Privacy Policy
Last updated October 1, 2026
In short
- The desktop app and command line keep your code on your computer. We never see it.
- In the web app, stored keys are encrypted and runs are deleted 14 days after they finish.
- We don't sell your data, and we never train AI models on your code or prompts.
- Analytics and ad cookies load only if you accept them; Global Privacy Control is honoured.
- Ask for a copy, a correction or deletion any time: [email protected].
1.Who we are
Macaron ("we", "us") provides macaron.sh, the Macaron web app, desktop app and command line (the "Services"). We are based in Florida, United States. For personal information we decide how to use, such as account, billing and website data, we are the "controller" under the EU and UK General Data Protection Regulation ("GDPR") and a "business" under the California Consumer Privacy Act ("CCPA").
When a business customer uses the Services to process personal data that belongs to them, such as personal data inside their code or repositories, we act as their "processor" or "service provider", and our Data Processing Addendum governs that processing.
Contact for anything in this policy: [email protected].
2.What this policy covers
This policy covers personal information we collect through the Services, our website, our emails and our support. It doesn't cover Third-Party Services you connect, such as model providers, GitHub or deployment platforms, which have their own policies. Read it together with the Terms of Service and the Cookie Policy.
3.The desktop app and command line
Our desktop app and command line run on your own computer. Your projects, chats, settings and history are stored there, and API keys you add to the desktop app are encrypted with your operating system's keychain. Prompts, code and files go directly from your computer to the AI model provider you chose, using your own account; they don't pass through our servers and we can't see them.
We receive information from these apps only when: you sign in to a Macaron account; update checks are turned on, when the app asks our update server whether a newer version exists, sharing your IP address, app version and operating system; or you choose to send us a report or feedback. The apps contain no analytics or advertising trackers.
4.Information we collect
Information you give us
- Account information. When you sign in with GitHub or Google: your account ID, username, and, if the provider shares it, name, email address and profile picture. We never receive your GitHub or Google password.
- Billing information. If you buy a plan: your Stripe customer ID, plan, billing status, invoices, billing country and address needed for tax. Stripe collects and stores your card details; we never see or store full card numbers.
- Keys and connections. API keys and tokens you save for model providers and connected services, stored encrypted (see section 11).
- Your Content in the web app. Prompts, repository addresses, run settings, agent logs, receipts and patches for runs, and the code and files placed on hosted Computers.
- Communications. What you send us by email or through support, and related records.
Information collected automatically
- Usage and device data. IP address, browser and operating system, pages visited, referring page, time and date, and request logs kept by our hosting provider to run and protect the Services.
- Service records. Session records that keep you signed in, an audit log of actions on your Computers and runs, and usage records such as Computer time and credit used, for billing and security.
- Cookies and similar technologies. Strictly necessary cookies always; analytics and ad measurement cookies only if you accept them. See the Cookie Policy.
Information from others
- Sign-in providers (GitHub, Google) send us the account details described above.
- GitHub, if you install our GitHub App, tells us which accounts and repositories you granted access to.
- Stripe tells us about payments, refunds, disputes and subscription status.
We don't intentionally collect special categories of personal data (such as health, ethnicity or biometric data). Please don't put such data in Your Content unless you have a lawful basis to.
5.How we use information and our legal bases
We use personal information only for these purposes. For people in the EU, UK and Switzerland, the legal basis for each is shown.
| Purpose | Legal basis (GDPR) |
|---|---|
| Create and run your Account, sign you in, provide the Services you request, run agents and Computers | Performance of our contract with you |
| Bill paid plans, process refunds, keep tax and accounting records | Contract; legal obligation |
| Keep the Services secure, prevent fraud and abuse, enforce our Terms and Acceptable Use Policy | Legitimate interests in protecting our users and Services |
| Answer questions and provide support | Contract; legitimate interests |
| Send service messages, such as receipts, security alerts and changes to our terms | Contract; legal obligation |
| Understand which pages and features are useful, through website analytics and ad measurement | Consent, which you can withdraw at any time |
| Improve and fix the Services using aggregated, de-identified usage information (never Your Content) | Legitimate interests in improving our product |
| Comply with law, respond to lawful requests, establish or defend legal claims | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have balanced them against your rights; you can object (section 12). We don't make decisions about you based solely on automated processing that have legal or similarly significant effects.
6.AI models and Your Content
- No training. We don't use Your Content, prompts, code or Output to train or fine-tune any AI model, and we don't sell or license it to anyone who would.
- Your providers. When an agent runs, what it sends to a model provider (prompts, code and context) is processed by that provider under your account and its terms and privacy policy. Check whether your provider retains or trains on API data.
- No human review of Your Content by us, except when you ask for support involving it, when we must investigate abuse or a security incident, or when the law requires it.
8.Categories under U.S. state privacy laws
In the last 12 months we have collected these categories of personal information, for the purposes in section 5, from the sources in section 4:
| Category | Examples | Disclosed to |
|---|---|---|
| Identifiers | Account ID, username, email, IP address | Hosting, sign-in and payment providers |
| Commercial information | Plans, purchases, refunds, credit used | Stripe |
| Internet activity | Pages visited, usage of the Services, logs | Hosting provider; Google, with consent |
| Approximate location | Country or city inferred from IP address; billing country | Hosting provider; Stripe |
| Professional information | Organization name, if you give it | Hosting provider |
| Sensitive personal information | Account credentials and API keys you store | Used only to provide the Services; not disclosed |
We use sensitive personal information only to provide the Services you requested, as allowed by the CCPA without a right to limit. We don't sell personal information. If you accept ad measurement cookies, Google's ad measurement may count as "sharing" for cross-context behavioural advertising under California law; you can opt out at any time by rejecting those cookies in our cookie settings or by using Global Privacy Control, which we honour. We don't knowingly sell or share the personal information of anyone under 16.
9.International transfers
We are based in the United States, and our providers process data in the United States and other countries. When we transfer personal data from the EU, EEA, UK or Switzerland to countries without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum and the Swiss equivalents, or on the EU–U.S. Data Privacy Framework where a provider is certified, together with appropriate supplementary measures. You can ask us for a copy of the relevant safeguards.
10.How long we keep information
| Data | Kept for |
|---|---|
| Account information | While your Account is open, then deleted within 30 days of closing, unless needed for the items below |
| Runs: prompts, logs, receipts, patches | 14 days after the run finishes, or until you delete it |
| Hosted Computers and their files | Until you delete the Computer, or it is removed for lack of credit |
| Stored keys | Until you delete them or close your Account |
| Sign-in sessions | Up to 30 days, or until you sign out |
| Billing, invoices and tax records | As long as tax and accounting law requires, generally 7 years |
| Security and audit logs | Up to 12 months, longer if needed for an investigation |
| Support messages | Up to 3 years after the conversation ends |
| Website analytics | The retention periods configured in Google Analytics and PostHog |
We may keep information longer where the law requires it or to establish or defend legal claims, and then delete it.
11.Security
We protect personal information with measures appropriate to the risk, including:
- encryption in transit with TLS, and encryption at rest of stored keys with AES-256-GCM, decrypted only to start a run;
- isolation of each agent run on a Computer of its own, separate from your device and from other customers;
- secure, http-only, same-site session cookies and protections against cross-site requests;
- access to production systems limited to people who need it, and an audit log of actions on Computers;
- keeping software and dependencies up to date.
No method of transmission or storage is completely secure. If a personal data breach affects you, we will notify you and the relevant authorities as the law requires, generally within 72 hours of becoming aware of it for GDPR purposes and without unreasonable delay under U.S. state breach laws.
12.Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you and receive a copy;
- Correct information that is inaccurate or incomplete;
- Delete your information;
- Port information you gave us, in a structured, machine-readable format;
- Restrict or object to processing, including processing based on legitimate interests and direct marketing;
- Withdraw consent at any time, without affecting earlier processing;
- Opt out of sale, sharing for cross-context behavioural advertising, targeted advertising and profiling with significant effects;
- Not be discriminated against for exercising these rights;
- Complain to a data protection authority, such as your local EU supervisory authority, the UK Information Commissioner's Office or the Swiss FDPIC.
You can delete runs, keys and Computers in the app at any time. For anything else, email [email protected]. We'll verify your request by asking you to confirm through your signed-in Account or email, and respond within one month under GDPR or 45 days under U.S. state laws, extendable where the law allows. You may use an authorized agent; we may ask for proof of their authority. If we deny a request, you may appeal by replying to our decision, and if we deny the appeal you may contact your state Attorney General.
13.U.S. state privacy laws
This section supplements this policy for residents of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Hampshire, New Jersey, Nebraska, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island and other states with comprehensive privacy laws, to the extent those laws apply to us.
- Notice at collection. Sections 4, 5, 8 and 10 describe the categories we collect, why, and how long we keep them.
- Global Privacy Control. If your browser sends a GPC signal, we treat it as a request to opt out of sale and sharing for that browser and don't load analytics or ad measurement tags.
- Do Not Track. There is no common standard for Do Not Track signals; we rely on GPC and our cookie settings instead.
- California "Shine the Light". We don't share personal information with third parties for their own direct marketing.
- Nevada. We don't sell covered information as defined by Nevada law.
- Financial incentives. We don't offer any.
14.Children
The Services are not directed to children and aren't for anyone under 16. We don't knowingly collect personal information from children under 13, as defined by the U.S. Children's Online Privacy Protection Act, or from anyone under 16. If you believe a child has given us personal information, email [email protected] and we will delete it.
15.Emails
We send service emails you can't opt out of while you have an Account, such as receipts, security alerts and changes to our terms. If we send product news or marketing, we'll do so only where the law allows, include our postal address and an unsubscribe link in every message, and honour opt-outs promptly, as required by the U.S. CAN-SPAM Act, Canada's Anti-Spam Legislation and EU and UK electronic marketing rules.
16.Canada, Brazil, Australia and other countries
If you live in Canada (PIPEDA and provincial laws, including Quebec's Law 25), Brazil (LGPD), Australia (Privacy Act 1988), Japan (APPI), Singapore (PDPA), South Korea (PIPA), India (DPDP Act) or another country with a data protection law, you have the rights that law provides, which generally include access, correction, deletion and complaint to a regulator. Contact [email protected] to exercise them; our privacy contact acts as the person responsible for personal information under those laws.
17.Changes to this policy
We'll update this policy when our practices or the law change. The date at the top shows the latest version. For material changes we'll notify you by email or in the Services before they take effect and, where the law requires, ask for your consent.
18.Contact
Privacy questions and requests: [email protected]. Postal: Macaron, Florida, United States. If you're in the EU, EEA or UK, you can contact us directly at the same address, and you also have the right to complain to your data protection authority.
Macaron, Florida, United States. Questions about this document: [email protected]