← Back to home

Privacy Policy

Black Label Trading LLC · Effective date: August 1, 2026

Black Label apps ship without customer data, and each app stores what you create on your own Mac by default. Several features are not local: when you use them, the app sends the content that feature needs to an outside provider, at the moment you use it. Which providers, and what reaches them, is listed under How the Apps Handle Your Data — read that section rather than assuming an app is offline. Ace queues request text and only the images needed for that request for Black Label's isolated HQ Codex CLI; queue content expires within ten minutes and is cleared on completion, and relay logs contain metadata, not content. Microphone audio is an exception in your favour: it is transcribed by Apple's on-device recogniser and the audio itself is never uploaded. Vigil is the other: its Mac app contacts no Black Label server at all. This website uses the analytics and advertising services identified below.

Who We Are

These apps are published by Black Label Trading LLC ("we," "us," "the developer"). If you have any question about this policy or your data, email us at mtuburnsbarber@gmail.com.

What We Collect

We collect the account, billing, licence, device-binding, security, and quota metadata needed to provide downloads and paid or granted access. The apps do not include advertising or third-party analytics SDKs. For Ace model requests, prompt text and requested images are processed transiently; queue content is cleared on completion or expiry, and relay logs never contain prompt, response, transcript, screenshot, audio, or file content. This website uses Google Analytics and Google advertising services, which may receive standard web request, cookie, device, and interaction data under Google's policies and your consent settings.

How the Apps Handle Your Data

Each app starts empty. Data you enter or import — leads, contacts, assets, property data, conversations, settings — is stored on your own Mac. It is not copied to a Black Label server as a matter of course, and there is no background sync of your workspace.

What that does not mean is that nothing ever leaves your Mac. Specific features exist to reach an outside service, and using one sends that feature's content to that service. In most cases the request runs on an API key or account you supplied, so the provider relationship is yours and the usage is billed to you. Per app:

  • Stored locally. Data you create or import is stored on your Mac, under your control, unless you use one of the features below.
  • Sovereign. Sovereign dispatches reasoning to the provider you configure — Anthropic's API or a prompt-capable CLI signed in under your own login, or a local Ollama model that stays on your Mac. When the provider is not local, your prompt is sent to it, and the stored facts Sovereign recalls as relevant to that request ride along as context and are sent with it. When the provider is local — Ollama is the default — the prompt and those recalled facts go nowhere, and a request Sovereign can answer straight from local memory never reaches a provider at all. Connectors you enable (Google, Microsoft, Slack, Linear, or any MCP server you add) read and write through your own accounts. Sovereign has no Black Label backend; your data does not pass through our servers.
  • Real Estate. Parcel, assessor and hazard lookups query public county, ArcGIS, FEMA and OpenStreetMap endpoints. Skip-trace is off until you connect a provider key; when you run one, the owner's name and street address are sent to that provider (BatchData or RocketSkip). Direct mail is off until you connect a mail-vendor key; when you approve a letter, the recipient's name and mailing address and the letter body are sent to that vendor (Lob or PostGrid) to be printed and posted. Both run on your key, at your cost, and only on the records you act on.
  • Marketing. Publishing is connector-gated: nothing is transmitted until you connect a channel and approve the asset. When you publish, captions, images and video are sent to the social APIs you connected (Meta/Instagram, Threads, X, LinkedIn, Pinterest, Google, Microsoft, HubSpot). If you use the messaging channel, recipient phone numbers and message text are sent to Sendblue. Each provider is consented separately and the consent is withdrawable.
  • Academy. Course content and progress are local, but cohort features run against a Black Label–hosted worker. Joining or participating in a cohort sends a device identifier and lesson-completion events as product interaction data to that hosted service.
  • Vigil. Discovery, control, automations and sensing run on your Mac and your LAN. Raw microphone, camera and sensor-node data is processed there and is never transmitted off your network — the app has no sign-in, no analytics SDK, and no call to any Black Label server, so we cannot receive it. Away Alerts is off until you configure it; once configured, a critical alert POSTs an alert title and message — which can include a resident's name — to the endpoint URL you chose. That endpoint is yours, not ours, and we do not receive the alert.
  • Ace CLI requests. Ace queues the current request text and only requested images through our entitlement-gated gateway. An outbound-only HQ relay runs one ephemeral Codex CLI turn under Black Label's saved ChatGPT subscription login. Shell, web, apps, hooks, plugins, agents, inherited config, credentials, and local filesystem authority are disabled. Microphone audio is transcribed on your Mac and the audio itself is not uploaded.
  • Updates and licensing. Ace, Sovereign, Marketing, Real Estate, Academy and Sunset check our update endpoint for a newer build and validate your licence or subscription. Those requests carry version, licence and device-binding metadata — not your content. Vigil's Mac app is the exception: it ships with no update check and no licence call, so it never sends us a version, a licence key or a device identifier.

Black Label Academy: the optional cohort

Black Label Academy works without a Black Label account. The installed lesson library, notes, review schedule, certificate name, and core lesson progress are stored locally on the device. Academy also offers an optional cohort, which is off by default: until you select Join a cohort, Academy's cohort refresh and lesson-completion paths make no network request.

  • What is sent after you join. Academy sends a random device identifier — generated on your device, not derived from your hardware — and lesson-completion events to the Black Label cohort service. The service also stores the cohort identifier, lesson identifier, membership record, completion markers, and aggregate member and completion counts.
  • What is never sent. The cohort service receives no name and no email. It is not linked to a Black Label account or to an identified person, and it is not used for advertising or cross-app tracking.
  • Why it is collected. To operate cohort membership, to keep completion counting idempotent so finishing a lesson twice never double-counts, to show peer progress, and for aggregate completion analytics.

Cohort membership and lesson-completion records are retained by the cohort service without an automatic expiration while that service operates, unless they are deleted in response to a valid deletion request or removed during service retirement. Leaving a cohort clears active cohort membership on the device and stops future cohort network requests; it does not delete records already retained by the service. Leaving and data deletion are separate actions.

To make a cohort data deletion request, email michael@blacklabelbots.com with the subject Black Label Academy cohort deletion request. Send the request from the device that joined the cohort where possible. Support will provide the steps needed to identify the random cohort record and will confirm when matching cohort membership and lesson-completion records have been deleted.

Third-Party Services You Connect

Most outbound features run on a provider you connect with your own key or login, so the account and the cost are yours. Depending on the app and what you enable, that can include: Anthropic or another prompt-capable CLI provider, and Ollama if you prefer a local model (Sovereign); BatchData or RocketSkip for skip-trace and Lob or PostGrid for print mail (Real Estate); Meta/Instagram, Threads, X, LinkedIn, Pinterest, Google, Microsoft, HubSpot and Sendblue (Marketing); Google, Microsoft, Slack, Linear and any MCP server you add (Sovereign connectors); and any webhook endpoint you nominate for alerts (Vigil). Two services are ours rather than yours: Ace uses OpenAI's Codex CLI through Black Label's managed ChatGPT subscription, and Academy cohorts run on a Black Label–hosted worker. Stripe processes payments, and this website uses Google analytics and advertising services. Those providers operate under their own privacy policies and terms; review them before using the relevant feature.

Selling or Sharing of Data

We do not sell app content. We disclose data only to service providers as needed to operate billing, licensing, downloads, Ace model processing, security, website analytics, and website advertising, or when legally required.

Data Retention and Deletion

Local app data is deleted from the app or Mac by you. Connected-service data is controlled in that service. We retain account, billing, licence, device, security, and quota metadata only as needed to operate and protect the service and meet recordkeeping obligations. Ace gateway logs do not retain prompt or response content.

Children

Black Label products and hosted services are not directed to children under 13.

Changes to This Policy

If we change this policy, we will update the effective date above and post the revised policy at this address. Continued use of the apps after a change means you accept the revised policy.

Contact

Questions about this Privacy Policy or your data? Email mtuburnsbarber@gmail.com.