Haymaker Labs

Frazzled privacy policy.

Version ra1.6-privacy-v3 · setup clarification published 30 September 2026

This policy explains how Christopher Cowan, a UK sole trader operating as Haymaker Labs, handles personal information for the small, private Frazzled beta.

Scope

The private TestFlight roster contains exactly 10 named adults for an evaluation of exactly 14 days. It has no public registration, marketing list, public TestFlight link or children. Ordinary planning remains on the participant's device.

With the replacement build 19 setup, you may enter a Tester ID as a record-only label, then make the existing in-app choice about online AI. The label may be blank or shared and is not a password, identity check or proof that someone is on the roster. This setup does not require an invitation code, a new passkey or another email reply. This clarification applies when you use that replacement setup; earlier app versions used the invitation and passkey route.

Information we use

The replacement setup stores a random installation credential securely on the iPhone. Our London service stores its verifier, the optional label, original AI-consent receipt, app-build information, evaluation close and withdrawal state. Linked operational identifiers keep installation requests separate and support the existing shared usage controls; they do not prove a unique person or device. These records are pseudonymous, not anonymous. Existing legacy account, passkey, invitation and session records keep their existing obligations.

Routine monitoring does not contain prompts, responses, planning content, direct email addresses, invitation values, Tester ID labels, passkeys, installation or session credentials, or provider credentials. Online suggestions remain proposals and cannot silently change an authoritative record.

Why we use it

Optional online AI uses consent. Explicit consent also covers a participant's own special-category information if they choose to include it. Narrow admission, authentication, security, quota, incident and essential-support controls rely on legitimate interests. Legal obligations apply where the law requires processing for a rights request or qualifying incident.

Services and international processing

OpenAI requests use store:false. This prevents an ordinary stored Responses object, but it does not mean zero retention. Under the selected standard, non-ZDR posture, abuse-monitoring records may be retained for up to 30 days and encrypted GPU-local prompt-cache tensors may persist for up to 24 hours. This beta does not claim Zero Data Retention, Modified Abuse Monitoring, UK data residency or UK-only processing. API content is not used for model training unless the customer opts in; Haymaker Labs does not opt this project in.

Retention and deletion

Online access ends at the cohort close. Installation and linked operational metadata have the existing logical deletion deadline of close plus 30 days; asynchronous physical deletion and backup limits still apply.

Expiry removes authority but does not instantly erase every record. Managed logs, asynchronous cleanup and backups can physically lag the logical deadline. OpenAI, Apple, passkey, App Attest and local-device records follow their own disclosed technical cycles. Haymaker Labs will not promise deletion from systems it cannot directly control.

Withdrawal stops new AI use but is not immediate deletion of all server records. After confirmed withdrawal, the replacement setup removes its credential, label and consent receipt from the app while keeping a minimal off marker. An unopened app or its backups cannot be remotely erased. Early server erasure may retain a minimum withdrawal record and operational controls for their disclosed period so delayed requests cannot restore access. The Privacy Choices page explains how to request this.

Your choices and rights

Joining is optional and the in-app online-AI choice begins unticked. Depending on the information and legal basis, you may request access, correction, deletion, restriction or a portable copy, or object to processing based on legitimate interests. Rights are not absolute and proportionate identity verification may be needed.

See the Frazzled privacy choices page for the practical steps and the differences between withdrawing, deleting the app and deleting server records.

Contact and complaints

Contact privacy@haymakerlabs.co.uk for privacy and rights, support@haymakerlabs.co.uk for cohort help, or security@haymakerlabs.co.uk for security concerns. You may also complain to the Information Commissioner's Office or call 0303 123 1113.

Website privacy

This informational website offers no account or public sign-up, uses no advertising tracker and sets no non-essential cookie. Its hosting service may process limited technical request information to keep the site secure and available; Haymaker Labs does not use it to profile or advertise to visitors.

Changes

The 30 September 2026 clarification covers the replacement build 19 setup. The existing AI purposes, choice wording, provider, retention posture, no-training and no-tracking commitments, and rights and contact details are unchanged.

A material change to the provider, model, purpose, information, retention, geography or beta boundary requires a fresh assessment and, where needed, a new notice and consent.