays on the user's computer unless the user deliberately connects an outside service. We do not run advertising, sell personal information, or use title-project or Google user data to train generalized AI or machine-learning models.

1. Information TitleDesk handles

Project and professional data

TitleDesk can handle documents, scans, extracted text, project and client names, property descriptions, ownership interests, contacts, deadlines, research history, time entries, expenses, reports, and other information the user imports or creates. This is processed on the user's computer and is not sent to The Harness Lab's licensing service.

Google user data

Google Drive sign-in is optional. When connected, TitleDesk may access the Google account email; Drive, folder, and file names; file identifiers, types, sizes, modification times, and checksums; contents of supported files in a folder the user chooses; and, for a separately connected personal Drive, folders and files needed to save reports or packages the user asks TitleDesk to upload.

TitleDesk does not request Google Contacts, Gmail, Calendar, advertising, or profile permissions beyond the email used to label the connection.

Credentials, licensing, and diagnostics

OAuth tokens and user-supplied credentials are encrypted through the operating system's secure credential store. If commercial licensing is used, we process the customer or company name, email, Stripe customer and subscription identifiers, subscription status, plan, device allowance, app version, device name and platform, an app-scoped machine fingerprint or its hash, activation status, and security events. Stripe—not TitleDesk—processes full payment credentials.

TitleDesk does not automatically upload analytics, crash reports, document contents, or diagnostics. The local diagnostic report excludes document contents, credentials, project names, and private paths and leaves the computer only if the user shares it. The web host may process ordinary request information such as IP address, browser type, requested page, and time.

2. How information is used

Information is used only for user-facing functions the user selects: importing and synchronizing documents; building runsheets, ownership calculations, issue lists, maps, reports, and packages; showing the connected account; saving finished work to a personal Drive; running optional AI features after consent; operating approved connectors; securing local data; administering billing and licensed devices; preventing fraud; and answering support, privacy, security, or legal requests.

We do not use Google user data or title-project data for advertising, retargeting, credit decisions, surveillance, data brokerage, or sale.

3. Storage and security

The structured database is stored on the user's computer and encrypted with AES-256-GCM. Its key is protected by macOS Keychain, Windows credential protection, or a supported Linux keyring. Google and other tokens are encrypted before storage in that database.

Files downloaded from Drive are mirrored into TitleDesk's local application-data folder. Source documents, Drive-cache files, exports, working copies, and AI-workspace files are local files; their protection also depends on the operating-system account, filesystem permissions, and full-disk encryption. Encrypted backups remain wherever the user saves them.

The licensing service uses Cloudflare Workers and D1. Licensing secrets are not bundled with the desktop app. No storage or transmission method is guaranteed completely secure.

4. Google API data use and Limited Use

TitleDesk Agent's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

5. When information is shared

Information may be processed as needed by Google for OAuth and Drive operations; a user-selected AI provider for an enabled feature; a user-configured connector; Cloudflare for the licensing bridge and D1; Stripe for billing; Keygen for license and device provisioning; Resend for activation email; a research site the user chooses to visit; or authorities and transaction participants where legally permitted and required.

Licensing vendors do not receive Google Drive contents or project documents from the desktop app. Local Ollama use does not send content to a cloud AI provider.

6. Retention and deletion

7. Choices, children, and policy changes

Users can use TitleDesk without Google Drive or cloud AI; choose company read-only or personal Drive access; disconnect either account; revoke access through Google; withdraw AI access; clear the workspace; and delete documents, projects, credentials, and local data. Removing local information does not remove copies the user exported, backed up, uploaded, or sent elsewhere.

TitleDesk is a professional business tool and is not directed to children. We do not knowingly collect children's personal information through TitleDesk.

We update the date and both public and in-app copies when practices change. A new use of Google user data will be disclosed and any required consent obtained before that use begins.

8. Contact

Privacy questions, access requests, corrections, or deletion requests: spencerandtheteagues@gmail.com. Include “TitleDesk privacy” in the subject. Do not email title documents, credentials, activation secrets, or Google tokens.