Privacy Policy
Last updated 1 September 2026 · Glancet v0.2.1 (early beta)
Glancet is a desktop app that runs entirely on your Mac. It has no account system, no advertising and no third-party analytics. Two things are counted, both described in full below: how many copies of Glancet are running, and how many people install it. Neither stores anything on your machine, and neither can follow you from one day to the next. This policy explains every place where data does move, so you can check the claim rather than take our word for it.
WHO IS RESPONSIBLE
The data controller is Hlopin Artur, trading as Glancet, contactable at [email protected]. For anything about your data, that address reaches a person, not a queue.
Payments are a separate matter: Lemon Squeezy, LLC is the merchant of record and is the controller of your payment data. See purchases below.
THE APP
What it reads
Glancet builds its display from data already on your machine, written there by the coding agents you run:
- Session events — your agents' hooks post small JSON payloads (project path, git branch, state, elapsed time, the prompt you typed, the agent's closing message) to a server Glancet runs on
127.0.0.1:47615. This is a loopback address: the traffic never leaves your computer and is not routable from your network. The endpoint requires a token generated on your machine. - Local files — the session transcript your agent writes (to read the model name and the last assistant message) and
.git/HEAD(to read the branch name). - Your Claude credential — read from your local Keychain, only to check usage limits, and only if you leave that feature on.
What it does not read
Glancet never reads, indexes, uploads or transmits the contents of your source code. It sees file paths that your agent reports, not file contents.
What leaves your machine
Two provider requests, both optional and behind one switch. When usage display is enabled, Glancet asks Anthropic's own usage endpoint (api.anthropic.com/api/oauth/usage) how much of your Claude limit remains, authenticated with the token already stored on your Mac — and while a Claude Code session is actually running, those figures arrive from the session itself over the loopback server above, so the request is skipped. For Codex, Glancet starts Codex's own local app-server and asks it for the official rate-limit snapshot: Codex talks to OpenAI itself, and Glancet never reads, receives or stores a Codex token — it only checks that Codex's credentials file exists before asking. Turning the usage feature off in Settings stops both and stops Glancet reading the Claude credential at all — it is a privacy switch, not a display toggle.
Two other requests exist. Both are counted, not recorded:
- The update check. Once a day Glancet asks
glancet.io/appcast.xmlwhether a newer version exists, and always asks you before installing anything. It sends nothing beyond what any HTTP request carries — your IP address and a user-agent naming the app and its version. Settings → Updates switches it off, after which Glancet only checks when you click “Check for Updates…”. - One “+1” on first launch. The first time Glancet starts it sends a single request to
glancet.ioso installs can be counted. It carries the version number and nothing else: no device identifier, no account, no UUID, nothing that could be joined to any other request. Settings → Privacy switches it off, and it is sent at most once per install.
That is the complete list: the usage requests, the update check, and the one-time install count. No crash reporting, no third-party SDK, no advertising identifier, and nothing describing what you or your agents are doing. How we turn those into numbers is below.
Where settings live
Preferences and your recently-completed session history are stored locally in macOS user defaults under io.glancet.Glancet. Removing Glancet from Settings deletes them.
HOW WE COUNT
We want to know two things: roughly how many people run Glancet, and how many people who download it actually install it. Both are answered on our own server, from requests you were already making, without storing anything on your Mac.
Every request to any website carries an IP address and a user-agent. We combine those with a secret and with today's date, hash the result one way, and store only that 24-character hash. The raw IP address is never written down. Because the date is part of what is hashed, the same computer produces a completely unrelated hash tomorrow — so we can say “412 copies of Glancet ran today” and we genuinely cannot say whether any of them ran yesterday. That is a property of the design, not a promise about our behaviour. Hashes are deleted after 90 days; the daily totals they produce are kept.
The install count is separate and holds no hash at all — just a row saying an install happened on this date, of this version. There is nothing in it to join anything to. One consequence, so it is not a surprise: because it carries no identifier, reinstalling Glancet on the same Mac counts again. It counts installs, not people. The only IP-derived value involved is a daily-rotating hash used to stop someone running the counter up in a loop; it lives in its own table for seven days and is never joined to anything.
There are no cookies, no local storage, no fingerprinting script, and nothing here or in the app that follows you anywhere else — which is why there is no consent banner to click.
THIS WEBSITE
glancet.io is a static site. It sets no cookies, runs no client-side analytics script and has no login — nothing in your browser is read or written. Downloads are counted on our server, as described under how we count. Its typefaces are served from this site, not from Google. Two third parties are involved in serving it:
- Cloudflare — hosts this site and serves every request, so your IP address is visible to Cloudflare whenever you load a page. It is also the processor that performs the counting described above, on our behalf. See Cloudflare's privacy policy.
- Feedbakery — the public roadmap is embedded from
feedbakery.ioin an iframe. Anything you do inside that board is handled by Feedbakery under its own privacy policy.
PURCHASES
When Glancet is available for purchase, orders are processed by Lemon Squeezy, LLC, who acts as the merchant of record. That means Lemon Squeezy — not us — is the seller on your card statement, collects and remits any applicable sales tax or VAT, and handles your payment details. We never see or store your card number.
From a completed order we receive your email address and the country used for tax purposes, so we can deliver your licence key and provide support. We use that address to send your licence and to answer you when you write to us. We do not sell it, rent it, or add you to a marketing list without you asking. See Lemon Squeezy's privacy policy for how they handle payment data.
Once you enter a licence key, the app sends that key and a short label for your Mac — its name plus six characters of a one-way hash of its hardware identifier, so you can tell your Macs apart — to Lemon Squeezy to activate it, and about once a week afterwards to confirm the key is still valid. Nothing about your sessions travels with it. Moving the licence to a Mac while another Mac still holds it goes through our own server (api.glancet.io), which frees the other Mac's activation and keeps no record beyond its request log. A trial never contacts anyone.
YOUR RIGHTS
Because we hold so little, most requests are simple. Write to [email protected] and we will tell you exactly what we have against your email address, correct it, or delete it. For payment records held by Lemon Squeezy as merchant of record, contact them directly or ask us and we will pass it on.
CHANGES
If this policy changes materially — in particular if Glancet ever starts sending anything new over the network — we will update this page and the date at the top, and note it in the changelog.
Questions: [email protected]