Docs

Privacy and your data

What Tracker Trapper keeps on your Mac, what Mobile sync uploads, and how long the relay keeps it.

Tracker Trapper is local-first. Your plans, tasks, runs and evidence live on your Mac. Nothing leaves your Mac unless you turn on GitHub sync or Mobile sync, and each of those sends only what it needs.

On your Mac

  • Everything is stored in ~/Library/Application Support/TrackerTrapper.
  • Agents report through a local MCP server and command-line tool. There's no open port and no web service to expose.
  • Session watching reads the agent session files you link, on your Mac. Transcripts are never uploaded.
  • Copied diagnostics leave out file paths, issue text, credentials and session transcripts.

GitHub

GitHub features use the account you've signed in to with the GitHub CLI (gh). Your credentials stay in gh. Tracker Trapper reads issue checklists you import and writes progress back only when you run a sync. Local plans never touch GitHub.

Mobile sync (iPhone companion)

Mobile sync is off until you turn it on. While it's off, Tracker Trapper makes no network requests for sync. When it's on, your Mac publishes your Active plans to Tracker Trapper's relay so your paired phone can read them.

What sync uploads

  • Active plan: ID, revision, title, source (local or GitHub), next task ID, last update time
  • GitHub plans only: repository owner/name, issue number and issue URL
  • Tasks: ID, order, revision, description, status, start and completion times
  • Runs: ID, agent name, status, last activity time
  • Asks waiting on you: kind, choices and the sentence the agent wrote, unless Send ask text to iPhone is off (a link in “where” is sent; a local path never is)

Never uploaded

  • Transcripts, tool names and tool arguments
  • Session IDs and session file paths
  • Any absolute or local path, including your workspace and repository paths
  • Credentials and tokens
  • Raw evidence and acceptance-check text
  • Activity message bodies

Your Mac shows these same lists in Settings → Companion.

Your account and devices

Your email is used to sign in and to check your beta invitation. Session credentials are stored in the iOS Keychain. Notification device tokens are used only to deliver notifications through Apple. You approve every phone from your Mac and can revoke it there.

How long the relay keeps data

DataKept
Current Active plansWhile Mobile sync is on
Change history7 days
Sign-in codes / pairing requests10 minutes / 5 minutes
Signed-in sessions30 days idle, 180 days at most
Relay backupsUp to 14 days

Delete your synced data

Open trackertrapper.com/app, sign in with your email, and choose Settings → Delete my synced data. If you signed in more than 10 minutes ago, you'll confirm with a fresh emailed code. This deletes your account on the relay and every workspace you own: synced plans, history, paired devices and queued notifications. Deletion from the live relay is immediate, and copies in existing backups expire within 14 days. Plans on your Mac aren't touched; Mobile sync stops until you set it up again.

On your iPhone

  • The app caches shared plans so you can read them offline. Signing out or being revoked clears that cache and its credentials.
  • Widgets read a small local file with plan and task titles. It holds no credentials or evidence and is excluded from backups.
  • Lock-screen notifications are generic unless you choose detailed previews.
  • The app doesn't use advertising tracking.

This website

trackertrapper.com is a static site. It loads the Buy Me a Coffee widget from buymeacoffee.com. Your theme choice is saved in your browser's local storage.

The site counts visits with Umami, self-hosted at analytics.shelbyklein.com. It records the page address, the referring site, the visit time, browser and device type, language, screen size and an approximate location from the network request. It uses no cookies and doesn't identify you. The web companion at trackertrapper.com/app doesn't load it.

Found a privacy problem? Please open an issue. Never include sign-in codes, QR codes, tokens or transcripts.