ASL AI Hub Master Suite — privacy and data handling
Updated September 13, 2026 for the 0.4.3 integration candidate. Provider: ASL LLC. Contact: support@autosecurelogin.com.
Local application and independent profiles
Master Suite combines native diagnostic, provider-connection, resource-hosting and workflow workspaces. Opening it does not automatically connect a provider, join a fleet, scan the computer, start reporting, run work or enable cleanup. Each workspace uses Suite-owned local storage, separate from the standalone PC Steward, rBroker and AI Hub applications. Suite does not silently import their credentials. Windows protection and local access controls protect stored credentials and identities; this is not protection against every compromised administrator or an already-compromised signed-in account.
Computer diagnostics and actions
Requested scans read performance totals, process names and resource usage, drive capacity/type, Windows sessions, startup entries, scheduled tasks, services, network/share configuration, antivirus registration, supported sensor readings, local broker status and bounded Windows reliability evidence. Some information can identify a person, computer, project or organization. These diagnostic scans are processed locally and do not automatically upload their results to ASL or an advertising service.
Local health history records bounded lightweight samples; action history records requests and observed outcomes. Historical incident dates are used to explain timing, not to infer a present failure. Live sensor coverage depends on installed drivers and hardware. Thermal readings are not automatically published to a fleet by opening the diagnostic workspace. Approved cooling helpers may retain protected recovery state until restoration is verified. They do not install replacement display drivers. A report or support export is created only when requested; minimized data is not guaranteed anonymous. Review every export before sharing.
Safe Cleanup previews only the bounded approved categories. Permanent deletion requires explicit manual approval or a separately enabled in-app schedule. A schedule authorizes its later runs while the app is open; closing the app stops it. Removal does not use the Recycle Bin. Local Data explains separately retained health/action/report records; exported copies saved elsewhere are independent.
Fleet viewing, membership and reporting
When you choose a fleet server and connect, it receives normal connection metadata such as the connecting IP address. Viewer credentials authenticate read-only fleet access. Returned status can include computer names, project descriptions, lease/attempt references and resource totals. Treat these as private operational information. Leaving the simple Fleet view clears its key and snapshot references; clearing managed-memory references is not guaranteed cryptographic erasure.
Join fleet sends the chosen public computer name, generated node/key identifiers, public signing key and signed enrollment evidence to your selected coordinator. The node's private signing key is not part of that public enrollment record. Reporting is a separate explicit action. Depending on selected sharing options, signed reports include node/service state, lease/work identifiers, supplied readable work descriptions and resource/worker totals. Status reporting does not extract private AI conversations to invent task names. Do not put secrets or sensitive customer information in names that you elect to share.
Choosing a customer-operated coordinator does not forward its fleet reports to the default ASL server. The server address is configurable. Fleet operators and authorized viewers can access the information intentionally sent to that fleet. They control their deployment's access, quotas, backups and retention. Stopping reporting does not erase previously retained reports or backup copies.
Approved execution and file transfer
Fleet membership alone does not authorize execution. Explicit node permissions limit dispatchers, handlers, resources and authorization lifetime. Saved workflow plans contain readable descriptions, selected computers, resource requirements, dependencies, input references and output destinations. Protected local journals retain the original operations and receipts so unknown outcomes can be reconciled without silently creating duplicate work.
Unlike status-only reporting, an approved workflow can intentionally transmit the selected task payload, input files, intermediate results and final outputs through its coordinator to permitted nodes and back to the selected recipient. Those recipients must be trusted to process that material. Transfer encryption at rest and HTTPS do not mean the authorized executing node or server operator cannot access the data it must process. Content hashes verify integrity, not anonymity. File names, local destination references and supplied descriptions may be identifying information even when the file's contents are not displayed.
Coordinator artifact quotas and operator-configured retention bound stored transfers. Local result files and user-made exports remain where the user chose to save them. Deleting a local profile does not delete remote copies. Contact the relevant coordinator operator for retained remote records. Do not delete identity, consent, journals or transfer state while accepted work still owns it.
AI providers and the hosted AI Hub platform
Connecting supported official provider clients and pairing an AI Hub account are deliberate actions. Official provider sign-in is handled by that provider's client; Suite does not ask you to paste provider passwords into fleet fields. The configured official client/provider receives the content necessary for the approved provider task under its own account terms and data policy. The AI Hub platform receives the pairing/task/receipt information required by that selected workflow. Provider work is not the same as a local GPU lease or fleet permission.
The hosted AI Hub platform, Microsoft Store, Windows, independently installed tools, customer hosting and third-party AI providers have their own privacy notices and terms. Purchasing Suite does not change those policies, make provider usage free, or authorize disclosure of unrelated files. Consult the policy of the endpoint/account you configure before submitting personal or confidential material. Suite's desktop support export does not automatically send that material.
Optional Windows service and diagnostic records
The separately installed service companion uses a restricted Windows service account and protected machine storage, not a copied desktop private identity or a saved interactive Windows password. It can keep selected components and separately consented CPU execution active without the desktop window. Installing or closing the Store app does not automatically install, stop or remove this independent service. It must be managed and drained explicitly.
Private component logs can record process parents, start/exit information, errors and job-to-worker ownership. Such records may reveal local operational details; review them before sharing. Safe diagnostic summaries omit raw logs and secrets. Uninstalling a desktop package or removing service registration is not a promise that all private state, recovery files, user exports or server backups are erased. Use the product's exact-target data controls and the server operator's documented retention procedure. Preserve pending-work evidence before removing anything.
Support and your choices
Suite includes no advertising or third-party advertising analytics SDK. No automatic support upload is performed. Opening a support email action is not sending a message. You choose the endpoint, shared description, selected input files, participant permissions and output destination for configured work.
The content-report action opens a fixed local email draft identifying Master Suite with blank fields for your concern. It reads or attaches no task, prompt, result, identity, key, file or log. You decide what to enter and whether to send through your email provider, which has its own policy. A missing email app leaves the support address available. Do not include harmful or private media.
For ASL product or ASL-operated processing questions, email support@autosecurelogin.com or visit https://support.autosecurelogin.com. For records held on a customer-operated coordinator, contact that operator. Requests may require enough non-secret information to identify the deployment and verify authority. Never include private signing keys, bearer credentials, passwords or unreviewed customer files in a support request.