Privacy Policy

Last updated October 1, 2026

In short

  • The desktop app and command line keep your code on your computer. We never see it.
  • In the web app, stored keys are encrypted and runs are deleted 14 days after they finish.
  • We don't sell your data, and we never train AI models on your code or prompts.
  • Analytics and ad cookies load only if you accept them; Global Privacy Control is honoured.
  • Ask for a copy, a correction or deletion any time: [email protected].

1.Who we are

Macaron ("we", "us") provides macaron.sh, the Macaron web app, desktop app and command line (the "Services"). We are based in Florida, United States. For personal information we decide how to use, such as account, billing and website data, we are the "controller" under the EU and UK General Data Protection Regulation ("GDPR") and a "business" under the California Consumer Privacy Act ("CCPA").

When a business customer uses the Services to process personal data that belongs to them, such as personal data inside their code or repositories, we act as their "processor" or "service provider", and our Data Processing Addendum governs that processing.

Contact for anything in this policy: [email protected].

2.What this policy covers

This policy covers personal information we collect through the Services, our website, our emails and our support. It doesn't cover Third-Party Services you connect, such as model providers, GitHub or deployment platforms, which have their own policies. Read it together with the Terms of Service and the Cookie Policy.

3.The desktop app and command line

Our desktop app and command line run on your own computer. Your projects, chats, settings and history are stored there, and API keys you add to the desktop app are encrypted with your operating system's keychain. Prompts, code and files go directly from your computer to the AI model provider you chose, using your own account; they don't pass through our servers and we can't see them.

We receive information from these apps only when: you sign in to a Macaron account; update checks are turned on, when the app asks our update server whether a newer version exists, sharing your IP address, app version and operating system; or you choose to send us a report or feedback. The apps contain no analytics or advertising trackers.

4.Information we collect

Information you give us

  • Account information. When you sign in with GitHub or Google: your account ID, username, and, if the provider shares it, name, email address and profile picture. We never receive your GitHub or Google password.
  • Billing information. If you buy a plan: your Stripe customer ID, plan, billing status, invoices, billing country and address needed for tax. Stripe collects and stores your card details; we never see or store full card numbers.
  • Keys and connections. API keys and tokens you save for model providers and connected services, stored encrypted (see section 11).
  • Your Content in the web app. Prompts, repository addresses, run settings, agent logs, receipts and patches for runs, and the code and files placed on hosted Computers.
  • Communications. What you send us by email or through support, and related records.

Information collected automatically

  • Usage and device data. IP address, browser and operating system, pages visited, referring page, time and date, and request logs kept by our hosting provider to run and protect the Services.
  • Service records. Session records that keep you signed in, an audit log of actions on your Computers and runs, and usage records such as Computer time and credit used, for billing and security.
  • Cookies and similar technologies. Strictly necessary cookies always; analytics and ad measurement cookies only if you accept them. See the Cookie Policy.

Information from others

  • Sign-in providers (GitHub, Google) send us the account details described above.
  • GitHub, if you install our GitHub App, tells us which accounts and repositories you granted access to.
  • Stripe tells us about payments, refunds, disputes and subscription status.

We don't intentionally collect special categories of personal data (such as health, ethnicity or biometric data). Please don't put such data in Your Content unless you have a lawful basis to.

5.How we use information and our legal bases

We use personal information only for these purposes. For people in the EU, UK and Switzerland, the legal basis for each is shown.

PurposeLegal basis (GDPR)
Create and run your Account, sign you in, provide the Services you request, run agents and ComputersPerformance of our contract with you
Bill paid plans, process refunds, keep tax and accounting recordsContract; legal obligation
Keep the Services secure, prevent fraud and abuse, enforce our Terms and Acceptable Use PolicyLegitimate interests in protecting our users and Services
Answer questions and provide supportContract; legitimate interests
Send service messages, such as receipts, security alerts and changes to our termsContract; legal obligation
Understand which pages and features are useful, through website analytics and ad measurementConsent, which you can withdraw at any time
Improve and fix the Services using aggregated, de-identified usage information (never Your Content)Legitimate interests in improving our product
Comply with law, respond to lawful requests, establish or defend legal claimsLegal obligation; legitimate interests

Where we rely on legitimate interests, we have balanced them against your rights; you can object (section 12). We don't make decisions about you based solely on automated processing that have legal or similarly significant effects.

6.AI models and Your Content

  • No training. We don't use Your Content, prompts, code or Output to train or fine-tune any AI model, and we don't sell or license it to anyone who would.
  • Your providers. When an agent runs, what it sends to a model provider (prompts, code and context) is processed by that provider under your account and its terms and privacy policy. Check whether your provider retains or trains on API data.
  • No human review of Your Content by us, except when you ask for support involving it, when we must investigate abuse or a security incident, or when the law requires it.

7.How we share information

We don't sell personal information for money. We share it only as follows:

  • Service providers (processors) that run the Services for us under contracts that limit their use of it. They are listed in the table below and in the Data Processing Addendum.
  • Services you direct us to use, such as model providers and services you connect, when an agent you run sends them data.
  • Legal and safety: to comply with law, a court order or a lawful government request; to protect the rights, property or safety of our users, the public or us; or to investigate fraud, abuse or security issues. Where lawful, we tell you about requests for your data first.
  • Business transfers: in a merger, acquisition, financing, reorganization or sale of assets, subject to this policy, with notice to you.
  • With your consent or at your direction.
ProviderWhat they doLocation
RailwayHosting for the website, web app and dataUnited States
StripePayments, subscriptions, invoices, taxUnited States
GitHub (Microsoft)Sign-in; repository access you grantUnited States
GoogleSign-in; website analytics and ad measurement, only with consentUnited States
PostHogWebsite pageviews and selected clicks, only with consent; no session recordingUnited States
CloudflareDomain name service and email routingUnited States / global
Cloud computer providersHosting Computers you create on hosted infrastructureShown when you create a Computer

8.Categories under U.S. state privacy laws

In the last 12 months we have collected these categories of personal information, for the purposes in section 5, from the sources in section 4:

CategoryExamplesDisclosed to
IdentifiersAccount ID, username, email, IP addressHosting, sign-in and payment providers
Commercial informationPlans, purchases, refunds, credit usedStripe
Internet activityPages visited, usage of the Services, logsHosting provider; Google, with consent
Approximate locationCountry or city inferred from IP address; billing countryHosting provider; Stripe
Professional informationOrganization name, if you give itHosting provider
Sensitive personal informationAccount credentials and API keys you storeUsed only to provide the Services; not disclosed

We use sensitive personal information only to provide the Services you requested, as allowed by the CCPA without a right to limit. We don't sell personal information. If you accept ad measurement cookies, Google's ad measurement may count as "sharing" for cross-context behavioural advertising under California law; you can opt out at any time by rejecting those cookies in our cookie settings or by using Global Privacy Control, which we honour. We don't knowingly sell or share the personal information of anyone under 16.

9.International transfers

We are based in the United States, and our providers process data in the United States and other countries. When we transfer personal data from the EU, EEA, UK or Switzerland to countries without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum and the Swiss equivalents, or on the EU–U.S. Data Privacy Framework where a provider is certified, together with appropriate supplementary measures. You can ask us for a copy of the relevant safeguards.

10.How long we keep information

DataKept for
Account informationWhile your Account is open, then deleted within 30 days of closing, unless needed for the items below
Runs: prompts, logs, receipts, patches14 days after the run finishes, or until you delete it
Hosted Computers and their filesUntil you delete the Computer, or it is removed for lack of credit
Stored keysUntil you delete them or close your Account
Sign-in sessionsUp to 30 days, or until you sign out
Billing, invoices and tax recordsAs long as tax and accounting law requires, generally 7 years
Security and audit logsUp to 12 months, longer if needed for an investigation
Support messagesUp to 3 years after the conversation ends
Website analyticsThe retention periods configured in Google Analytics and PostHog

We may keep information longer where the law requires it or to establish or defend legal claims, and then delete it.

11.Security

We protect personal information with measures appropriate to the risk, including:

  • encryption in transit with TLS, and encryption at rest of stored keys with AES-256-GCM, decrypted only to start a run;
  • isolation of each agent run on a Computer of its own, separate from your device and from other customers;
  • secure, http-only, same-site session cookies and protections against cross-site requests;
  • access to production systems limited to people who need it, and an audit log of actions on Computers;
  • keeping software and dependencies up to date.

No method of transmission or storage is completely secure. If a personal data breach affects you, we will notify you and the relevant authorities as the law requires, generally within 72 hours of becoming aware of it for GDPR purposes and without unreasonable delay under U.S. state breach laws.

12.Your rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you and receive a copy;
  • Correct information that is inaccurate or incomplete;
  • Delete your information;
  • Port information you gave us, in a structured, machine-readable format;
  • Restrict or object to processing, including processing based on legitimate interests and direct marketing;
  • Withdraw consent at any time, without affecting earlier processing;
  • Opt out of sale, sharing for cross-context behavioural advertising, targeted advertising and profiling with significant effects;
  • Not be discriminated against for exercising these rights;
  • Complain to a data protection authority, such as your local EU supervisory authority, the UK Information Commissioner's Office or the Swiss FDPIC.

You can delete runs, keys and Computers in the app at any time. For anything else, email [email protected]. We'll verify your request by asking you to confirm through your signed-in Account or email, and respond within one month under GDPR or 45 days under U.S. state laws, extendable where the law allows. You may use an authorized agent; we may ask for proof of their authority. If we deny a request, you may appeal by replying to our decision, and if we deny the appeal you may contact your state Attorney General.

13.U.S. state privacy laws

This section supplements this policy for residents of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island and other states with comprehensive privacy laws, to the extent those laws apply to us.

  • Notice at collection. Sections 4, 5, 8 and 10 describe the categories we collect, why, and how long we keep them.
  • Global Privacy Control. If your browser sends a GPC signal, we treat it as a request to opt out of sale and sharing for that browser and don't load analytics or ad measurement tags.
  • Do Not Track. There is no common standard for Do Not Track signals; we rely on GPC and our cookie settings instead.
  • California "Shine the Light". We don't share personal information with third parties for their own direct marketing.
  • Nevada. We don't sell covered information as defined by Nevada law.
  • Financial incentives. We don't offer any.

14.Children

The Services are not directed to children and aren't for anyone under 16. We don't knowingly collect personal information from children under 13, as defined by the U.S. Children's Online Privacy Protection Act, or from anyone under 16. If you believe a child has given us personal information, email [email protected] and we will delete it.

15.Emails

We send service emails you can't opt out of while you have an Account, such as receipts, security alerts and changes to our terms. If we send product news or marketing, we'll do so only where the law allows, include our postal address and an unsubscribe link in every message, and honour opt-outs promptly, as required by the U.S. CAN-SPAM Act, Canada's Anti-Spam Legislation and EU and UK electronic marketing rules.

16.Canada, Brazil, Australia and other countries

If you live in Canada (PIPEDA and provincial laws, including Quebec's Law 25), Brazil (LGPD), Australia (Privacy Act 1988), Japan (APPI), Singapore (PDPA), South Korea (PIPA), India (DPDP Act) or another country with a data protection law, you have the rights that law provides, which generally include access, correction, deletion and complaint to a regulator. Contact [email protected] to exercise them; our privacy contact acts as the person responsible for personal information under those laws.

17.Changes to this policy

We'll update this policy when our practices or the law change. The date at the top shows the latest version. For material changes we'll notify you by email or in the Services before they take effect and, where the law requires, ask for your consent.

18.Contact

Privacy questions and requests: [email protected]. Postal: Macaron, Florida, United States. If you're in the EU, EEA or UK, you can contact us directly at the same address, and you also have the right to complain to your data protection authority.

Macaron, Florida, United States. Questions about this document: [email protected]