Haymaker Labs
Frazzled privacy policy.
Version ra1.6-privacy-v3 · setup clarification published 30 September 2026
This policy explains how Christopher Cowan, a UK sole trader operating as Haymaker Labs, handles personal information for the small, private Frazzled beta.
Scope
The private TestFlight roster contains exactly 10 named adults for an evaluation of exactly 14 days. It has no public registration, marketing list, public TestFlight link or children. Ordinary planning remains on the participant's device.
With the replacement build 19 setup, you may enter a Tester ID as a record-only label, then make the existing in-app choice about online AI. The label may be blank or shared and is not a password, identity check or proof that someone is on the roster. This setup does not require an invitation code, a new passkey or another email reply. This clarification applies when you use that replacement setup; earlier app versions used the invitation and passkey route.
Information we use
- the closed roster and administrative contact address;
- installation setup and consent facts, and existing one-use invitation, account, device, passkey and session records from the earlier route;
- the minimum information a participant deliberately submits for an optional online-AI feature;
- pseudonymous, content-free operation, quota, cost, availability and security facts; and
- correspondence deliberately sent to our role addresses.
The replacement setup stores a random installation credential securely on the iPhone. Our London service stores its verifier, the optional label, original AI-consent receipt, app-build information, evaluation close and withdrawal state. Linked operational identifiers keep installation requests separate and support the existing shared usage controls; they do not prove a unique person or device. These records are pseudonymous, not anonymous. Existing legacy account, passkey, invitation and session records keep their existing obligations.
Routine monitoring does not contain prompts, responses, planning content, direct email addresses, invitation values, Tester ID labels, passkeys, installation or session credentials, or provider credentials. Online suggestions remain proposals and cannot silently change an authoritative record.
Why we use it
Optional online AI uses consent. Explicit consent also covers a participant's own special-category information if they choose to include it. Narrow admission, authentication, security, quota, incident and essential-support controls rely on legitimate interests. Legal obligations apply where the law requires processing for a rights request or qualifying incident.
Services and international processing
- Amazon Web Services provides the private London-region API, identity, database, logging and alerting infrastructure.
- Google Workspace carries the individual administrative handoff and support, privacy, rights and security correspondence.
- OpenAI processes the minimum typed input and structured output for an online-AI request in a dedicated Global API project.
- Apple provides TestFlight delivery, App Attest and passkey platform services.
OpenAI requests use store:false. This prevents an ordinary stored Responses object, but it does not mean zero retention. Under the selected standard, non-ZDR posture, abuse-monitoring records may be retained for up to 30 days and encrypted GPU-local prompt-cache tensors may persist for up to 24 hours. This beta does not claim Zero Data Retention, Modified Abuse Monitoring, UK data residency or UK-only processing. API content is not used for model training unless the customer opts in; Haymaker Labs does not opt this project in.
Retention and deletion
Online access ends at the cohort close. Installation and linked operational metadata have the existing logical deletion deadline of close plus 30 days; asynchronous physical deletion and backup limits still apply.
- invitation authority lasts no more than 21 days;
- CloudWatch operational logs have a seven-day expiry;
- the roster and ordinary pseudonymous operational, identity and audit records have a 30-day logical deletion deadline after the beta closes;
- ordinary support correspondence has a 90-day active-mailbox deletion deadline; and
- a rights or security case is kept longer only where individually necessary, with a documented review and deletion date.
Expiry removes authority but does not instantly erase every record. Managed logs, asynchronous cleanup and backups can physically lag the logical deadline. OpenAI, Apple, passkey, App Attest and local-device records follow their own disclosed technical cycles. Haymaker Labs will not promise deletion from systems it cannot directly control.
Withdrawal stops new AI use but is not immediate deletion of all server records. After confirmed withdrawal, the replacement setup removes its credential, label and consent receipt from the app while keeping a minimal off marker. An unopened app or its backups cannot be remotely erased. Early server erasure may retain a minimum withdrawal record and operational controls for their disclosed period so delayed requests cannot restore access. The Privacy Choices page explains how to request this.
Your choices and rights
Joining is optional and the in-app online-AI choice begins unticked. Depending on the information and legal basis, you may request access, correction, deletion, restriction or a portable copy, or object to processing based on legitimate interests. Rights are not absolute and proportionate identity verification may be needed.
See the Frazzled privacy choices page for the practical steps and the differences between withdrawing, deleting the app and deleting server records.
Contact and complaints
Contact privacy@haymakerlabs.co.uk for privacy and rights, support@haymakerlabs.co.uk for cohort help, or security@haymakerlabs.co.uk for security concerns. You may also complain to the Information Commissioner's Office or call 0303 123 1113.
Website privacy
This informational website offers no account or public sign-up, uses no advertising tracker and sets no non-essential cookie. Its hosting service may process limited technical request information to keep the site secure and available; Haymaker Labs does not use it to profile or advertise to visitors.
Changes
The 30 September 2026 clarification covers the replacement build 19 setup. The existing AI purposes, choice wording, provider, retention posture, no-training and no-tracking commitments, and rights and contact details are unchanged.
A material change to the provider, model, purpose, information, retention, geography or beta boundary requires a fresh assessment and, where needed, a new notice and consent.