Effective: August 8, 2026
This Privacy Policy applies to all software, websites, and services operated by Locke Werks ("we," "us," "our"), including but not limited to ARCHON, Attest, DeadLetter, and Witness (collectively, the "Services"). By using any of our Services, you agree to the collection and use of information as described here.
Not every Service collects the same information, and some collect none at all. Sections 1 and 2 describe the maximum scope of what we may collect across our Services. Section 3 states what each individual product actually does, and where a product collects nothing, that governs. DeadLetter is a locally installed desktop application with no backend service: it collects nothing and transmits nothing to us. See Sections 3 and 4.
Information you provide directly:
Information collected automatically (server-backed Services only; never DeadLetter):
Information we do not collect:
We will never sell your personal information. We will never share your email address with third parties for marketing purposes.
ARCHON: Game progress, scores, and leaderboard entries are stored to provide gameplay features. Leaderboard data (display name, scores) is publicly visible by design.
Attest: Creative session data, audio fingerprints, and attestation manifests are stored to provide cryptographic provenance services. Manifests you choose to publish become publicly verifiable. Email addresses collected for launch notifications are used solely for that purpose and are never distributed or sold.
Witness: Photographs, cryptographic hashes, timestamps, and chain-of-custody records are stored to provide evidence integrity services. Your evidence data is encrypted in transit and at rest. We do not access, view, or analyze the content of your photographs except as required to provide the Service or as compelled by law.
DeadLetter: DeadLetter is a desktop email client that runs entirely on your own computer. It has no backend service. We collect nothing from it: no personal information, no mail content, no account details, no usage statistics, no crash reports, no analytics, and no install or launch pings. Your messages, attachments, search index, and settings are stored locally on your device. Account credentials and OAuth tokens are held by your operating system's credential store (Credential Manager on Windows, Keychain on macOS, Secret Service via libsecret on Linux). The application communicates only with the mail providers you choose to connect. None of the automatic collection described in Section 1 applies to DeadLetter, because DeadLetter transmits nothing to us. See Section 4 for how DeadLetter handles Google user data.
This section applies to DeadLetter when you connect a Gmail or Google Workspace account. It describes what DeadLetter accesses through Google APIs and what it does with it.
Permissions requested. DeadLetter requests two Google permissions, and only these two:
https://www.googleapis.com/auth/gmail.modify — to read your messages so they can be displayed, indexed for search, and cached for offline use; to send the messages you compose; and to apply the changes you make in the application, such as marking read or unread, starring, archiving, moving, and labeling. This permission does not allow permanent deletion of your mail, and is requested instead of full Gmail access for that reason.https://www.googleapis.com/auth/calendar — to display the calendar attached to that account, render meeting invitations that arrive as email, and let you accept, decline, and create events from within the application. The full calendar permission is required because reading and writing calendar sharing settings is not possible with the narrower events-only permission.Where the data goes. Google user data travels directly between Google's servers and the copy of DeadLetter installed on your computer. It is not sent to Locke Werks, is not routed through any server we operate, and is not stored by us in any form. We operate no infrastructure that touches it. Mail retrieved from Google is cached in a local database on your own disk to provide offline access and search.
Authentication. Sign-in uses OAuth 2.0 with PKCE and takes place on Google's own sign-in page in your browser. DeadLetter never receives, sees, or stores your Google password. The resulting access and refresh tokens are stored in your operating system's credential store.
Limited Use. DeadLetter's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
Retention and revocation. Because we hold no Google user data, there is nothing for us to retain or delete. Data cached locally by DeadLetter is removed when you remove the account from the application or uninstall it. You may revoke DeadLetter's access to your Google account at any time at myaccount.google.com/permissions.
We may share your information only in these circumstances:
We implement industry-standard security measures to protect your data, including encryption in transit (TLS), encryption at rest, access controls, and regular security assessments. However, no system is perfectly secure. We cannot guarantee absolute security, but we commit to promptly notifying affected users in the event of a data breach.
We retain your data for as long as your account is active or as needed to provide our Services. If you request deletion of your account, we will remove your personal data within 30 days, except where retention is required by law or necessary to fulfill our legal obligations. Anonymized, aggregate data may be retained indefinitely.
Depending on your jurisdiction, you may have the right to:
To exercise any of these rights, contact us at privacy@lockewerks.com.
Our Services are not directed at children under 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will delete it promptly. If you believe a child under 13 has provided us with personal information, please contact us.
Our Services may contain links to or integrate with third-party services (e.g., payment processors, analytics providers, AI generation platforms). These third parties have their own privacy policies, and we are not responsible for their practices. We encourage you to review their policies.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the effective date. Continued use of our Services after changes become effective constitutes acceptance of the revised policy.
If you have questions about this Privacy Policy or our data practices, contact us at:
privacy@lockewerks.com
Locke Werks
Colorado Springs, CO