Home/Privacy

Privacy policy.

AITerm has no account system, and nothing it measures is tied to a person. This page is the full inventory: every call the app makes, every field the site stores, every company that sees any of it.

Last updated: 3 August 2026 Applies to: aiterm.app and AITerm for macOS

The short version

Your source code, your prompts, your agent output, your file paths and your terminal content never leave your Mac. AITerm has no telemetry on any of it.

The app makes four kinds of outbound call: licence checks, the update feed, one anonymous daily ping, and the public feeds behind Radar when you open that panel. The website stores your email only if you type it into a form.

The site does count visits, without a cookie and without an identifier that survives the day. How that works is detailed in section 5 and in the cookie notice, and it stops entirely if your browser sends Do Not Track or Global Privacy Control.

Nothing is sold, rented or shared with advertisers. There is no advertising network anywhere in this product.

1. Who is responsible

The data controller is Jordane Sanson, sole trader, Résidence La Calante, 32 B rue Jean Michelet, 33115 La Teste-de-Buch, France. Full identification is on the legal notice.

For anything on this page, including a request to delete your data, write to hello@aiterm.app. No data protection officer has been appointed: the scale of processing does not require one under article 37 of the GDPR.

2. What never leaves your Mac

This is the part that matters most, so it comes first. AITerm never transmits, and never stores on a server:

  • Your source code, your files or your file paths.
  • The prompts you write to an agent, and anything the agent writes back.
  • Terminal output, scrollback, keystrokes or screenshots.
  • Project names, repository names, branch names or commit messages.
  • Your CLAUDE.md files, your dotfiles, your MCP configuration or your API keys.
  • Your Claude or OpenAI credentials. AITerm reads the credentials already installed on your Mac by those tools and never copies them anywhere.

The Shipped weekly recap is computed locally, on your machine, from your own agent transcripts and your local git history. It reaches the network only if you press the export button yourself, and then it goes to whichever app you choose to share it with.

The Quotas panel calls api.anthropic.com directly from your Mac, using the credentials Claude Code already stored there. The response is displayed and discarded. Our servers are not in that path and never see it.

3. What the app sends

Five outbound calls exist in the whole application. Here they are, exhaustively.

CallWhenWhat is sent
Trial anchor First launch, then while the trial runs A machine fingerprint: the SHA-256 hash of your Mac's hardware identifier, salted. The server records the date your trial started and returns a signed copy so the countdown cannot be reset by changing your clock. The hash cannot be reversed into a serial number and is not tied to any name or email.
Daily ping Once per calendar day, when the app becomes active The same machine fingerprint, plus usage counters accumulated since the last ping: the app version, your macOS major version, your Mac's chip family and core count, your system locale, whether you are on trial or licensed, how many sessions you started per agent type and how long they ran, how many minutes the app spent in the foreground, how many times you launched it, how many times each panel was opened (Radar, quotas, Shipped, servers, settings and the rest), how many projects you track, the highest number of panes and sessions you have had open at once, and the agent hours already shown on your Shipped page. No project names, no file paths, no commands, no session content, no name, no email.
Licence check and activation When you paste a key, and periodically to confirm the subscription is live Your licence key, the machine fingerprint and an activation identifier. Used to enforce one active Mac per subscription and to read or cancel the subscription from the app.
Update feed Automatic update check A plain request for aiterm.app/appcast.xml. As with any file download, the server log records your IP address and the app version in the user agent.
Radar and model catalogue Only when you open the Radar panel or the agent configuration screen Requests to public feeds: the GitHub search API, the Hacker News search API, YouTube RSS feeds and thumbnails, models.dev, and the skills hub through our relay. These are read-only public feeds. Each host sees your IP address, as it would in a browser. No account, no identifier and no search history is attached.

The daily ping exists so a solo developer can tell how many people actually use the app, how much they use it, which parts they use, on which Macs, and whether a release broke something. It is counters only: nothing about what you build, and nothing that could reconstruct your work. It is not personalised, not resold, and not connected to any advertising or analytics platform.

You can switch it off in Settings, under Privacy, and nothing further is sent. To also delete what was already recorded, write to hello@aiterm.app with your licence key and the fingerprint and its counters are removed. See section 10.

4. What the website collects

Browsing aiterm.app is counted, but never attached to you: no cookie, no identifier, nothing stored in your browser. A visit becomes one anonymous hash that is impossible to reverse and is unlinkable from one day to the next, and what we keep is a table of counts. There is no tag manager, no advertising pixel and no advertising cookie. The mechanism is described step by step in the cookie notice, and Do Not Track switches it off entirely. Personal data appears only when you type it into a form.

Form or eventDataWhy
Contact form Name, email, subject category, message, the page you were on, your IP address, timestamp To answer you. The message is stored in private storage and emailed to us. The IP is kept to deal with abuse.
Blog newsletter Email, the article you subscribed from, timestamp To tell you when a new article goes out. You can unsubscribe by replying to any email or writing to us.
Download link by email Email Used once to send you the download link, then not stored on our side. You are not added to any mailing list.
Checkout Handled entirely by Stripe: email, billing details, payment method Card data never touches our servers. From Stripe we receive and store your email, the Stripe customer and subscription identifiers, and the licence key issued to you.
Server logs IP address, requested URL, user agent, timestamp Recorded by our host for security, rate limiting and debugging. Rate limiting also holds IP addresses in memory for one minute.
Web fonts IP address, browser and OS, sent to Google The site loads its typefaces from Google Fonts, so your browser contacts Google servers when a page renders. Nothing else is shared with Google.

Cookies and local storage are covered separately in the cookie notice. Short version: the site sets no cookie on visitors at all.

5. How we count visits

Knowing how many people read a page, and which pages are worth writing, does not require knowing who you are. So we do it without an identifier.

Your IP address and user agent are mixed with a random number drawn fresh every night, and only the resulting hash is kept. That hash counts as one visitor for the day. It cannot be turned back into an IP address, and once the night's number is discarded nothing links it to the following day. Your browser sends one message when you leave a page: the path, how long the tab was in front of you, the referring site and whether you clicked a download or subscribe button. It carries no identifier, because none exists.

What is stored is a table of counts: visits per day, most read pages, referring sites, countries, average time on page. It is never used to build a profile, never attached to a customer record, and never shared with an advertiser or a data broker. Vercel Web Analytics runs alongside it on the same principle, served from this domain, storing nothing in your browser.

Legally this is audience measurement strictly limited to statistics, which is why it needs no consent banner. If you would rather not be counted, Do Not Track and Global Privacy Control are both honoured, and any content blocker works too. Full detail is in the cookie notice.

6. Who processes your data

Five companies are involved, each for one job. None of them is allowed to use your data for their own purposes.

ProcessorJobLocation
VercelHosting the site, the API endpoints, the private storage holding licences, contact messages, trial anchors and visit counts, plus the cookieless Web Analytics scriptUnited States, with EU regions in use
StripePayments and merchant of record: checkout, tax, invoices, subscription managementIreland and United States
ResendSending transactional email: licence keys, download links, contact notificationsUnited States
Google FontsDelivering the typefaces used on this siteUnited States
skills.shPublic skills directory read through our relay when you open RadarUnited States

The public feeds behind Radar (GitHub, Hacker News, YouTube, models.dev) are contacted directly by your Mac. They are not our processors: they see the same thing a browser visit would show them.

7. Legal bases

  • Performance of a contract: the trial anchor, licence activation and subscription management. Without them the software cannot enforce the trial or the licence you bought.
  • Legitimate interest: the anonymous daily ping, the visit counts described in section 5, server logs, rate limiting and answering your contact message. Our interest is knowing whether the product works and keeping it available. The data used is minimal and cannot identify you by name. Audience measurement here stays within the scope that French rules exempt from consent, and it is switched off for browsers sending Do Not Track or Global Privacy Control.
  • Consent: the blog newsletter and the download link by email. You gave it by submitting the form and you can withdraw it at any time.
  • Legal obligation: accounting records tied to your purchase, held by Stripe as seller.

8. How long we keep it

DataRetention
Trial anchor (machine hash and start date)24 months after the trial ends
Daily pings and device counters13 months, then deleted
Licence record (key, email, Stripe identifiers)For as long as the subscription is active, then 3 years
Contact messages3 years after the last exchange
Newsletter subscriptionUntil you unsubscribe
Invoices and accounting records10 years, held by Stripe as merchant of record, as French law requires
The nightly random number used to hash visitorsA new one every night, each deleted after 7 days. Keeping them any longer would undo the anonymity the counting relies on
Visit counts (page, duration, referrer, country)13 months, then deleted
Server logsAs set by our host, in the order of 30 days

9. Transfers outside the EU

Vercel, Stripe, Resend and Google are established in the United States, so some data is processed there. Those transfers rely on the European Commission's Standard Contractual Clauses, and on the EU-US Data Privacy Framework where the company is certified under it.

The data concerned is small and known: an email address, a licence key, a salted machine hash, an IP address in a log. No source code and no project content is ever part of it.

10. Your rights

Under the GDPR you can ask for access to your data, correction, erasure, restriction, portability, and you can object to processing based on legitimate interest. You can also set instructions for what happens to your data after your death.

Write to hello@aiterm.app. Requests are answered within one month. Two practical notes:

  • To delete a licence record we may need the licence key or the email used at checkout, because that is the only identifier attached to it.
  • The machine fingerprint is a one-way hash, so we cannot find your device from your name. Send the request from the app or include the licence key.

If you think your rights are not respected, you can lodge a complaint with the CNIL: 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, cnil.fr. You can also complain to the supervisory authority of the EU country where you live.

11. Security

Everything travels over HTTPS. Stored records sit in private object storage that is not publicly readable. Licence keys are stored under a hash of the key rather than in the clear. The trial payload is cryptographically signed so it cannot be forged locally. Card data is never handled by our code.

No system is perfect. If you find a vulnerability, email hello@aiterm.app before disclosing it publicly and you will get an answer.

12. Children

AITerm is a professional development tool and is not directed at children. We do not knowingly collect data from anyone under 15.

13. Changes

If this policy changes in a way that affects you, the date at the top changes and the change is described in the release notes. Adding a new outbound call to the app would be a material change and would be announced, not slipped in.