Skip to content

Narrative Council · Hajar Labs LLC

Privacy Notice and Notice at Collection

Version 2026-09-01-public-3

# Privacy Notice and Notice at Collection **Effective date:** September 1, 2026 **Last updated:** September 1, 2026 Hajar Labs LLC, a Texas limited liability company, operates the Narrative Council product. Our address is 2916 Grand Mission Way, Pflugerville, TX 78660. For privacy questions, requests, or appeals, email keith@narrativecouncil.com. This notice explains how we handle personal information when you visit, create an account, purchase, or use Narrative Council. ## 1. Information we collect Depending on how you use the service, we collect: - **Account and contact information:** name, email address, authentication details, and account preferences. - **Project information:** instructions, documents, text, images, audio, links, research inputs, decisions, and generated work related to your engagement. - **Transaction information:** purchase status, amount, tax, payment status, refund status, and Stripe-provided payment identifiers. Stripe, not Hajar Labs, receives and stores full payment-card information. - **Device and service information:** IP address, browser and device characteristics, logs necessary for security and reliable operation, and essential storage choices. - **Support, privacy, and dispute information:** messages, requests, verification information, and records needed to respond. Please do not submit sensitive personal information or confidential third-party material unless you have a lawful basis and the material is genuinely necessary for the engagement. We do not seek to collect children's information; the service is for people 18 and older. ## 2. How and why we use information We use personal information to provide, secure, personalize, and support the service; create and administer accounts; process payment and tax; generate and deliver your Playbook; prevent fraud and abuse; maintain records; comply with law; and resolve disputes. We process only information that is adequate, relevant, and reasonably necessary for these purposes. We may use aggregated or de-identified information for reliability and product analysis where permitted by law. We do not sell personal information. We do not share personal information for cross-context behavioral advertising. Optional analytics are off by default and will not run unless an approved consent flow is active and you grant the optional choice. We do not make eligibility, lending, housing, insurance, employment, education, criminal-justice, or basic-necessity decisions about you through profiling. ## 3. Service providers and AI processing We disclose information to service providers that process it for us and under our instructions, including payment, cloud, storage, authentication, email, security, research, and AI-processing providers. The current public provider disclosures identify active categories and named services. These include Google Gemini for limited source extraction, AssemblyAI for client-requested voice transcription, Cloudflare Workers AI and Vectorize for scoped retrieval, Cloudflare Workers AI as a bounded fallback host for approved DeepSeek and GLM model workloads, Cloudflare R2 for object storage, Cloudflare AI Gateway when configured as an approved request transport or observability layer, OpenRouter as the primary transport to specifically allowlisted model-hosting endpoints for strategic reasoning and review, and Tavily for public-web research only. Private uploaded material is not intended for Tavily queries. We do not state a universal data-residency, provider-retention, zero-retention, or model-training promise because those details depend on the active provider configuration and current provider terms. OpenRouter requests use exact model identifiers with a preferred upstream-provider ordering and resilient fallback routing across providers that satisfy strict privacy requirements: zero-data-retention routing, denied provider data collection, and required structured-output parameter support. Request metadata such as token counts and latency may still be retained, and processing location depends on the selected endpoint. Qualified GPT-OSS model workloads may be hosted by DeepInfra, CoreWeave, Together, or Groq through OpenRouter's BYOK routing. Approved DeepSeek and GLM model workloads may be hosted by Cloudflare Workers AI as a fallback. Direct OpenAI and the direct DeepSeek API are not current default processors for new public engagements unless an explicitly authorized current provider profile and disclosure permit them. Read the AI Provider Disclosure and Subprocessors page for the current role-based information. ## 4. Retention and deletion We apply the following ordinary retention schedule, unless a longer period is needed for a legal, tax, security, fraud, or dispute hold: - incomplete browser or server-side project drafts: **90 days**; - uploaded project materials: **6 months**; - final Playbooks and account project records: **3 years**, or earlier following a verified deletion request where feasible; - backups: rolling expiration within **90 days**; and - transactional, tax, payment, legal, security, and dispute records: as long as legally required or reasonably necessary for those purposes. Deletion from active systems does not always instantly remove information from protected backups; those copies roll off under the backup schedule unless a lawful hold applies. We may retain the minimum information necessary to honor a deletion request and prevent reprocessing. ## 5. Your choices and privacy rights You may update certain account information in your account. Depending on applicable law, you may request confirmation of processing, access, correction, deletion, portability, restriction, or information about our disclosures. You may also opt out of targeted advertising, sale, or certain profiling if those activities ever apply. We will not discriminate against you for exercising applicable rights. Submit a request using the authenticated account privacy-request feature or by emailing keith@narrativecouncil.com with the subject line "Privacy request." Include the account email and the right you want to exercise; do not send passwords or card numbers. Because Narrative Council operates online and has a direct relationship with its users, email is also our secure direct request channel. We may verify your identity and authority before acting. An authorized agent may make a request where applicable, subject to verification of authority. Where the Texas Data Privacy and Security Act applies, we will respond to an authenticated request within the period required by law, normally within 45 days, with any permitted extension explained. If we deny a request, you may appeal by emailing keith@narrativecouncil.com with "Privacy appeal" in the subject line within a reasonable time after the decision. We will explain our appeal decision in writing within the period required by law and, if we deny the appeal, provide the applicable Texas Attorney General complaint mechanism. This notice does not limit any right required by applicable law. ## 6. Security and incidents We use reasonable administrative, technical, and organizational safeguards designed to protect personal information, including access controls and service-provider controls. No method of transmission or storage is completely secure. If we determine that a security incident requires notice, we will notify affected people and regulators as required by applicable law. ## 7. Changes and contact We may update this notice as our practices or legal requirements change. We will post the new version with its effective date. Contact keith@narrativecouncil.com for questions, requests, appeals, or complaints.