Thank you for using our applications and website. Hangzhou Levinthal Biotechnology Co., Ltd. (hereinafter referred to as "we" or "Levinthal") places great importance on protecting personal information and privacy. We have therefore adopted this Lévin™ Harness Privacy Policy (hereinafter referred to as the "Policy") to explain whether and how your personal information is collected, used, shared, transferred, publicly disclosed, stored, and protected when you use our applications and website, and how you can manage that information.
Before you begin using our applications and website, please note that this Policy is an important document governing the rights and obligations between you and Levinthal. Please read all terms carefully, especially those highlighted in bold. If you have any questions, comments, or suggestions about this Policy, you may contact us. If you do not understand or agree to any part of this Policy, please do not use our applications or website. By using our applications or website, you acknowledge that you have read, understood, and accepted this Policy.
This Policy will help you understand the following:
- Applications we provide and the scope of this Policy
- Collection, use, and storage of data
- Data sent to connected services
- Choices and controls
- Data retention and deletion
- Security
- Cross-border data transfers
- Use of the website
- How to exercise your rights
- Protection of minors
- Policy updates
- Miscellaneous
- Contact us
1. Applications We Provide and Scope of This Policy
Lévin™ Harness Preview is a desktop application released by Levinthal and designed with a "local-first" approach (hereinafter referred to as the "Application" or "Lévin™ Harness"). It is currently available only as a preview, and the current version supports macOS only; versions for other platforms are planned.
"Local-first" does not mean that all operations are completed offline. When you configure and use artificial intelligence models (hereinafter referred to as "Models"), web search, iCloud backups, plugins, MCP services, or remote SSH hosts in the Application, the data necessary to complete those operations will be sent to the third-party service providers you select. Those providers process data under their own user agreements and privacy policies. When you use a third-party service, any processing of your personal information by that service is governed by the service's applicable policies. We cannot be responsible for third-party processing activities. We recommend that you read the relevant third-party policies carefully so you understand your rights and obligations.
This Policy applies to Lévin™ Harness and the official Lévin™ Harness website (available at http://levinthal.design/levin-harness/, hereinafter referred to as the "Website").
2. Collection, Use, and Storage of Data
2.1 Collection and Use of Data
Lévin™ Harness can be used without registration. The current version does not provide any user account, login, subscription, or payment system operated or controlled by Lévin™ Harness. Lévin™ Harness does not operate a centralized backend service for receiving, storing, or processing user project content. Your project files, conversation content, prompts, API keys, Model responses, local settings, and runtime logs are stored on your device by default and are not automatically sent to us.
Lévin™ Harness accesses and processes data locally on your device as necessary to execute your requests and save local project state and preferences. Unless you actively configure and invoke a third-party service or actively submit relevant information to us, your project files, conversation content, runtime logs, and diagnostic data will not leave your device and will not be accessed by us.
When you contact us through the methods specified in Section 13, we will receive the information you actively submit. We will not otherwise entrust, share, transfer, or publicly disclose this information to any third party unless you have given prior consent or laws and regulations provide otherwise.
2.2 Data Storage
Depending on the Application features you use, Lévin™ Harness may store the following content on your device, including but not limited to:
- Project folders, file references, working files, and generated outputs;
- Conversations, prompts, Agent plans, workflow definitions, and tool results;
- Application preferences, Model and provider settings, plugin configurations, and remote-device configurations;
- API keys and other credentials you enter;
- Local logs and diagnostic information used to run the Application and investigate problems.
Unless you select a function in the Application to transmit or back up data, the above data (hereinafter referred to as "Local Data") remains under the control of your device's operating system and security measures. Other users or applications with access to your device may also access this Local Data.
We will not access the Local Data described above in any manner, nor will we use your data to train any Model.
Information you actively submit through the contact methods in Section 13 will be stored within the People's Republic of China. Unless we obtain your separate consent and the arrangement complies with applicable laws and regulations, we will not provide that information outside China. Unless applicable laws and regulations require otherwise, we will retain the information only for as long as necessary to process your request. If the Application ceases to operate, we will notify you by announcement or another appropriate means and, within a reasonable period, anonymize or permanently delete the information you submitted, except where laws and regulations provide otherwise.
3. Data Sent to Connected Services
Lévin™ Harness sends data to a connected service only when you use a relevant feature or authorize the corresponding operation, and only to the extent necessary to complete it. Before authorizing an operation, confirm the service provider and the scope of authorization. For data sent by the Application to the services described above, Levinthal acts only as the tool provider and does not determine the recipient, purpose, or retention method. The connected service you select acts as the data processor.
In this Policy, "connected services" means third-party services and external platforms that you actively configure, enable, or authorize in Lévin™ Harness, including the types of services listed in this section and other similar services subsequently supported by the Application.
3.1 Model Providers
To run inference, prompts, conversation context, selected file content, images, tool results, and other inputs may be sent to the Model provider you configure. Data retention and Model-training practices depend on the Model provider, plan, and settings you select. Before sending confidential or regulated information, review the Model provider's data-processing terms.
3.2 Optional iCloud Backup
After you enable the backup feature, the data you select will be uploaded to your Apple iCloud account and will be subject to your Apple settings and Apple's terms.
3.3 Plugins and MCP
Plugins, skills, scripts, and services accessed through MCP (collectively, "Extensions") may execute code, access content within the authorized scope, or connect to third-party services. Extensions are developed by third parties, and Levinthal does not review each Extension's privacy practices. Before enabling any Extension, review its source, publisher, permission scope, and data-processing practices, and independently assess the third party's data policy and permission requests.
Enabled Extensions may, within the authorized scope, receive files, prompts, metadata, credentials, or tool inputs; execute code on local or remote devices; or connect to third-party services.
3.4 Remote SSH Devices
Commands, code, environment information, and task inputs that you authorize will be sent to the host you configure. Data on the host is controlled by you and the host operator.
3.5 Web Search and Websites
Search terms will be sent to the search service you select. When you open a webpage, the website operator may receive standard web-request data such as your IP address, browser information, and requested URL.
3.6 External Links and Services
When you access or use Discord, GitHub, model providers, or other external websites, the relevant platform may collect data under its own policy.
3.7 Model Training and Provider Controls
Lévin™ Harness cannot control whether a third-party Model provider retains the data you submit or uses it to improve its Models. Before sending confidential or regulated information, review the privacy, retention, and training options provided by the Model provider.
4. Choices and Controls
While using the Application, you can make the following choices and exercise the following controls:
- Choose the Model provider, endpoint, and Model you use.
- If you do not want data sent to a particular service or Extension, do not connect to or enable that service or Extension.
- Limit permissions for files, folders, plugins, MCP, and remote hosts to the scope required for the task.
- Choose whether to enable or disable iCloud backup.
- Use features provided by the Application or operating system to delete local projects, conversations, settings, credentials, and Application data.
- Manage or delete information held by third-party services through their control panels.
5. Data Retention and Deletion
Local Data remains on your device until you delete it, uninstall the Application and remove the corresponding data, or your device's operating system clears it. After you delete data locally, backups and remote copies may continue to exist; you must manage them through the applicable backup service, provider, or host.
Third-party services retain data according to their policies and your settings on those services. Retention or deletion of information posted to GitHub or Discord is controlled by these platforms, and the information may continue to exist in thread histories, messages, backups, or review records.
Because Lévin™ Harness does not require registration and does not provide an account system, you do not need to close a Lévin™ Harness account or ask us to delete account data. If you maintain an account with a third-party service, please follow that service's rules to close or delete the account and related data.
6. Security
We will endeavor to adopt reasonable security measures appropriate for the Application, but no device, network, Model, Extension, or remote host can be guaranteed to be completely secure. Except for the scenarios expressly described in this Policy (including connected services you configure and webpage access you initiate), the Application will not send data to any server. Protect your device account, Mac account, storage devices, provider keys, SSH credentials, and backups; follow the principle of least privilege; and promptly rotate credentials that may have been exposed.
Please do not publish reports involving your sensitive personal information through public channels. If you need to make such a report, contact us using the email address specified in Section 13.
7. Cross-Border Data Transfers
The model providers, the iCloud region associated with your Apple account, GitHub, Discord, website operators, plugins, or remote hosts you configure may process data in other countries or regions. You are responsible for selecting services and regions that meet the laws, contracts, compliance requirements, and data-governance requirements applicable to you. Because data transfers occur between you and the third-party services you select, rather than between you and Levinthal, Levinthal does not participate in or control any cross-border transfer of your data and therefore does not assume the compliance obligations for cross-border transfers performed by personal-information processors.
8. Use of the Website
The Website is a static site and does not contain account or payment forms. The Website does not provide account registration, collect information that identifies users, or use analytics tools. The Website does not currently use cookies; it only uses browser local storage to save language preferences.
The Website's hosting provider may process standard server information such as IP address, access time, requested page, user agent, and security events. Standard server logs maintained by the Website's hosting provider, if any, are handled by the hosting provider under its own policy; Levinthal does not actively collect or analyze the information described above.
The Website's "Support & Feedback" module does not provide a form or submission channel; it only provides links to third-party platforms such as Discord and GitHub. You may use those links to provide feedback about problems and suggestions arising from your use of the Application. We will not receive, store, or forward any user information through this module. All content you submit or publish on third-party platforms such as Discord and GitHub is handled by the relevant platform and its operator under their applicable policies. Before sharing on a third-party platform, remove your API keys, passwords, sensitive personal information, confidential data, and file content unrelated to the Application.
9. How to Exercise Your Rights
For personal information you actively provide to us through the contact methods specified in Section 13, you have the right to restrict or refuse our processing of your personal information, except where laws and regulations provide otherwise. You may request that we stop processing or delete relevant information by notifying us through the contact methods specified in Section 13. After you request that we stop processing or delete relevant information, we will no longer process the relevant personal information; however, please understand that this may prevent us from processing your requests.
You manage Local Data on your device directly through the Application or your device's operating system.
For data transmitted between you and a third-party service, or information you publish on external platforms such as Discord and GitHub, submit requests for notice, decision, access, copying, correction, supplementation, deletion, or export to the relevant service provider or platform operator.
If your request concerns standard server logs held by the Website's hosting provider, submit it to the hosting provider because it holds the relevant data.
If you have any questions about this Policy or believe that our handling of personal information violates this Policy or applicable laws and regulations, you may contact us at the email address specified in Section 13, and we will respond within the period required by applicable law. If you believe that our processing of personal information violates applicable law, you may also file a complaint with the regulator that has jurisdiction over the matter, as permitted by law.
10. Protection of Minors
Anyone who cannot legally consent to using our Application or Website independently should do so only with a parent or guardian's consent.
Unless you have a lawful basis, necessary authorization, and appropriate protective measures, please do not use our Application to process children's personal information. Our Application does not intentionally collect children's personal information. If you believe that children's information is stored locally on your device, you may directly delete the relevant data.
11. Policy Updates
We may update this Policy as the Application is updated or legal requirements change. The top of this page will show the most recent update date. We will notify you of material changes through the Website or another appropriate channel.
If you do not understand or agree to an update to this Policy, please stop using our Application and Website after the update takes effect.
12. Miscellaneous
This Policy is made in both Chinese and English. If there is any inconsistency, ambiguity, or conflict between the two language versions, the Chinese version shall prevail.
The formation, validity, interpretation, performance, and dispute resolution of this Policy are governed by the laws of the People's Republic of China (for purposes of this Policy, excluding the laws of the Hong Kong Special Administrative Region, the Macao Special Administrative Region, and Taiwan). Any dispute arising from this Policy or your use of our Application or Website should be resolved through friendly consultation. If consultation fails, either party may bring an action before the people's court with jurisdiction over Hangzhou Levinthal Biotechnology Co., Ltd.'s domicile.
13. Contact Us
13.1 If you have any issue using the Application or Website, please visit the Website's "Support & Feedback" module. You may also contact us using the following information:
Email: info@levinthal.bio
13.2 If you need to file a complaint because your lawful rights and interests have been infringed, you must submit valid proof of identity and contact information, together with a written request and preliminary evidence of the infringement. We will process your request as soon as possible after verifying your identity and respond within the period required by applicable law.
13.3 Contact address: 2nd Floor, Building 1, X-Valley, No. 2 Qiannong 1st Road, Xiaoshan District, Hangzhou, Zhejiang Province, China.