← Back to home

Privacy Policy

Black Label Trading LLC · Effective date: August 31, 2026

Black Label apps ship without customer data, and each app stores what you create on your own Mac by default. Several features are not local: when you use them, the app sends the content that feature needs to an outside provider, at the moment you use it. Which providers, and what reaches them, is listed under How the Apps Handle Your Data — read that section rather than assuming an app is offline. Microphone audio is transcribed by Apple's on-device recogniser when that feature is available and the audio itself is not uploaded. Vigil keeps raw sensing local; its user-triggered update check requests a public version manifest from Black Label. This website and the hosted services use the providers and limited data flows identified below.

Who We Are

These apps are published by Black Label Trading LLC ("we," "us," "the developer"). Black Label Bots is part of the BlackLabel Tech network. If you have a question or privacy request, email info@blacklabelbots.com.

What We Collect

We collect the account, billing, licence, device-binding, security, and quota metadata needed to provide downloads and paid or granted access. This can include name, email, authentication method, subscription and Stripe references, product entitlement, app version, licence state, device binding, download events, IP-derived security signals, and support correspondence. The installed apps do not include advertising or third-party analytics SDKs. The public website can use PostHog, Google Analytics, and Google advertising. When optional measurement is enabled, those services may receive the page URL, referrer, browser/device details, coarse network location, interaction or conversion events, and their own identifiers. Session replay, PostHog autocapture, and PostHog person profiles are disabled. Browser Global Privacy Control, Do Not Track, and the site opt-out below prevent these optional measurement and advertising scripts from loading.

How the Apps Handle Your Data

Each app starts empty. Data you enter or import — leads, contacts, assets, property data, conversations, settings — is stored on your own Mac. It is not copied to a Black Label server as a matter of course, and there is no background sync of your workspace.

What that does not mean is that nothing ever leaves your Mac. Specific features exist to reach an outside service, and using one sends that feature's content to that service. In most cases the request runs on an API key or account you supplied, so the provider relationship is yours and the usage is billed to you. Per app:

  • Stored locally. Data you create or import is stored on your Mac, under your control, unless you use one of the features below.
  • Sovereign. Sovereign dispatches reasoning to the provider you configure — Anthropic's API or a prompt-capable CLI signed in under your own login, or a local Ollama model that stays on your Mac. When the provider is not local, your prompt is sent to it, and the stored facts Sovereign recalls as relevant to that request ride along as context and are sent with it. When the provider is local — Ollama is the default — the prompt and those recalled facts go nowhere, and a request Sovereign can answer straight from local memory never reaches a provider at all. Connectors you enable (Google, Microsoft, Slack, Linear, or any MCP server you add) read and write through your own accounts. Sovereign has no Black Label backend; your data does not pass through our servers.
  • Real Estate. Parcel, assessor and hazard lookups query public county, ArcGIS, FEMA and OpenStreetMap endpoints. Skip-trace is off until you connect a provider key; when you run one, the owner's name and street address are sent to that provider (BatchData or RocketSkip). Direct mail is off until you connect a mail-vendor key; when you approve a letter, the recipient's name and mailing address and the letter body are sent to that vendor (Lob or PostGrid) to be printed and posted. Both run on your key, at your cost, and only on the records you act on.
  • Marketing. Publishing is connector-gated: nothing is transmitted until you connect a channel and approve the asset. When you publish, captions, images and video are sent to the social APIs you connected (Meta/Instagram, Threads, X, LinkedIn, Pinterest, Google, Microsoft, HubSpot). If you use the messaging channel, recipient phone numbers and message text are sent to Sendblue. Each provider is consented separately and the consent is withdrawable.
  • Academy. Course content and progress are local, but cohort features run against a Black Label–hosted worker. Joining or participating in a cohort sends a device identifier and lesson-completion events as product interaction data to that hosted service.
  • Vigil. Discovery, control, automations and sensing run on your Mac and LAN. Raw microphone, camera and sensor-node data is processed there and is not uploaded to Black Label. The app has no sign-in and no analytics SDK. Away Alerts are off until you configure them; a critical alert then sends the title and message—which can include a resident name—to the endpoint you chose. A manual update check requests the public Vigil or Homefront version manifest from blacklabelbots.com; the normal web request metadata reaches our Cloudflare-hosted service, but raw sensing and the local home database do not. Read the controlling Vigil Health & Sensing Data Notice.
  • Updates and licensing. Sovereign, Marketing, Real Estate, Academy and Sunset can check our update endpoint and validate a licence or subscription. Those requests carry the product, version, licence state and device-binding metadata needed for the request—not workspace content. Vigil's manual check reads only a public release manifest and does not send a licence key or raw sensing.

Hosted Website, Account, Support, and MCP Services

Cloudflare hosts the public site, account and session routes, D1/KV records, R2 downloads, security controls, and request logs. Stripe handles checkout, receipts, subscriptions, and billing portals. When you ask the on-site support assistant a question, the question, selected support-corpus excerpts, and the generated answer are processed by Cloudflare Workers AI; do not include passwords, licence keys, protected health information, or other unnecessary sensitive data. Connected hosted products such as Operator, Continuum, BL Sign, and customer MCP endpoints publish their own supplements for prompts, code, files, credentials, artifacts, signatures, integrations, or blockchain records.

Black Label Academy: the optional cohort

Black Label Academy works without a Black Label account. The installed lesson library, notes, review schedule, certificate name, and core lesson progress are stored locally on the device. Academy also offers an optional cohort, which is off by default: until you select Join a cohort, Academy's cohort refresh and lesson-completion paths make no network request.

  • What is sent after you join. Academy sends a random device identifier — generated on your device, not derived from your hardware — and lesson-completion events to the Black Label cohort service. The service also stores the cohort identifier, lesson identifier, membership record, completion markers, and aggregate member and completion counts.
  • What is never sent. The cohort service receives no name and no email. It is not linked to a Black Label account or to an identified person, and it is not used for advertising or cross-app tracking.
  • Why it is collected. To operate cohort membership, to keep completion counting idempotent so finishing a lesson twice never double-counts, to show peer progress, and for aggregate completion analytics.

Cohort membership and lesson-completion records are retained by the cohort service without an automatic expiration while that service operates, unless they are deleted in response to a valid deletion request or removed during service retirement. Leaving a cohort clears active cohort membership on the device and stops future cohort network requests; it does not delete records already retained by the service. Leaving and data deletion are separate actions.

To make a cohort data deletion request, email michael@blacklabelbots.com with the subject Black Label Academy cohort deletion request. Send the request from the device that joined the cohort where possible. Support will provide the steps needed to identify the random cohort record and will confirm when matching cohort membership and lesson-completion records have been deleted.

Third-Party Services You Connect

Most outbound features run on a provider you connect with your own key or login, so the account and the cost are yours. Depending on the app and what you enable, that can include: Anthropic or another prompt-capable CLI provider, and Ollama if you prefer a local model (Sovereign); BatchData or RocketSkip for skip-trace and Lob or PostGrid for print mail (Real Estate); Meta/Instagram, Threads, X, LinkedIn, Pinterest, Google, Microsoft, HubSpot and Sendblue (Marketing); Google, Microsoft, Slack, Linear and any MCP server you add (Sovereign connectors); and any webhook endpoint you nominate for alerts (Vigil). Academy cohorts run on a Black Label–hosted worker. Cloudflare provides website, account, storage, security, logging, and Workers AI infrastructure; Stripe processes payments; PostHog, Google Analytics, and Google advertising provide optional measurement or advertising when privacy controls permit them. Those providers operate under their own privacy policies and terms; review them before using the relevant feature.

Selling or Sharing of Data

We do not sell app content or personal information for money. Analytics and advertising disclosures can be treated as “sharing,” targeted advertising, or a sale under some state laws even without a cash payment. We honor browser Global Privacy Control and Do Not Track signals for optional site measurement and advertising. You can also disable those scripts on this browser now: . Essential service, fraud-prevention, checkout, account, and transaction processing continues.

Data Retention and Deletion

Local app data is deleted from the app or Mac by you. Connected-service data is controlled in that service. We retain account, entitlement, licence, device, quota, transaction, delivery, security, and support records while needed to provide the service, investigate abuse, resolve disputes, honor deletion or suppression requests, and meet tax, accounting, or legal duties. Newsletter unsubscribe records remain as suppression entries so we do not mail the address again. A verified request can seek access, correction, export, or deletion; required transaction, security, and suppression records may remain.

Health and Regulated Data

Touching health-related data does not by itself make every product subject to HIPAA. Covered-entity and business-associate status depends on the customer, relationship, and function. Except under a separately reviewed deployment with the required safeguards and any required written business-associate agreement, the general website, support assistant, account, upload, prompt, signature, and MCP services are not offered to process protected health information on behalf of a HIPAA covered entity. Vigil's consumer sensing data is governed by its product-specific notice; it does not claim HIPAA or medical-device certification and is not an emergency service.

Children

Black Label products and hosted services are intended for adults and are not directed to children under 13.

Changes to This Policy

If we change this policy, we will update the effective date above and post the revised policy at this address. Continued use of the apps after a change means you accept the revised policy.

Contact

Questions about this Privacy Policy or your data? Email info@blacklabelbots.com. The network-wide baseline is also available from BlackLabel Tech.