This Privacy Policy explains how Stlog handles information in the Stlog macOS application and on stlog.ai. Stlog is a local-first personal work log. It does not require a Stlog account and does not use a Stlog-operated cloud database for your work logs or drafts in the current release.
1. At A Glance
Private by default. Work logs and drafts are stored on your Mac. Data leaves only through a provider, connector, export, or scheduled provider action that you choose.
- Automatic capture is off until you enable it and grant the required macOS permissions.
- Stlog does not sell personal data, run advertising, or track you across apps and websites.
- Stlog does not operate an analytics or crash-reporting service in the current release.
- Generated drafts are never automatically published or submitted to another person or work system.
2. Information Stlog Processes
2.1 Work Activity And Content
Depending on the features you enable, Stlog may process:
- timestamps and the duration of a captured activity
- the active application name and bundle identifier
- window titles
- workspace or repository names and local paths
- text entered while automatic capture is active
- a limited preview of pasted text when a paste shortcut is detected
- manual notes and imported Git activity
- generated daily, weekly, or monthly work-update drafts
- references connecting a draft to the local activity records used to create it
Text and paste previews are passed through a pattern-based redaction filter before Stlog writes them to disk. The filter looks for certain token, API key, email, payment-card-like, and identifier patterns. Automated redaction can miss sensitive information. Review captured activities and generated drafts and delete anything you do not want to keep or send.
2.2 Settings And Permissions
Stlog stores capture status, excluded apps, language, selected draft provider, workspace preferences, repository paths, Work Rhythm times, notifications, launch-at-login preferences, and an optional connector URL.
Stlog may request macOS Input Monitoring and Accessibility permissions for automatic capture and workspace context. You can pause capture in Stlog and revoke permissions in macOS System Settings.
2.3 Credentials
An access token or API key that you enter for an MCP connector is stored in macOS Keychain, not in Stlog's JSON settings files. Stlog does not read or store your Codex authentication token. Codex authentication remains under the control of the Codex CLI or application you installed separately.
2.4 Support Communications
If you contact us, we process the contact details, message content, and files you choose to provide so that we can respond and maintain a record of the request. Do not send raw work logs or secrets unless they are necessary and you are authorized to share them.
2.5 Website Requests
The legal website at stlog.ai is hosted through Cloudflare. Cloudflare may process network information such as IP address, request time, user agent, and security events to deliver and protect the site. We do not add advertising trackers or analytics cookies to the legal site.
3. Where Data Is Stored
Stlog stores local settings, activity records, and drafts as JSON files under ~/Library/Application Support/Stlog.
These JSON files are not separately encrypted by Stlog. They rely on your macOS account, device encryption, backups, access controls, and physical security. Connector credentials are stored separately in macOS Keychain.
If you export a TXT or JSON backup, the exported file may contain work content, window and workspace context, and generated drafts. You choose its destination and are responsible for protecting, moving, and deleting that file.
4. When Data Leaves Your Mac
4.1 Codex
When you choose Codex and start draft generation, Stlog sends a prompt to the locally installed codex executable. The prompt can include redacted activity text, app names, window titles, workspace names or paths, timestamps, manual notes, and draft instructions. The Codex runtime may transmit that prompt to OpenAI under the account and settings you use with Codex.
If you explicitly enable Work Rhythm and automatic Daily Wrap preparation, Stlog may invoke your selected draft provider at the configured wrap-up time without another button press. The resulting draft remains local and is not automatically published or submitted.
OpenAI processes data according to its own terms and privacy policy. Stlog does not control OpenAI's retention or account settings. Review OpenAI's Privacy Policy before using Codex with confidential work information.
4.2 Ollama
When you choose Ollama, Stlog sends prompts to an Ollama server on your Mac at a loopback address such as 127.0.0.1. Stlog does not configure a remote Ollama endpoint in the current release. Models and the Ollama runtime are installed and managed separately by you.
4.3 MCP Connectors
If you configure an MCP connector, Stlog sends authenticated requests to the endpoint you provide. Requests may include connector metadata, project queries, and reviewed work-update content that you choose to send. The endpoint operator sets its own retention, security, and privacy practices. Do not connect a work service or submit content unless you are authorized to do so.
4.4 Exports And Clipboard Actions
Copy, TXT export, and JSON backup actions place data in a destination you control. Other applications, clipboard managers, sync tools, or backup services may then process that data under their own settings.
5. Purposes And Legal Bases
Where data-protection law requires a legal basis, we rely on:
- Performance of a contract or steps you request: to capture, organize, generate, export, and restore your work records.
- Consent: for optional macOS permissions and optional transfers to an AI provider or connector where consent is required. You can withdraw consent by pausing capture, disabling automation, revoking permissions, or disconnecting the provider.
- Legitimate interests: to secure, troubleshoot, and improve the app and respond to support requests, provided those interests do not override your rights.
- Legal obligations: when we must retain or disclose limited information to comply with applicable law.
7. Retention And Deletion
Local work logs, settings, and drafts remain on your Mac until you delete them. The current release does not automatically expire local activity records.
Stlog provides controls to delete today's records and drafts, delete all local Stlog data, delete a connector credential, and export a JSON backup before deletion.
Deleting local Stlog data does not delete data that you previously exported, copied, submitted to a connector, or sent through an external AI provider. Use the receiving service's controls for those copies. Uninstalling the app may not remove files under Application Support, so use Stlog's delete control first if you want those files removed.
Support communications are kept only as long as reasonably needed to resolve the request, maintain security and support records, or meet legal obligations. Cloudflare controls retention of infrastructure and security data it processes for the website.
8. Your Choices And Rights
You can inspect, edit, export, and delete local records directly in Stlog. You can also pause capture, exclude applications, turn off Work Rhythm, remove a connector token, or revoke macOS permissions.
Depending on where you live, you may also have rights to request access, correction, deletion, restriction, objection, or portability for personal data that the operator holds, and to complain to your local data-protection authority. Because the operator does not receive your local work logs by default, many requests can be completed immediately with controls on your Mac. Contact privacy@stlog.ai for data held in support communications or for other privacy requests.
9. International Processing
Apple, Cloudflare, OpenAI, and a connector you choose may process data in countries other than your own. Their privacy notices describe their locations and transfer safeguards. Do not enable an external provider for work content if your employer, client, or applicable law prohibits that transfer.
10. Security
Stlog uses local storage, macOS permission controls, Keychain for connector credentials, denylisted applications, secure-input detection, and pattern-based redaction to reduce risk. No product or storage method is perfectly secure. Keep macOS updated, use device encryption and a strong login password, and review captured content before exporting or sending it.
11. Children
Stlog is a workplace productivity application and is not directed to children under 16. Do not use Stlog if you cannot legally agree to these practices in your jurisdiction.
12. Changes To This Policy
We may update this policy when Stlog's data practices or legal requirements change. We will update the date above and provide additional notice in the app when a change materially affects how your data is handled.
13. Contact
Data controller: Jeonguk Hur
Country or region: Republic of Korea
Email: privacy@stlog.ai