Privacy policy
Effective October 7, 2026. Operated by zob.llc ("Ablehand," "we").
This policy covers three groups of people. Find yours.
- Visitors to ablehand.ai, including the live demo.
- Customers: people who sign in to the console at app.ablehand.ai.
- End users: people who use Ablehand on a customer's site. For your data, the customer whose site you were on is the controller and we are their processor. Their privacy policy governs; this section tells you what the widget does.
The trust statement has the exact data table, subprocessors, and retention mechanics. This policy does not contradict it; where it is more specific, it wins.
1. Visitors to ablehand.ai
- Server logs. Our host (Vercel) records requests with IP address, user agent, and timestamp for security and debugging, kept for a short period under their retention.
- No advertising or analytics trackers. We do not run third-party analytics or advertising scripts on ablehand.ai.
- The widget on our own pages. ablehand.ai and the demo run the Ablehand widget. If you type a goal into it, that goal and the page's visible controls are processed exactly as described for end users below, with ablehand.ai as the customer. A random identifier is stored in your browser so we can count returning visitors to the demo; it is not derived from anything about you and is not shared.
- Email. If you write to hello@ablehand.ai we keep the correspondence to answer you and for our records.
2. Customers (console users)
- Account data. Name, email, organization, and sign-in identifiers, handled by our authentication provider (Clerk) and stored with your organization record.
- Configuration and insights. Sites, origins, guardrails, hints, appearance, retention settings, and the usage and insights derived from your users' goals. Every change to guardrails, hints, and keys is recorded in an audit log with who made it and when.
- Billing. Card details are handled by our payment processor (Stripe) and never touch our servers. We keep invoices and payment status.
- Email. The weekly digest goes to the addresses you list in the console. We send operational email (install detected, payment issues, material changes to terms). We do not send marketing email to console users without asking.
3. End users (people using Ablehand on a customer's site)
What leaves your browser when you use the bar:
- The goal you typed and any clarifications, redacted in your browser first for card numbers, government identifiers, and secrets.
- A table of the visible, interactive controls on the current page: their roles and labels, never selectors, raw HTML, or your page's code.
- A bounded slice of the page's visible text, redacted the same way. The site may add masking for emails, phone numbers, IP addresses, and custom patterns.
- A short history of the steps taken so far for this goal.
- When the goal ends: its outcome (resolved, blocked, abandoned), the number of steps, the mode, the device type, the start and end page paths, and a random per-browser identifier used to count users. The identifier is not a fingerprint and is not linked to anything about you.
What never leaves your browser: cookies, local storage, authentication tokens, passwords, file inputs, hidden inputs, payment fields and payment-provider frames, request or response bodies, and anything the site has excluded.
The widget can only do what you could already do by clicking in your own session. It never holds credentials. Irreversible actions ask you first.
Why we process this: to choose the next step of your goal and to show the site owner what their users need. Our legal basis is the contract with the site owner; where consent is required for a site's use of an assistant, the site owner obtains it.
Where the data goes
The decision request is processed by our servers and by the structured decision model provider (TypeSafe). If the site enables generated text, the goal and the field label may be sent to OpenAI to compose a short value. Data is stored with our database provider (Neon) and hosted on Vercel, all in the United States. The current list is in the trust statement. We do not sell personal data and do not use the content of goals to train models.
Retention
Decision traces and goal outcomes are kept for the period the site owner sets (default 90 days) and then deleted by a daily job. A site may choose to persist nothing beyond usage counts. Usage counts (daily totals with no content) are kept for billing. Customer account and configuration data is kept while the account is active and for 90 days after it ends.
Your rights and requests
Depending on where you live, you may have the right to access, correct, delete, or export personal data, to object to or restrict processing, and to complain to a supervisory authority.
- End users: contact the site you were using; they are the controller. If you contact us directly we will help you reach them and, where we can identify the data, act on their instruction.
- Customers and visitors: email hello@ablehand.ai. We respond within 30 days. Customers can also export goals and usage from the console and delete a site, which removes its traces and outcomes.
Security
The security measures are described in the security and trust model: redaction in the browser, no selectors or code from the model, same-origin scope, capability gates, access tokens for administration, and audit logging. No system is perfectly secure; if you believe you've found a vulnerability, email hello@ablehand.ai and we will acknowledge within three business days.
Children
Ablehand is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16 for our own purposes.
Changes
We will post updates here with a new effective date and email customers about material changes at least 30 days before they take effect.
Contact
zob.llc · hello@ablehand.ai