Privacy Policy
Effective date: September 17, 2026
Last updated: September 20, 2026
In short
- The SupaYatta Mac app has no analytics or telemetry of its own. The supayatta.com website uses PostHog for anonymous analytics.
- The Mac app never uploads your prompts, code or replies.
- A seven-day trial uses your verified email and a device security key. Loops delivers the verification email; MongoDB stores the trial record.
- Product updates and offers are optional and require a separate unchecked consent box.
- Paid activation sends your license key and a device name to Dodo Payments.
- Codex usage bars come from your own signed-in Codex CLI, under your own OpenAI account.
- Dodo Payments handles checkout and payment details; we never see or store your full card details.
1. Who we are
SupaYatta is made by Kshetez Vinayak, an individual independent developer based in India. In this policy, "we" and "us" means Kshetez. Kshetez also makes SupaSidebar. For anything about privacy, refunds, support or grievances, contact admin@supasidebar.com.
2. What the Mac app reads (on your Mac)
When you connect an agent, the app reads: session status from Claude Code and Codex hooks; task titles and project folder paths; a short preview of the agent's last reply or question, trimmed to 200 characters; and, read-only, the tail of Claude Cowork transcripts and Codex desktop's local task list. To match sessions to the right chat title, it also reads, read-only, the Claude and Codex apps' local session records and app logs. It reads these only to show you a session's state, and never changes them. It reads nothing else on your Mac unless you turn on the optional Accessibility feature described in section 8.
3. What the app stores and where
The app stores session states, recent alerts, your settings and usage percentages in its own local folder on your Mac. That folder's directories are set to 0700 and its files to 0600, so only your user account can open them. If you start a trial, the app also stores its device-bound trial private key and signed receipt in your macOS Keychain.
4. What leaves your Mac
When you request a trial, the app sends your email to our trial service. When you start or revalidate it, the app sends the signed trial receipt and a device public key or proof; the private key never leaves your Keychain. When you enter a paid key, the app sends the license key and a device name or identifier to Dodo Payments' license API, to activate it and enforce the 5-Mac limit. Codex usage is read by running your own installed, signed-in Codex CLI, which talks to OpenAI under your own account and OpenAI's terms; SupaYatta receives only the percentages it reports. Your prompts, code, replies and local session history are not sent to our trial service. The app has no analytics, telemetry or crash reporting.
5. Seven-day trials
To provide one seven-day trial per verified email and bind its receipt to one app installation, our server sends a six-digit verification code through Loops and stores a trial record in MongoDB Atlas. That record contains your normalized email, a keyed email hash, your device public key and its hash, the fixed trial start and end times, and your marketing-consent choice. The server may also receive ordinary hosting logs such as IP address, user agent and request time. Loops receives your email and verification-code template data for transactional delivery, but this request does not add you to our marketing audience. Verification records expire after about ten minutes. We retain the trial record while needed to enforce the one-trial policy, prevent abuse and provide support, subject to your rights below.
6. Website
supayatta.com is hosted on Vercel and uses PostHog for anonymous product analytics: pages viewed, clicks, and device or browser information, tied to an anonymous identifier PostHog stores in a cookie or local storage in your browser. This is separate from the Mac app, which still sends no analytics or telemetry of its own (see above). Our hosting provider may also log your IP address, user agent and request time, for security and running the service. The purchase delivery page does not initialize PostHog. We use a temporary, signed browser cookie lasting up to 24 hours to retrieve your purchase securely; this cookie contains no email or license key.
7. Purchases
Dodo Payments is the Merchant of Record and reseller for SupaYatta. Checkout happens on Dodo's own hosted page, where Dodo collects your name, email, billing country or address and payment details. We never see or store your full card details. Dodo's own terms and privacy policy apply to the purchase, see dodopayments.com. Dodo shares order details with us: your email, name, country, amount paid and license key. Our server verifies your checkout with Dodo before displaying the matching key on the purchase page.
8. Emails you send us
If you email us for support, to claim a free key, or for a refund, we keep that email only as long as we need it to help you, or as long as we must for tax and legal records. If you separately choose product updates, discounts and offers, we send your chosen email address and signup source to Loops to manage that subscription. You may use your purchase email or another address. Choosing another address does not change your purchase details. You can unsubscribe from update emails at any time. Joining our Discord community is a separate choice, governed by Discord's terms and privacy policy.
9. Changes the app makes to your config files
When you connect an agent, the app first backs up ~/.claude/settings.json or ~/.codex/hooks.json with an exact copy, then adds only its own hooks. Disconnect removes only what it added; the backup stays. An optional experimental feature may ask for macOS Accessibility permission, only if you turn it on yourself. With it on, the app reads the controls in the Claude app window to spot when it is waiting for you.
10. How long we keep data
App data on your Mac stays until you delete it yourself, see Your rights below for how. Trial verification records expire after about ten minutes. We keep the trial identity and grant record while needed to enforce the one-trial policy, prevent abuse and provide support. We hold purchase data for as long as we need it to support you and for as long as tax or legal rules require, then delete what we no longer need to keep.
11. Your rights
You can ask to access, correct, or delete the data we hold about you, and you can withdraw consent where consent is the basis for holding it. This applies under India's Digital Personal Data Protection Act, 2023, and, where applicable, the GDPR, UK GDPR and California law. We do not sell or share your personal data for advertising. To exercise any of these rights, email admin@supasidebar.com.
12. Children
SupaYatta is not directed at anyone under 18.
13. Security
We keep conversation and session data local to your Mac, with restrictive file permissions (0700 directories, 0600 files). Trial secrets are stored in your macOS Keychain, and the backend stores only the public device key. Access to MongoDB, Loops, Dodo Payments and our hosting account is restricted, but no method of storage or transfer is perfectly secure.
14. Changes to this policy
We may update this policy from time to time. We'll update the "Last updated" date at the top when we do.
15. Contact and grievance officer
Grievance officer: Kshetez Vinayak. Email: admin@supasidebar.com. We aim to respond within 30 days.
Questions about this policy? Read our Terms of Service or email admin@supasidebar.com.