The short version
- Ruru has no account system or cloud sync for your work.
- Your history, preferences, and credentials are stored on your Mac.
- Prompts and context leave your Mac only when you send them to a model, CLI agent, or connector you choose.
- License validation, software updates, optional diagnostics, and support use the limited data described below.
- We do not sell your data or use it for advertising.
Data stored on your Mac
- History: prompts and interaction history are stored in
~/Library/Application Support/Ruru. - Credentials: API keys and connector tokens are stored in the macOS Keychain.
- Preferences: hotkeys, appearance, and agent settings are stored in local macOS preferences.
- Attachments and OCR: attachments and screen captures are held in memory or local temporary storage while Ruru prepares a request. Apple Vision OCR runs locally. If you include an image or extracted text in a prompt, it is then sent to the provider, agent, or connector you selected.
Agents, models, and connectors
When you choose a local CLI agent, Ruru launches the executable on your Mac through your login shell and passes it the prompt and context you selected. The process runs with your user permissions and may be able to access files, environment variables, credentials, and network services available to your account. Ruru does not control how that executable or its provider handles data.
When you use a hosted model with your own API key, Ruru sends your request directly from your Mac to that provider. When you invoke a connector, Ruru communicates directly with the external platform. Ruru does not proxy this content through an Atcharm server.
Those services have their own privacy, retention, and training terms. Review them before sending confidential, personal, or regulated data. Ruru-managed connector actions that change remote data ask for your confirmation; actions performed independently by a CLI agent or custom script are outside that confirmation flow.
macOS permissions
Ruru requests permissions only when a feature needs them:
- Accessibility is used to identify the focused app, read selected text when you invoke an action, remove the
@@trigger, and insert a response. - Input Monitoring is used to detect global shortcuts and the
@@trigger. Ruru keeps only the last two trigger characters in its detection buffer and does not maintain a general keystroke history. - Screen Recording is used only when you capture a window or screen, including for local OCR. Ruru does not continuously record your screen.
Licensing and purchases
Polar is our Merchant of Record and processes checkout, payment, tax, receipts, purchase records, and license-key delivery. Polar acts as the data controller for that transaction under its privacy policy. Atcharm does not receive your card or bank details.
To activate, validate, or deactivate Ruru, your Mac sends Polar the license key, a randomized device identifier, a device label, and ordinary network metadata such as an IP address and request headers. This is used to manage the two-Mac activation limit, prevent abuse, and maintain purchase access. Polar determines its own retention periods under its policy.
Software updates
Ruru uses Sparkle to check a signed appcast and download releases from GitHub. Update requests may include ordinary network metadata, the installed Ruru version, and your macOS version. They do not intentionally include prompts, files, screenshots, API keys, or license keys. GitHub handles request data under its own privacy policy.
Diagnostics
Ruru may send minimal diagnostic and usage events to help us find bugs and understand app stability. These can include fixed event names, error codes, app version, and macOS version. Our diagnostic events are designed not to include prompts, completions, code, selected text, file paths, OCR output, window titles, screenshots, credentials, or license keys.
You can disable diagnostic reporting at any time in Settings → General → Privacy without losing app features. We retain diagnostic data only while it is reasonably needed for debugging and product measurement, then delete or aggregate it.
Website and support
Our website hosting provider may process ordinary request metadata, such as IP address, user agent, requested page, and time, to deliver and protect the site. We do not use this data for advertising or cross-site tracking.
If you email us or submit a support report, we receive the contact information and content you provide. We use it to respond, resolve problems, prevent abuse, and meet legal obligations. Do not send API keys, license keys, secrets, or confidential project content. Support records are kept while needed for those purposes and then deleted.
Your choices and deletion
You can clear Ruru history and settings in the app, remove credentials from the macOS Keychain, and remove local files from ~/Library/Application Support/Ruru. Deleting local data does not delete information already sent to Polar, GitHub, a model provider, CLI provider, connector, or support channel; contact that service to exercise rights over data it controls.
Depending on where you live, you may have rights to access, correct, delete, restrict, export, or object to our processing of personal data. Email us to make a request. We may need to verify your identity, and some records may be retained where required by law or needed to resolve fraud, security, or legal issues.
Security
We use reasonable safeguards and minimize the data Ruru sends, but no system is completely secure. Protect your Mac, backups, API keys, and license key, and review the security practices of services you connect.
Changes and contact
We may update this policy when Ruru or our data practices change. Material changes will be reflected by the “Last updated” date and, where appropriate, noted in release notes.
Questions or privacy requests can be sent to hello@atcharm.com. You can also review our terms of service.