Skip to content
Castellan

Privacy notice

Effective October 7, 2026

The short version. Castellan's AI runs on your PC, on its NPU, GPU or CPU, and your files never leave it: no cloud AI, no uploads, no one reading your documents, photos or code. Castellan has no advertising, no analytics and no tracking. It goes online to check your licence, to fetch updates, and to fetch what you ask an agent to fetch. All of it is listed below.

Who we are

Castellan is sold by Jeremy Collier (“we”). Questions about this notice, or about your data: support@castellan-software.com.

What stays on your PC

  • Everything the AI reads. The local model sees only what an agent asks it about, and only on your PC: a few lines of a document's text for Warrener (with personal details taken out first), one frame of a video for Miller, a rollback's evidence for Lamplighter, your screenshots' text for Clerk.
  • Your files, your mail and your code. Indexes, captions, search pages and each agent's records stay in your user folder. Chamberlain reads your mail from your own mail server, with the password kept by Windows' own protection (DPAPI).
  • Logs. Each agent's log holds your Windows user name and file paths. They stay on your PC.
  • Settings backups. Castellan backs up its settings once a day to a folder you choose in Settings. If that folder is one a cloud service syncs (OneDrive often syncs Documents), that service gets a copy.

What goes online, and why

Your licence: the Exchequer

The Exchequer is our licence and release service. When you buy, the payment goes through Stripe, and we keep your email address and Stripe's customer and subscription identifiers. When a PC takes a place on your licence, it sends:

  • a random identifier Castellan makes for that PC (not a hardware fingerprint), the PC's name and its kind of processor;
  • your licence key, or your email and a sign-in code, and the PC's IP address with the request.

We keep:

  • your licence, and only scrambled hashes of your key and of each PC's token, never the key itself;
  • each PC on the licence, with when it joined and when it last checked in;
  • each download (which licence, which PC, which agent and version, when), kept 400 days;
  • hashed IP addresses and hashed emails for the limits on trials and sign-in codes, kept one day.

Once an hour, Castellan asks the Exchequer which new releases your licence covers, and once a week it refreshes the licence.

Updates and setup

  • Castellan's own updates and Heiward's come from GitHub; the staff's come from the Exchequer.
  • The setup downloads Node.js, the runtime the agents run on, from nodejs.org.
  • Setting up the local AI downloads its model servers (llama.cpp, from GitHub) and its models (from Hugging Face, several gigabytes), and your NPU's runtime from its maker.
  • To know whether it's online, Castellan opens a connection to github.com, www.msftconnecttest.com and www.cloudflare.com, at most once a minute. No data is sent.

What each agent fetches

  • Herald fetches the news you follow. For the weather and local news it sends a place name and rounded coordinates (Open-Meteo, OpenStreetMap's Nominatim, the US National Weather Service, Google News); for games, the names of the games installed (Steam, GOG); for markets, the stock symbols you follow (Yahoo Finance).
  • Reeve fetches your repositories from their own remotes, package documentation (npm, jsDelivr, GitHub), and GitHub's security alerts through your own GitHub sign-in. Its answers go to the AI assistant you use, under that assistant's own terms.
  • Weigher checks the connection with Microsoft's connectivity test every minute, and runs Cloudflare's speed test every 3 hours (never on a metered connection).
  • Lamplighter, after rolling a driver back, asks Windows Update for drivers.
  • Thatcher asks Windows' own package manager which apps have updates.
  • Surveyor reads only the agents' own pages on your PC, and GitHub for what's new.
  • Developer Herald, Pinder, Aletaster and the Steward, the developer agents, talk to GitHub through your own sign-in, for your own repositories.

Signing in with your email

When you sign in on this site, or sign a PC in, with your email, a six-digit code is sent to it. Supabase checks the code; Resend delivers the email.

This website

This site sets no cookies and has no analytics. Our host, Vercel, keeps standard server logs (IP address, the page asked for, the browser) for a short time to run and protect the service. The theme you pick is remembered in your browser only. Signed in, your account page keeps its sign-in in that browser tab only, until the tab closes or 12 hours pass, and talks to our licence service directly.

Who processes data for us

ServiceWhat for
StripePayments, subscriptions, invoices and sales tax.
SupabaseThe Exchequer's database, and checking sign-in codes.
VercelHosting this site and the Exchequer.
CloudflareStoring release files (R2), the domain, and forwarding email sent to support.
ResendDelivering sign-in codes.

We don't sell your data, and we don't share it with anyone else unless the law requires it.

Your choices and rights

  • Give a PC's place back in Castellan's Settings, and its token is retired.
  • Manage or cancel your subscription in Stripe's customer portal (Settings, Licence, Manage subscription).
  • Ask us for a copy of what we hold about you, to correct it, or to delete it: support@castellan-software.com. We keep invoices as long as tax law requires.
  • Uninstalling Castellan removes it from your PC; you choose whether its settings and data go too.

Changes

When an agent starts sending something new, this notice says so first, and the release notes name the change. The date at the top is when it last changed. The licence terms are a separate page.