Privacy
What this site and this tool know about you, and what they do not.
Effective 20 August 2026 · Foxxception LLC
halligan.dev is a handful of static files. It sets no cookies, runs no analytics, loads nothing from a third party, and has no forms, no accounts and no payments. The Halligan command-line tool has no telemetry of any kind — it never calls home, and your API keys and transcripts never touch our infrastructure because there is no infrastructure for them to touch.
The one thing we will not claim: our host, Cloudflare, has to process your IP address to serve you a page at all. Section 3 says what that means.
- 1. Who we are
- 2. The website
- 3. Hosting and server logs
- 4. The Halligan tool
- 5. Model providers
- 6. Third-party services
- 7. If you email us
- 8. Your rights
- 9. Children
- 10. Changes
- 11. Contact
1. Who we are
Halligan is published by Foxxception LLC (“we”, “us”), a Florida limited liability company, which is the data controller for this website. This policy covers the website at halligan.dev and the Halligan software distributed on PyPI and GitHub.
2. The website
Every page on this site is a static file. Nothing on it profiles you, and that was a design decision rather than something we can quietly reverse without the commit showing. Specifically, this site does not:
- set cookies, or write to local storage or session storage;
- run analytics, tag managers, session recording or advertising pixels;
- load fonts, scripts, stylesheets or images from any other domain — the typefaces are the ones already on your device;
- contain a single form field, login, cart or payment flow;
- fingerprint your browser, or build a profile of you across visits.
The only JavaScript we ship is a copy-to-clipboard button on the landing page, which writes an install command to your clipboard and sends nothing anywhere.
3. Hosting and server logs
The site is served by Cloudflare, which acts as our hosting provider and processor. To deliver a page at all, and to protect the site from attack and abuse, Cloudflare processes standard request metadata: your IP address, the page requested, your user agent string, approximate location derived from that IP, and the time of the request.
We do not use that data to identify you, we do not combine it with anything else, and we do not sell or share it. Our lawful basis, where the UK or EU GDPR applies, is our legitimate interest in keeping the site available and secure. Cloudflare's own handling is governed by its privacy policy, and it retains these logs on its own short schedule.
4. The Halligan tool
Halligan is a command-line program that runs entirely on your own machine or in your own CI. It contains no telemetry, no usage reporting, no crash reporting, no update check and no licence check. We receive nothing when you install it, run it, or fail a build with it — we have no way of knowing you use it at all unless you tell us.
Your API keys are read from the environment only, are never accepted as a command-line argument, and are never written to disk by Halligan. Run artifacts and HTML reports are written to the path you choose, on your own disk, and pass through a redaction filter that masks known credential formats first.
A report can still contain the conversation text of a run, which is by design — you cannot review a guardrail failure you cannot read. That text is adversarial by nature and may be sensitive. Reports are yours to keep or destroy; read one before you share it. The security page covers credential handling in detail.
5. Model providers
When you point Halligan at a model, it sends your probe prompts directly from your machine to whichever endpoint you configured — Anthropic, OpenAI, Google, a local Ollama or LM Studio instance, or your own HTTP target. That traffic goes to that provider, not through us.
What the provider then does with those prompts is between you and them, under their terms and their privacy policy, and it is worth reading before you run a suite that carries your own production system prompt. A model running locally sends nothing off your machine at all.
6. Third-party services
This site links out to GitHub, PyPI, GitHub Sponsors and Ko-fi. We embed nothing from them, so they learn nothing about you until you actually follow a link — at which point you are on their site under their policy. Installing Halligan from PyPI, or cloning it from GitHub, is a request to those services and is visible to them, not to us.
7. If you email us
If you write to us, we hold your message and your address for as long as it takes to deal with it and to keep a record of the correspondence. We use it to reply, and for nothing else — no mailing list, no marketing, no sharing.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, export or object to the processing of your personal data, including under the GDPR and the Florida Digital Bill of Rights.
We will honour any such request we are able to honour. In practice we hold almost nothing: apart from email you have sent us, the only data that exists is transient hosting metadata that is not tied to your identity and that we cannot search for “you” within. We have never sold or shared personal information, and we do not process it for targeted advertising or profiling. To make a request — or to complain to a supervisory authority, if we have not resolved it — start at the contact address below.
9. Children
Halligan is a developer tool and is not directed at children. We do not knowingly collect personal information from anyone under 13.
10. Changes
If this policy changes, the effective date at the top changes with it, and the edit is visible in the public commit history of this page — including what the previous wording was. Material changes will be called out in the project release notes.
11. Contact
Privacy questions and data requests:
support@foxxception.com
Legal notices: legal@foxxception.com
Foxxception LLC, Florida, United States
Found a vulnerability instead? Please use private disclosure rather than email.