HalAxe Privacy Policy
Effective date: 16 September 2026
In short: HalAxe is a desktop application that runs entirely on your own computer. There is no HalAxe account, no HalAxe server, and no sign-up. The developer does not collect, receive, transmit, or have access to any of your data. Everything HalAxe stores stays on your device, encrypted.
1. Overview
HalAxe is a local proxy application. It sits between your tools and the APIs you connect to, and it handles authentication on your behalf. To do this, HalAxe stores the connection settings and credentials you provide, and it makes network requests to the services you configure.
This policy explains what information HalAxe handles, where it is kept, what leaves your computer and to whom, and the choices you have. It applies to the HalAxe desktop application distributed through the Microsoft Store.
2. Information HalAxe Handles
All of the following is created and stored locally on your computer to make HalAxe work. It is never sent to the developer.
- Environment settings: the names, Base URLs, authorization URLs, token URLs, redirect URLs, and scopes you enter for each connection.
- Credentials and secrets: OAuth Client IDs and Client Secrets, usernames and passwords (for the Resource Owner Password flow), and any fixed HTTP headers you configure, such as API keys or bearer tokens.
- Access and refresh tokens obtained from your identity provider during sign-in.
- Email (SMTP) settings: host, port, username, password, and from-address, only if you choose to import an email configuration for an environment.
- Saved queries and schema addresses you create for the built-in AI assistant feature.
- Local activity logs: per-environment records of requests and any errors, used for troubleshooting on your machine.
- Application state: your preferences, a local security certificate for optional HTTPS, and a per-user key file used for encryption.
3. How Your Data Is Stored and Protected
HalAxe keeps its data in a single folder on your computer (on Windows, typically
%AppData%\halaxe).
- Sensitive data is encrypted at rest using AES-256-GCM and further protected with the Windows Data Protection API (DPAPI).
- This protection is tied to your Windows user account, so the stored files cannot be read on another machine or by another user, even if the files are copied.
- Access tokens are held encrypted in memory only and are not written to disk in a form that survives closing the application.
- None of this data is transmitted to the developer or to any HalAxe-operated service, because no such service exists.
4. Data That Leaves Your Device
HalAxe only sends data to destinations that you choose, plus Microsoft for the reasons described below. Specifically:
- The APIs you configure: HalAxe forwards your requests to the upstream API hosts you set up, adding the authentication those requests require.
- The identity providers you configure: HalAxe contacts your authorization and token endpoints to sign in and to refresh tokens.
- Your mail server: if you use the email feature, HalAxe connects to the SMTP server you configured and passes your message through to it. HalAxe does not retain the message afterward.
- Schema addresses you provide: when using the AI assistant feature, HalAxe may fetch an API schema from a URL you specify.
- Microsoft: for license verification, in-app purchases, and automatic updates through the Microsoft Store (see section 8).
HalAxe does not send your data anywhere else. Because HalAxe is a proxy, it needs network access to reach whatever hosts you configure. It does not contact any other destination on its own.
5. Sign-In Windows
For browser-based sign-in (Authorization Code and PKCE flows), HalAxe opens either your default web browser or an embedded Microsoft Edge WebView2 window. The credentials you type there go directly to your identity provider, not to HalAxe. HalAxe only receives the result of a successful sign-in. WebView2 is a Microsoft component and is governed by Microsoft's privacy terms.
6. AI Assistant Feature
HalAxe includes an optional built-in server that lets an AI assistant query your APIs, explore their schemas, run saved queries, and send email through HalAxe. When enabled, this server listens only on your local machine. Data returned from your APIs passes through to the connected AI tool at your direction. Your stored credentials and secrets are never exposed to the AI assistant; HalAxe applies authentication itself and only returns the API response.
7. Email Sending
If you import an email configuration for an environment, HalAxe can send email on your behalf through your own SMTP server, including when requested by a connected AI assistant. The email content is delivered to your mail server and is not stored by HalAxe beyond completing the send. The SMTP configuration itself is stored encrypted on your device, like your other credentials.
8. Microsoft Store and Purchases
HalAxe is distributed through the Microsoft Store. When it starts, and when you make a purchase, HalAxe uses the Microsoft Store services on your device to verify your license and any in-app purchases, and to receive automatic updates. This communication is with Microsoft, not with the developer.
All purchases and payments are handled entirely by the Microsoft Store. HalAxe never sees, receives, or stores your payment details. Microsoft's handling of that information is governed by the Microsoft Privacy Statement.
9. Analytics and Tracking
HalAxe contains no analytics, no telemetry, no advertising, and no tracking of any kind. It does not build a profile of you, and it does not report your usage to the developer or to any third party.
10. Data Retention and Deletion
Your data remains on your computer until you remove it. You are always in control:
- Delete an environment in HalAxe to remove its settings and stored credentials.
- Uninstall HalAxe, and delete its data folder (on Windows,
%AppData%\halaxe), to remove everything it stored. - Use the built-in Export feature to make your own encrypted, PIN-protected backup. Backups are created and kept by you, not by HalAxe.
11. Children's Privacy
HalAxe is a developer and productivity tool. It is not directed at children and is not intended for use by children.
12. Changes to This Policy
If this policy changes, the updated version will be posted on this page with a new effective date. Continued use of HalAxe after an update means you accept the revised policy.
13. About HalAxe.com
The halaxe.com website is a static informational site, separate from the HalAxe application described above. We place no cookies, run no analytics, use no tracking, and provide no sign-up, and we do not collect personal information from visitors ourselves.
The website is served by a third-party hosting provider. To deliver the pages, that provider necessarily processes standard technical connection data, such as your IP address and browser type, and may keep its own server or access logs. This processing is carried out by the host under its own privacy terms, not by us, and we do not use that data to identify you. Our current hosting provider is Cloudflare, Inc. (Cloudflare Pages), whose privacy policy is available at https://www.cloudflare.com/privacypolicy/.
If you email us using the address below, we receive your message and email address solely to reply to you.
14. Contact
If you have questions about this policy or about how HalAxe handles data, contact: