Skip to content

Privacy and security

Astramar is designed around a local-first phrase library on your Mac. Optional networked AI, retrievers, Team services, analytics, and similar capabilities have separate enablement and data-flow boundaries — they are not required for Free Beta phrase expansion.

Authoritative detail lives in the published privacy and security policies. This page is the customer summary for Free Beta docs.

  • Phrase content lives in Application Support under the PhrasePilot technical identity.
  • The library file is ordinary JSON protected by your macOS account, filesystem permissions, and any disk encryption you enable (for example FileVault). Astramar does not encrypt the library file itself.
  • Rolling recovery backups and quarantine copies help with fail-closed recovery. Prefer in-app export over hand-editing files (Library backups).
  • Accessibility enables intentional paste / direct insert into other apps. Without it, clipboard-only workflows remain available.
  • Accessibility may also expose limited UI context (focused app, selection) for features that need it. Deny or revoke access anytime; doing so must not erase your library.
  • Clipboard history shown in the palette (when enabled) stays in memory for the session and is not written into the library file.
  • Personal Insights (Settings → General) stay on this Mac: expansions, palette opens, and phrases created for 7 days / 30 days / all time. They never leave the device and do not require Product Analytics.
  • Product Analytics is opt-in and off by default. Local collection keeps allowlisted counters on-device. Transmission needs a separate notice and opt-in plus a configured first-party ingest path; without an ingest bearer, outbound stays fail-closed.
  • Routine product analytics must not include phrase or clipboard content.

Full customer walkthrough: Personal Insights and Product Analytics.

  • Export Diagnostic Summary… is metadata-only and reviewable before sharing.
  • Credentials and service tokens belong in macOS Keychain, not in library exports or public issues.

Near-term public distribution is a verified Developer ID direct download when the website release record promotes an exact package. Public website downloads stay disabled until that record authorizes them (Release status).