Privacy Policy
Pixel Pane is a local-first assistant for your Mac. This policy describes what the app can access, what leaves your computer, and the choices you control. The short version: your questions, files, answers, terminal content, and local paths are never included in analytics or automatic crash reports. They leave your Mac only when you connect your own AI provider or deliberately write something into a support report. Pixel Pane operates no model proxy or account service of its own.
What Pixel Pane can access on your Mac
- Nothing on your screen. Pixel Pane is text-only: it has no screen capture, takes no screenshots, and holds no Screen Recording permission. It cannot see your display at all.
- Files and folders — only the folders you explicitly grant. Every file the assistant reads is recorded in the run trace you can inspect. The assistant cannot change a file without showing you an approval card first.
- System snapshots — bounded, read-only lists of running processes and local listening ports, used to answer questions you ask about them.
- Now playing — the title and artwork of media already playing on your Mac, to draw the pill in the notch. This stays in the app's own window; it is never added to a question or sent to any model.
- Terminal sessions — the built-in terminal runs commands as you, on your Mac. Pixel Pane does not transmit what you type or what scrolls past. Any tool you choose to run in there does whatever it does on its own terms, not under this policy.
- Chat history — stored only on your Mac, in the app's Application Support folder. You can review or delete any chat in Settings → History.
Local Mode (the default)
In Local Mode, everything — your questions, file contents, and answers — is processed on your Mac using models you install. Pixel Pane makes no network requests for AI processing in Local Mode.
Housekeeping connections can still happen in any mode: update and license checks, plus the independently controlled anonymous analytics and fatal-crash reporting described below. None carries your questions, answers, or local content. Installing an on-device model is a download, so it needs the network too.
OpenRouter (explicit opt-in)
Pixel Pane can route requests through your own OpenRouter account. Signing in opens openrouter.ai in your browser; Pixel Pane never sees your password. What it receives back is an API key scoped to your account, stored in the macOS Keychain. Requests are billed to your OpenRouter credits — Pixel Pane operates no server, takes no cut, and holds no account of its own.
When this route is on, the following is sent to OpenRouter (and on to whichever model provider ends up serving the request) to generate the answer:
- your question and the visible conversation in that chat;
- local context the assistant gathers for the request — such as text it reads from your granted files, the names of your granted folders, and the current date/time;
- your approximate, city-level location — only if you have separately granted macOS Location access and enabled location sharing in Settings (two explicit switches; never precise coordinates).
Pixel Pane sends two attribution headers with each request identifying the app (not you). Your data handling at OpenRouter and at the underlying model provider is governed by your agreement with them.
Custom Provider (explicit opt-in)
Pixel Pane can also route to your own OpenAI or Anthropic account with an API key you supply. The key is stored in the macOS Keychain, is never written to preferences or logs, and is sent only to that provider. The same context listed above applies.
Even on a remote route, local tools stay local: file reads happen under the grants you gave, file writes and terminal commands still require your approval, and they execute only on your Mac.
Anonymous analytics and fatal crash reports
Before either service can start, Pixel Pane shows a one-time privacy disclosure. The two Settings → Permissions controls are independent, take effect immediately, and default on:
-
Share anonymous usage analytics. Pixel Pane uses
TelemetryDeck
to count anonymous active installations, sessions, onboarding
completion, and coarse feature use. The only app-defined events are
onboarding completed, support report opened, and agent run
started/finished. Run properties are limited to route class
(
local,openrouter, orcustom), run mode, and a coarse outcome such as completed, blocked, failed, canceled, or interrupted. Pixel Pane supplies no email, account, license, model, or custom user ID. TelemetryDeck creates its own anonymous installation identifier and adds SDK, app version/build, operating-system and device category, architecture, language/locale/region, time-zone, display/orientation, distribution/debug state, and session/retention metadata. These categories are used only for aggregate product analytics. - Send automatic crash reports. Pixel Pane uses Sentry only for fatal app crashes. The report is reduced before transmission to crash type and mechanism, sanitized symbol/stack addresses, timestamp, app version/build, macOS version, CPU architecture, release, distribution, and environment. Sentry's PII collection, user identity, breadcrumbs, logs, network tracking, tracing, profiling, replay, screenshots, view hierarchy, attachments, sessions/release health, hangs, metrics, and nonfatal automatic events are disabled. The Sentry project is configured to suppress stored IP addresses and apply server-side scrubbing as a second layer.
Neither service receives prompts, answers, chat transcripts, screenshots, OCR, clipboard data, files or paths, terminal content, tool input/output, provider URLs, model identifiers, API keys, error messages, precise location, licenses, or Pixel Pane run/session UUIDs. Network providers necessarily receive a connection from your IP address, but Pixel Pane does not attach the address as an analytics or crash field and Sentry is configured not to retain it.
Turning a control off stops new collection immediately; it cannot retract data already received. Pixel Pane's TelemetryDeck plan exposes up to three months of live analytics, while TelemetryDeck states that older unloaded data can remain in vendor cold storage under its service terms. Sentry crash and feedback events are configured for no more than 90 days. Earlier deletion may be requested through the contact below, subject to the anonymous nature of analytics data and vendor deletion capabilities.
Private support reports
The first-party form at pixelpane.app/support.html submits through a separate private Sentry Feedback project. Merely opening the page sends no report. The page does not enable automatic website error collection, replay, tracing, cookies, attachments, or user context; transmission happens only after you press Send private report.
The form sends the category and text you enter, plus an email only if
you choose to provide one. When opened from the app, it can prefill app
version/build, macOS version, CPU architecture, coarse route class, and
source=app. Those diagnostics are visible, editable, and
removable before submission. The app does not prefill screenshots,
attachments, chats, files, paths, logs, model identifiers, provider
details, keys, or licenses. If you put sensitive content into a text
field yourself, it becomes part of the report you chose to send.
Trial, purchase, and license checks
Pixel Pane is paid software with a free trial. The trial clock is a single timestamp written to the app's preferences on first launch — nothing is sent anywhere to start or track it.
Purchases are handled by Polar, which is the merchant of record for Pixel Pane. Checkout happens on Polar's own pages in your browser: they collect the email, payment, and tax details needed to sell you a license and to send your key, under their privacy policy. Pixel Pane never sees your payment details and keeps no customer records.
License keys are checked directly against Polar's customer-portal API
(api.polar.sh) from your Mac. Three moments touch the
network:
- Activation, once, when you paste a key: Pixel Pane sends the key, Pixel Pane's public organization id, and a label for this Mac — your computer's name as macOS reports it, so you can tell your activations apart in Polar's portal. If you named your Mac after yourself, that name contains your name.
- Revalidation, on launch: the key and the activation id, nothing else. A failed or offline check never revokes your access; only a definitive rejection does.
- Removal, when you remove a license: the activation slot is released with Polar so the key can be used on another Mac.
The key and activation id are stored in the macOS Keychain. No content from your chats, files, or terminal is ever part of a license request.
Software updates
Release builds check for updates automatically (using Sparkle) by fetching a signed appcast from GitHub, and Settings offers a manual check. GitHub sees what any web server sees when you visit it — your IP address and the request itself. Pixel Pane sends no identifier, no system profile, and nothing about your usage with the check.
Downloading on-device models
Apple's built-in model needs no download. Choosing any other local model
downloads its weights from Hugging Face into the
standard ~/.cache/huggingface folder; Hugging Face sees the
download request and your IP address. The optional MLX runtime setup runs
python3 -m pip install on your Mac, which fetches those
packages from PyPI. Both are downloads of public software — nothing about
you or your chats is sent.
What Pixel Pane does not do
- No account with us and no identified-person analytics profile.
- No advertising, cross-site tracking, or analytics on the website.
- No screen capture or screenshots at all.
- No background screen or file monitoring.
- No Pixel Pane model proxy or content backend.
- No selling of data, advertising profiles, or use of your content to train models.
- Your questions, files, answers, and terminal content never enter analytics or automatic crash reports.
Your controls
- Switch between Local, OpenRouter, and your own provider key at any time in Settings → AI.
- Add or remove folder grants at any time in Settings → Files.
- Revoke Location access in System Settings, or turn off location sharing in Settings.
- Sign out of OpenRouter, or remove any stored API key, at any time in Settings.
- Revoke Pixel Pane's key from your OpenRouter account at openrouter.ai.
- Turn anonymous usage analytics or automatic fatal-crash reports off independently at any time in Settings → Permissions.
- Review, edit, remove, or simply do not send the diagnostics on a support report.
- Remove your license in Settings → License, which releases this Mac's activation slot; manage or delete your customer data with Polar directly.
- Delete any or all chat history in Settings → History.
Contact
Questions about this policy: snehithn5@gmail.com
Changes
Last updated August 12, 2026. We will update this document when data practices change.