This Privacy Policy explains how Stlog handles information in the Stlog macOS application, the Stlog managed AI service, and stlog.ai. Stlog is a local-first personal work log. It does not require a Stlog account or upload your local work-log database for cloud backup.
1. At A Glance
- Work logs and completed drafts are stored on your Mac.
- Automatic capture is off until you enable it and grant the required macOS permissions.
- When you ask Stlog AI to create or improve a draft, the app sends the redacted prompt needed for that request to the Stlog managed service.
- Stlog AI creates only daily work-update drafts. It does not generate weekly or monthly AI summaries.
- Stlog AI verifies App Store signed material, applies Free or Pro policy, and chooses the model on the server. You do not provide an AI-provider login or API key.
- The managed service does not persist raw prompts, generated text, or Apple signed transaction material in its application ledger or application logs.
- Generated drafts are never automatically published or submitted to another person or work system.
- Product-improvement analytics is off by default. If you enable it, Stlog sends a narrowly limited set of product-use events to Firebase Analytics.
- Stlog does not sell personal data, run advertising, or track you across apps and websites.
2. Information Stlog Processes
2.1 Local Work Activity And Content
Depending on the features you enable, Stlog may process:
- timestamps and activity duration
- active application name and bundle identifier
- window titles
- workspace or repository names and local paths
- keyboard activity timing and event counts while automatic capture is active
- the fact that a paste shortcut occurred, without reading clipboard contents
- manual notes and imported Git activity
- generated daily work-update drafts
- local references connecting a draft to the evidence used to create it
Stlog does not reconstruct or store typed characters and does not read or store clipboard contents during automatic capture. Manual notes, imported activity, app and window context, workspace details, and draft prompts pass through a pattern-based redaction filter where applicable. Automated redaction can miss sensitive information. Review captured activities and generated drafts before keeping, copying, exporting, or sending them.
2.2 Settings And Permissions
Stlog stores settings such as:
- capture status and excluded applications
- selected language, appearance, and writing style
- workspace-context preferences and configured repository paths
- Work Rhythm start and wrap-up times
- notification, analytics, and launch-at-login preferences
Stlog may request macOS Input Monitoring and Accessibility permissions for automatic capture and workspace context. You can pause capture in Stlog and revoke permissions in macOS System Settings.
2.3 Stlog Managed AI Requests
When you explicitly request Stlog AI, or enable scheduled Daily Wrap preparation, Stlog may process:
- the redacted draft prompt and writing instructions
- redacted activity text, app names, window titles, workspace names or path tails, timestamps, and manual notes included as evidence
- for Work Memory, your question and a bounded set of top-ranked redacted evidence records
- requested draft kind and response format
- an opaque idempotency key and provider-reported input, cached-input, cache-write, output, reasoning, and total token counts
- an integer micro-USD cost derived from the published server-selected model rate, or a marker when terminal usage is unavailable
- provider-attempt and terminal counts, request status, stable error category, and Free or Pro policy
- network and request metadata processed by Google Cloud to deliver and secure the service
The macOS app obtains signed AppTransaction and, when available, current subscription transaction material from StoreKit. The managed service processes that material to verify the production app, Apple environment, and Stlog subscription entitlement. It derives a pseudonymous HMAC subject from the verified App Transaction ID. Raw JWS values and raw Apple transaction identifiers are not stored in the Stlog AI ledger or written to Stlog application logs.
Stlog AI uses short-lived one-time challenges and signed session tokens. It does not ask for or store your Apple Account password, AI-provider credentials, or model-provider API keys.
2.4 App Store Purchases And Subscription Status
Apple processes Stlog purchases and subscriptions. Stlog may receive and process the product identifier, verified entitlement state, transaction environment, expiration or renewal date, renewal status, billing-grace or billing-retry state, and revocation or refund state needed to unlock Pro and apply managed AI policy.
Stlog does not receive or store your payment-card number, bank-account details, or Apple Account password. Apple handles that information under its own privacy notice.
2.5 Optional Product Improvement Analytics
Product-improvement analytics is disabled by default. If you enable it in Settings, Stlog uses Google Firebase Analytics to process:
- an app-instance identifier generated for the Stlog installation
- app version and technical app, operating-system, device, language, session, and approximate-region information provided by Firebase Analytics
- allowlisted events such as onboarding completion, capture start or pause, manual-note creation, local or Stlog AI summary state, summary period and draft kind, the constant managed AI route, paywall reason, and subscription stage
Stlog does not put work-log text, manual-note text, app or window names, bundle identifiers from recorded activity, workspace or file paths, AI prompts or results, Apple signed material, email addresses, or a Stlog user ID into analytics events. Stlog uses the Firebase Analytics core SDK without advertising-identifier support, disables IDFV collection and ad-personalization signals, and does not use analytics for tracking.
You can turn analytics off at any time. Stlog then stops future collection and resets the Analytics identifier stored on that Mac. Previously received events remain subject to the configured Firebase and Google Analytics retention and deletion controls.
2.6 Support And Website Requests
If you contact us, we process the contact details, message content, and files you choose to provide so that we can respond. Do not send raw work logs, transaction JWS values, or secrets unless necessary and authorized.
The legal website at stlog.ai is hosted through Cloudflare. Cloudflare may process network information such as IP address, request time, user agent, and security events to deliver and protect the site. We do not add advertising trackers or analytics cookies to the legal site.
3. Storage And Retention
3.1 On Your Mac
Stlog stores local settings, activity records, and drafts in its macOS Application Support directory. In an App Store sandbox, that directory is inside Stlog's app container. In a local development build, it is typically:
~/Library/Application Support/Stlog
These files are not separately encrypted by Stlog. They rely on your macOS account, device encryption, backups, access controls, and physical security. They remain until you delete them.
Exports and backups may contain work content, activity context, and drafts. You choose their destination and are responsible for protecting and deleting them.
3.2 Stlog Managed AI
The Stlog service processes raw prompts, generated text, and Apple signed material only for the request. Stlog's application code does not persist those items in Firestore or write them to application logs.
The managed ledger stores pseudonymous subject and idempotency hashes, policy, draft kind, request state, timestamps, provider-reported token counts, integer micro-USD cost, provider-attempt and terminal counts, usage-availability state, and stable error categories. The service writes an expiry to production ledger documents after the applicable quota or usage window plus the configured retention period; production deployment requires Firestore TTL policies on that field. One-time challenge records expire within minutes, and session tokens expire within minutes without a server-side session record.
Stlog AI runs on Google Cloud Run and Firestore and routes each request to a server-selected OpenAI model. Cloud Run creates platform request logs, and Google Cloud may process infrastructure, security, and diagnostic metadata. OpenAI Responses requests are sent with store: false, but OpenAI's default API abuse-monitoring logs may still retain customer content for up to 30 days unless the applicable organization or project has approved retention controls. Stlog does not claim zero data retention unless the deployed OpenAI project has been separately verified for that claim.
See the Google Cloud Privacy Notice and OpenAI API data controls.
4. When Data Leaves Your Mac
4.1 Stlog Managed AI
Data leaves your Mac only after you accept the Stlog AI transfer disclosure and then start a Stlog AI operation or explicitly enable scheduled Daily Wrap preparation. Stlog sends the redacted prompt and the StoreKit signed material described above to the Stlog managed service over HTTPS. The service verifies entitlement, enforces quota, and routes the prompt to a server-selected OpenAI model. The model remains server-owned and is not selected by the app.
Stlog does not include provider credentials, raw keystroke events, or complete local files in this request. The completed draft returns to the app, remains review-only, and is not automatically posted or submitted.
If you enable scheduled Daily Wrap preparation after accepting the disclosure, a request can occur at the configured wrap-up time without another button press. Withdrawing consent disables that automation. You can change either setting at any time.
4.2 Firebase Analytics
If you opt in, the limited data described in Section 2.5 is sent to Google Firebase Analytics. See the Google Privacy Policy.
4.3 Exports And Clipboard Actions
Copy, TXT export, and JSON backup actions place data in a destination you control. Other applications, clipboard managers, sync tools, or backup services may then process it under their own settings.
5. Purposes And Legal Bases
Where data-protection law requires a legal basis, we rely on:
- Performance of a contract or steps you request: to capture, organize, generate, secure, meter, export, and restore your work records and Stlog subscription features.
- Consent: for optional macOS permissions, optional analytics, and optional or scheduled Stlog AI transfers where consent is required. You can withdraw consent by pausing capture, disabling analytics or automation, revoking permissions, or turning off Stlog AI data transfer in Settings.
- Legitimate interests: to secure, prevent abuse, troubleshoot, and improve Stlog and to respond to support requests, provided those interests do not override your rights.
- Legal obligations: when limited retention or disclosure is required by applicable law.
7. Deletion
Stlog provides controls to:
- delete today's local activity records and drafts
- delete all local Stlog data and settings
- export a JSON backup before local deletion
The managed-only migration also removes Stlog API keys that an older version may have stored under Stlog's retired Keychain service. Stlog no longer stores AI-provider API keys.
Deleting local data does not delete information already copied, exported, or processed by infrastructure providers. Managed ledger records expire under the 30-day TTL policy; raw prompt and generated text are not stored in that ledger. Contact privacy@stlog.ai for support or a privacy request involving data held by the operator.
Support communications are retained only as long as reasonably needed to resolve the request, maintain security and support records, or meet legal obligations. Website and analytics data follow the applicable provider retention controls.
8. Your Choices And Rights
You can inspect, edit, export, and delete local records in Stlog. You can pause capture, exclude applications, turn off Work Rhythm or scheduled Daily Wrap, disable analytics, choose not to invoke Stlog AI, and revoke macOS permissions.
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, or portability for personal data the operator holds, and to complain to a data-protection authority. Because local work logs remain on your Mac, many requests can be completed directly with in-app controls. Contact privacy@stlog.ai for other requests.
9. International Processing
Apple, Google, OpenAI, Cloudflare, and their subprocessors may process data outside your country. Their notices describe processing locations and safeguards. Do not use Stlog AI for work content if your employer, client, or applicable law prohibits that transfer.
The production backend must use an approved non-Korea Google Cloud region and the release must continue to exclude Korea on main. This product-targeting decision does not guarantee that every infrastructure subprocessor operates only in that region.
10. Security
Stlog uses local storage, macOS permission controls, excluded applications, secure-input detection, pattern-based redaction, HTTPS, short-lived challenge/session credentials, signed Apple material verification, HMAC pseudonyms, quota enforcement, least-privilege cloud identity, bounded content-free logging, and a service kill switch. No product or storage method is perfectly secure. Keep macOS updated, use device encryption and a strong login password, and review captured content before sending or exporting it.
11. Children
Stlog is a workplace productivity application and is not directed to children under 16. Do not use Stlog if you cannot legally agree to these practices in your jurisdiction.
12. Changes To This Policy
We may update this policy when Stlog's practices or legal requirements change. We will update the date above and provide additional notice when a change materially affects how data is handled.
13. Contact
- Data controller:
Jeonguk Hur - Country or region:
Republic of Korea - Email:
privacy@stlog.ai