Privacy

Last updated 25 July 2026 · AwareLock 1.0

AwareLock is a camera-based security tool, so the honest question is not whether we respect your privacy but what actually happens to the video. The answer is that it never leaves your computer, and this page explains exactly what does.

In one line: the app sends us your licence key and a hash that identifies your machine. Nothing else. No images, no video, no descriptors, no usage analytics, no crash reports.

What stays on your computer

  • Camera frames. Processed in memory to answer one question — is the enrolled person present — and then discarded. They are never written to disk except as an intruder clip you enabled.
  • Face templates. Enrolment stores 128 numbers per look. These are measurements, not pictures: there is no way to reconstruct a photograph from them. They are encrypted at rest with a key derived from your hardware, so copying them to another machine yields unreadable data.
  • Intruder clips. Written to your own disk, capped in total size, and deleted automatically after the retention period you set (30 days maximum). Nothing is uploaded, ever. Delete them at any time from Intruder clips.
  • Settings and logs. A plain settings file and a local log. The log deliberately contains no licence key and no hardware identifier.

What is sent to us

Only when you activate a licence, and then roughly once every few days to confirm it is still valid:

Data Why How it is stored
Your licence key To check it exists and is unused Never stored. We keep only a keyed hash (HMAC-SHA256 with a secret pepper), so a copy of our database cannot be used to recover or guess keys.
A hardware fingerprint To bind one key to one computer, which is what stops a copied installer from working elsewhere The app hashes your machine's identifiers before sending; we store a hash of that hash. Raw identifiers never leave your computer, and the app never displays them.
Computer name, OS, app version So you can recognise your own device in support requests Plain text, alongside the licence record.
Your email address To send your keys and answer support Stored with the order. Provided to Stripe (payment) and Resend (email delivery) for those purposes only.
IP address Rate limiting, to make key guessing impractical Kept for 24 hours in a counter table, then deleted.

Who else is involved

  • Stripe processes payment. We never see or store your card details. See Stripe's own privacy policy for what they retain.
  • Resend delivers the email containing your keys.
  • Hetzner hosts the licence server, in Finland (EU). Backups stay in the same region.

There is no analytics provider, no advertising, no third-party script on this website, and no tracking cookie. The site sets no cookies at all.

How long we keep things

  • Licence records for as long as the licence exists — it is perpetual, so that means indefinitely, or until you ask us to delete it.
  • A recoverable copy of freshly issued keys for 14 days, encrypted, so the success page can show them and support can resend them. Then it is erased.
  • Rate-limit counters for 24 hours. Server event log for 90 days.

Your choices

  • Erase everything locally — Settings → Data → Erase. Face data, clips and the local licence are removed from your computer.
  • Move to another computer — Settings → Licence → Release this computer. The fingerprint is cleared from our records.
  • Ask us to delete your data — email support and we will remove the order and licence records. Note that this also invalidates the key, so it cannot be used afterwards.
  • Get a copy of what we hold — email support with the first block of your key (AWL-XXXX) and we will send it.

Children

AwareLock is not directed at children and we do not knowingly collect their data.

Changes

If this policy changes in a way that affects what we collect, the date at the top changes and the previous version is available on request. We will not start collecting new categories of data from an installed version without saying so.

Contact

Mikkel Lorenz, Denmark — email. If you are in the EU or UK and unhappy with our answer, you may complain to your national data protection authority.