Privacy Policy
Last updated: 16 August 2026
PapAgent is a local-first Mac app. Your projects, code, prompts, agent logs and AI output stay on your computer. This page lists every case where data does leave your machine, and why.
What stays on your Mac
Project files, git worktrees, agent conversations, terminal output, local configuration, API keys and CLI credentials are stored on your computer only. We have no way to read them.
What leaves your Mac
- A machine identifier, when you start a trial or activate a license. The app sends a SHA-256 hash of your Mac's hardware UUID to papagent.com. We store that hash so a trial cannot be restarted indefinitely on the same machine, and so a license key activates on one Mac at a time. The hash cannot be reversed into your hardware UUID, and it is not linked to your name or email unless you buy a license.
- Your email address, when you buy a license. Stripe collects it at checkout. We store it so we can email you your license key and so you can retrieve that key later by signing in with the same address.
- App version and platform, when checking for updates. The updater asks papagent.com whether a newer build exists, which reveals your current version, platform and CPU architecture, plus the IP address the request comes from. This happens whether or not you are licensed.
- An anonymous counter, when you download the app. We increment a single total. No per-download record is kept.
What we do not do
The app contains no analytics or telemetry SDK. We do not track feature usage, record sessions, or send your prompts, code or file paths anywhere. We do not sell or share personal data, and we do not run advertising.
Website measurement
The public website uses first-party, cookie-free aggregate measurement to understand which broad sources lead to page views, downloads, checkout starts and completed purchases. The analytics dataset receives only the event type, public page path, broad source category (such as Google, ChatGPT or direct), broad channel, and landing page. We do not write IP addresses, full referrer URLs, URL query strings, email addresses, license or payment identifiers, user-agent strings, or a persistent visitor ID to the analytics dataset.
Broad attribution is kept in your browser's session storage only for the life of the current tab so a download or purchase can be attributed to its landing source. There are no analytics cookies, cross-site tracking, advertising profiles or session replay. Aggregate events are processed using Cloudflare Workers Analytics Engine.
Payments
Payments are processed by Stripe. Card details go directly to Stripe and never reach our servers. We receive only your email address, the amount, and an identifier for the purchase.
Optional account
Buying does not require an account. If you choose to sign in at billing.longames.com to view your purchases, identity is handled by Clerk. We link a purchase to that account only when the email address on the account has been verified and matches the address used at checkout.
Services you connect yourself
If you use AI backends (Claude, Codex, Gemini, Cursor, Copilot and others), or enable optional integrations such as Telegram or a tunnel, those services receive whatever you send them under their own terms and privacy policies. PapAgent does not proxy that traffic through us.
Retention and deletion
Trial records, activation records, purchase records and license keys are kept while the license is valid, and afterwards for as long as needed for tax and accounting purposes. To request deletion of your email address and purchase record, email hello@papagent.com. Note that deleting a purchase record also removes our ability to re-issue your license key.
To remove local data, delete the app's data directory and uninstall the app.
Contact
Questions about this policy: hello@papagent.com.
Operator: PapAgent, an independent software project based in British
Columbia, Canada.
Contact: hello@papagent.com — we reply to every
message, and can provide our full registered details on request.