The short version. Munder Difflin runs on your computer. The app does not send us your prompts, your code, your files or the API keys you enter, apart from Teams messages, which pass through our server encrypted. We do collect some information: your account details, what you buy, some facts about the computers you activate, usage events from the app and our websites, and your email address so we can write to you. This policy explains what we collect, why, who else handles it, and what you can do about it.
1. Who we are
Munder Difflin is made and sold by Chaitanya Information Technologies. In this policy "we", "us" and "our" mean Chaitanya Information Technologies. You can reach us about anything in this policy at support@harnessmd.com.
2. What this policy covers
This policy applies from 22 September 2026 to:
- the Munder Difflin desktop app, version 0.5.2 and later;
- our website munderdiffl.in; and
- harnessmd.com, including app.harnessmd.com, where you create an account, buy a plan, use the console, manage licences and teams, and download the app.
Together we call these the services. This policy does not describe earlier versions of the app. Services you connect to the app yourself have their own policies (section 10).
3. What stays on your computer
The app runs command line AI agents on your computer. Your prompts, what your agents produce, your code and files, the API keys and tokens you enter, and your agents' memory, tasks and history are kept on your computer, and the app does not send them to us. The one exception is Teams: messages and requests between your team's machines pass through our server, encrypted (section 4).
4. Information we collect
Your account. From version 0.5.2 the app needs an account, and a free one is enough. Accounts are run by Clerk, our sign in provider, which holds your email address, your name if you give one, and what it needs to sign you in. Our server keeps your account id. It also keeps your email address where a feature needs it, for example when you register a free install, are invited to or join a team, or receive a gift or a discount. When you register a free install from the app, we also keep that computer's name.
Licences and computers. When you activate a licence or add a computer to a team, the app sends our server that computer's name, its operating system, the app version, and a public key the app creates for that computer, from which we work out a fingerprint. The app checks your licence with our server, and we record when each computer last checked in.
Purchases. Payments are handled by Razorpay, and we do not receive your full card number or its security code. Razorpay tells us whether a payment went through. We keep the payment and order references, what you bought, the amount, the currency and the date, and for a card payment we may keep the card network and its last four digits. We do not store a country with your order, but some prices are only sold in some countries, so the amount you paid can show that you bought from one of them.
Founding Supporters. If you bought a place on the Founders' Wall, the name you gave, the date and the Razorpay payment reference are published on munderdiffl.in, on the wall page and in the public data file behind it. To give supporters their price and gifts, we keep their email addresses, in some places only as a one way hash.
Teams. If you use Teams, we keep your team's name, seats and billing status, and for each member their name, their email address if given, their role and permissions, the name they give their orchestrator, the computers they add, and a log of changes made in the console showing who made each one. Messages and requests between your team's machines pass through our server encrypted with keys that stay on those machines, and we do not hold the keys to read them. We can see which machines exchange them, when, and whether they belong to the same conversation, and for a request, what kind of request it is. Messages and requests held on our server are deleted automatically after they expire.
5. Usage events
From the app. The app sends usage events to PostHog, our analytics provider, so we can see how it is used and improve it. This is on by default. Each event carries the app version, the operating system, the processor type, and a random id the app creates the first time it runs. That id is not your account, and PostHog is told not to create a profile of you. The events, and the details each one carries, are:
- the first run, each launch, and an update being applied (the old and new version, and how it was installed);
- setup being finished (the agent engine you chose);
- an agent being requested, started, failing to start, or ending (the engine; for a failure, a reason from a fixed list; for an end, a reason and a time range);
- an agent engine install starting and finishing (the engine, the install method, and whether it worked);
- a message you send to an agent (where in the app you sent it from, never what it says);
- a feature being used (which one, from a fixed list);
- the app closing (a time range); and
- for paid plans, the upgrade screen being shown, checkout being opened or finished, a licence being activated, access being blocked, or a team invite being used (fixed values such as the plan, what opened the screen, the period, a seat range, the result, the reason, how the licence was activated, or the role).
These events do not contain your prompts, your messages, your code or your files.
From our websites. munderdiffl.in and harnessmd.com also send events to PostHog: page views, and a few actions, such as a download link being clicked, the Founding Supporters page being opened or its button being used, a card form being opened, or a payment we could not confirm straight away. Autocapture, session recording and person profiles are off, so PostHog does not record every click, your keystrokes, what you type into forms, or recordings of your screen. On harnessmd.com, sign in tokens and invite codes are removed from web addresses before they are sent. PostHog keeps a random identifier in a cookie and in your browser's local storage. If your browser sends a Do Not Track signal, these websites do not record your visit.
From our server. Our server also sends PostHog events about billing, such as a subscription starting or being charged, marked with the id of the licence or team they belong to and, for a subscription charge, the amount. It also reports errors on harnessmd.com pages, marked with the page's route rather than with you.
Your IP address. When the app, one of our websites or our server sends PostHog an event, PostHog records the IP address the event arrived from and stores it with the event.
Location lookup is turned off for events from the app, from most pages of munderdiffl.in, from harnessmd.com and from our server. For events where it is not turned off, PostHog may work out an approximate location, such as a country or a city.
Turning it off. To stop the app sending usage events, turn off Anonymous usage stats in the app's settings or during setup, or set the DO_NOT_TRACK environment variable, for example to 1. Deleting the app's data also deletes its random id.
6. Our server and your IP address
Our server at harnessmd.com receives your IP address with each request, as every web server does. We use it to answer the request, to protect the services from abuse, for example by limiting how often some requests can be made, and to choose which price to show you (section 7). We do not store it with your account, licence, team or orders. Our hosting may keep technical logs for security and to fix problems.
The app checks for updates and downloads them from our server at app.harnessmd.com. Downloads from the main page of munderdiffl.in also come from our server.
7. Regional prices
When you look at prices on munderdiffl.in or harnessmd.com, or buy on harnessmd.com, our server works out which country your IP address belongs to, using a database file held on that server, without asking any other company. It uses the country only to choose the price. The price lookup does not save the country or your IP address, and no country is stored with an order. Because it follows where your connection appears to be, a VPN can change the result. Country data from nro.net, under CC BY 4.0.
8. Emails
When you create an account, we add your email address, and your first and last name if you gave them, to our mailing list at Loops, which sends our emails. We use it to send you emails about your account and your purchases, and product news and offers. By creating an account, you agree to receive these emails. We may also tell Loops facts about your account, such as that you bought Pro, have not activated it yet, that a payment did not go through, or that it is about to end, so that the right email reaches you. You can unsubscribe using the link in these emails, or by writing to support@harnessmd.com. Clerk may also email you what you need to sign in.
9. Who else handles your information
- Clerk runs sign in and accounts. It receives your email address, your name if you give it, your sign in details, and your IP address and browser details when you sign in.
- Razorpay takes payments on harnessmd.com and for the Founders' Wall. It receives the payment details you enter, and your IP address when its checkout loads.
- PostHog receives the usage events described in section 5. It is hosted in the United States.
- Loops receives your email address, your name if you gave it, and the facts about your account described in section 8. Until 22 September 2026 this was Mailchimp.
- GitHub hosts munderdiffl.in and our public source code, and serves some downloads. The app fetches some public files from GitHub, such as its list of AI models, and the main page of munderdiffl.in asks GitHub for its star count. GitHub receives your IP address when that happens.
- Google Fonts serves the typefaces on most pages of munderdiffl.in, so Google receives your IP address when those pages load.
- Product Hunt serves the badge on the main page of munderdiffl.in, so it receives your IP address when that page loads.
- YouTube plays videos in blog posts from youtube-nocookie.com, and only after you press play.
- Our own server at harnessmd.com holds the information described in section 4, runs the price lookup, and serves the app's updates.
Each of these companies handles your information under its own privacy policy.
We may also share your information where the law requires it, to answer a lawful request, or to protect our rights, our users or the services. If the services are sold or transferred, your information may move with them, and it stays covered by this policy.
10. Services you connect
The app works with services you choose and connect yourself: the AI providers whose agents you run, such as Anthropic, OpenAI, xAI, Google and Moonshot, any local model server, voice and other providers you give a key to, and Slack, webhooks and other integrations. Your data goes from your computer to those providers under their own terms and policies, not through us. Read their policies before you send them anything sensitive.
11. Why we use your information
We use it to provide the services, to create and secure your account, to take payments and deliver what you bought, to run Teams, to choose prices, to send you emails, to understand and improve the product, to prevent fraud and abuse, and to meet our legal obligations. Where the law asks for a legal basis, ours are: performing our contract with you, our legitimate interests in running, securing and improving the services, your consent where we ask for it, and complying with the law. Where we rely on consent, you can withdraw it at any time, and that does not affect anything done before.
12. How long we keep it
We keep information for as long as we need it for the purposes in this policy, or longer where the law requires or allows it, for example for tax, accounting or disputes. Some records expire on their own, such as sign in codes and Teams messages held on our server. The companies in section 9 keep information under their own retention rules.
13. Where it is processed
We and the companies in section 9 may store and process your information outside the country where you live, including in India and the United States.
14. Security
We take reasonable steps to protect your information, such as storing license keys encrypted and relaying Teams messages only in encrypted form. No system is perfectly secure, and we cannot guarantee the security of information sent over the internet.
15. Your rights
Depending on where you live, the law may give you rights over your personal data, such as to access it, correct it, delete it, receive a copy of it, or object to or limit how it is used. To use any right the law gives you, write to support@harnessmd.com. We may need to confirm who you are before we act, and some rights have limits, for example where we must keep records by law. App usage events are tied to a random id rather than to your account, so we may not be able to find the ones that came from your computer. If you are not satisfied with our answer, you may be able to complain to the data protection authority where you live.
16. Children
The services are not for children. You must be at least 18, or the age of majority where you live if that is higher, to create an account or buy anything. We do not knowingly collect personal data from children. If we learn that we have, we will delete it unless the law requires us to keep it.
17. Changes to this policy
We may change this policy by posting a new version on munderdiffl.in and harnessmd.com with a new effective date. The new version applies from that date.
18. Contact
Questions or requests about your information: support@harnessmd.com. Security reports have their own route, described in SECURITY.md in our GitHub repository.
See also the Terms of Service.