Privacy notice
Local-first by design — here's exactly what leaves your machine, and why.
Last updated July 29, 2026
1. Who is responsible
Ahjola is operated by Axel Adlercreutz, who acts as the data controller for the personal data described in this notice. For any privacy question or request, contact support@ahjola.dev.
2. Local-first by design
Ahjola reads your Claude configuration directly from your machine using your browser's file system access. Your artifacts, version history and audit results stay on your device. Nothing in your configuration is sent to our servers unless you explicitly publish a bundle, join a team workspace with sync enabled, or use an AI-assisted feature on a specific artifact.
3. What we collect and why
- Account data — email address, name and avatar from your sign-in provider, and your chosen handle. Used to create and operate your account. Legal basis: performance of our contract with you.
- Published content — bundles and artifacts you choose to publish, after the built-in secret scrubber runs. Used to provide the marketplace and team registries. Legal basis: performance of contract.
- AI feature inputs — the content of an artifact you ask the AI editor to modify, sent for processing and not used to train models by us. Legal basis: performance of contract.
- Usage and telemetry — aggregated usage rollups you opt to sync, and team telemetry (token/cost metrics) sent by your own tooling to your team workspace. Used for usage dashboards. Legal basis: performance of contract and our legitimate interest in providing team features.
- Support messages — what you send us when you ask for help. Legal basis: legitimate interest in supporting users.
- Log and device data — IP address, browser type and request logs generated when the app talks to our backend. Used for security, fraud prevention and service operation. Legal basis: legitimate interest in keeping the Service secure.
Payment data (card details, billing address) is collected and processed by Paddle as Merchant of Record, not by us.
4. Who we share data with
- Infrastructure and hosting providers that run our backend, database, authentication and AI processing (acting as our processors);
- Paddle, our Merchant of Record, for the sale of subscriptions, payments, tax compliance, invoicing and subscription management;
- Professional advisers (legal, accounting) where needed;
- Authorities, where required by law.
We do not sell personal data.
5. International transfers
Some of our processors operate outside the EEA. Where personal data leaves the EEA, we rely on safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision.
6. Retention
We keep personal data only as long as needed for the purposes above: account data for the life of your account, published content until you unpublish or delete it, and logs for a short rolling window. When data is no longer needed it is deleted or anonymised. Deleting your account removes your account data and personal-scope content; your local files are untouched because we never had them.
7. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict and port your personal data, to object to processing based on legitimate interests, and to withdraw consent where processing is based on consent. Contact support@ahjola.dev and we will respond within one month. You also have the right to lodge a complaint with your supervisory authority — in Finland, the Office of the Data Protection Ombudsman (tietosuoja.fi).
8. Security
We apply appropriate technical and organisational measures: encryption in transit, row-level access controls on all cloud data, scoped tokens for telemetry ingest, and secret scrubbing before anything you publish leaves your machine.
9. Cookies and local storage
Ahjola uses only essential browser storage: your authentication session and local app state (such as demo data and connection handles) are kept in your browser's local storage and IndexedDB. We do not use advertising or third-party analytics cookies.