Privacy · Release-candidate policy
Privacy, in concrete terms.
SystemLens collects bounded Windows diagnostic evidence only when an authenticated user asks it to inspect a paired PC.
This policy reflects the current implementation. The legal controller, public contact, production log-retention period, and effective date must be finalized before public distribution.
Data processed
Depending on the requested tool, SystemLens can process an internal account subject; device UUID and label; OS and hardware summaries; fixed-volume storage; process names and resource totals; startup entries; driver metadata; sanitized grouped crash or Windows diagnostic-event evidence; service state; minimized network state; attached USB metadata; bounded installed-software metadata; and safe OS-reported sensor availability.
How collection works
Collection is on demand. The companion validates each request against a fixed allowlist, applies local sanitization, and returns a bounded structured result. It does not continuously index the computer or personal documents.
Storage and retention
Ordinary collector results exist in backend memory for the request. User-created diagnostic snapshots are encrypted with AES-256-GCM and expire after a short configured TTL; the current release-candidate default is 30 minutes. Pairing codes expire after 10 minutes and are single-use. Device metadata and a one-way device-token verifier remain until disconnection or account deletion.
Operational logs contain metadata such as request ID, tool, latency, status, and stable error code—never ordinary raw telemetry. The production retention duration is a launch blocker and will be published here before release.
Explicitly excluded
SystemLens does not collect arbitrary file contents, documents, browser activity, passwords, tokens, command lines, process memory, keystrokes, clipboard data, camera or microphone input, unrestricted Registry data, or unrestricted Event Logs. User-profile paths and common secret patterns are sanitized locally before transmission.
Sharing and model use
Requested diagnostic results are returned to the authenticated OpenAI host so it can answer the user. SystemLens does not sell telemetry and includes no advertising or third-party analytics. OpenAI handles information under the user’s applicable OpenAI terms and settings.
Deletion
Users can delete snapshots early, revoke paired devices, remove the local companion credential, and request account deletion once the public support channel is live.