Legal

Privacy policy

PRCHD has no profile for core use. Your work stays on the computer you installed it on; the optional notification path carries names and outcomes, never the work itself.

Last updated August 31, 2026

No profile for core use

You can install the Mac host, pair a phone, and use the direct phone-to-Mac connection without creating a PRCHD profile. Pairing happens between devices you control. We do not receive the pairing code, device token, repository list, or device relationship.

Connecting a Mac to the optional notification service uses one email address and a one-time code. There is no password or profile. That exception is described below.

Your work stays on your Mac

Source code, prompts, messages, attachments, file contents, diffs, commands, process output, file paths, environment values, trigger payloads, and durable event history stay on the Mac running the host. A paired phone reads them over your tailnet. Velzosoft does not collect or store that data. If you opt into push, a notification names the project and workspace it concerns; that path is described below.

The PRCHD service

Your phone talks to your Mac directly over your own Tailscale network. Repositories, worktrees, prompts, transcripts, diffs, command output, and attachments stay on your Mac.

There is one PRCHD service. It enrolls your Mac’s identity and forwards short notification requests to Apple and Google. It is not a relay for app traffic and never sees source code. It stores no project, workspace, chat, event, prompt, or notification body.

A push notification names the project and workspace so you know what needs you — like “Agent turn finished · prchd · fix-login-flow”. Beyond those names, payloads carry fixed event values and opaque routing ids — never code, prompts, paths, diffs, command output, or agent prose. Connecting a Mac stores one email address for the sign-in code and new-Mac notice. A Mac you never connect sends the service nothing.

The service stores the connected Mac identity, the email address used for its sign-in code and new-Mac notice, and notification routing data; no notification body is stored. The phone’s push token is sent only to paired Macs and encrypted with a Keychain-backed key before it reaches the service.

A notification request carries a short message naming the event, the project, and the workspace — like “Agent turn finished · prchd · fix-login-flow” — plus a fixed event kind and outcome, opaque routing ids, and a host-key digest. It contains no source, prompt, chat, path, diff, command output, error text, or agent prose, and the service stores none of it.

The Slack surface

A host can be connected to a Slack workspace so a bound channel can ask questions about a project or start a recipe against it. The Slack app is your own custom app, installed into your Slack workspace from a published manifest with tokens you hold. Velzosoft does not operate it, does not receive its tokens, and is not a processor for it. Your relationship with Slack is governed by Slack’s own terms and privacy policy.

The connection is outbound only. The host opens no inbound port for it, and nothing about a Slack interaction reaches the PRCHD service.

An answer posted into a channel may quote code from the bound project. That is an export from the machine into your Slack workspace, and it is why binding a channel is an action taken at the machine by the operator rather than from inside Slack. The operator decides which channels are bound, whether a channel may run recipes, and whether its activity is visible to paired phones at all.

Every Slack interaction is recorded on the host as a content-free event naming the Slack workspace, the channel, the asker’s Slack id, and where relevant the thread’s permalink — question received, run requested, refused with a reason, reply posted, reply failed. The message text is not part of that record.

Webhook triggers

A trigger gives an external service a URL on the PRCHD service that starts a stored recipe on your machine. The service seals every delivery to your machine’s public key on arrival using ECIES over P-256 and stores only ciphertext. It cannot read what a payload says, which trigger it fires, or what the run produced; the private half of that key never leaves your machine’s Keychain.

Your machine collects deliveries by polling outbound. A sealed payload is deleted as its run starts, so a third party’s data does not outlive its use. A delivery that fails is held as a dead letter and stays replayable by hand for seven days; rejection diagnostics are kept for one day and carry no body.

Hosts with no paired phone

A host with no paired device sends no push notification at all — its notification path is the Slack thread the work was asked in. On such a host the notification service is never enrolled, so nothing in the notification sections above applies to it, and no email address is stored.

Crash and diagnostic processing

Packaged builds can send crash reports, performance diagnostics, and allow-listed product metrics tied to synthetic installation and device ids. Dynamic source content is never a metric dimension. Mobile session replay is captured only on errors, with text and images masked.

Sentry processes crash reports and performance diagnostics on our behalf. For its current handling practices, read Sentry’s privacy policy.

Resend processes the sign-in code and new-Mac alert emails, if you turn on push notifications on our behalf. For its current handling practices, read Resend’s privacy policy.

We do not sell personal data, use it for advertising, or use it to track you across apps or websites.

This website

prchd.app uses Google Analytics to understand how the marketing site is used. It records page views, the path from one page to the next, time spent on each page, referrers, scroll depth, FAQ opens, and clicks on the Mac download and store links. Advertising features and Google Signals are off. A first-party cookie identifies a browser across visits to this site; it is not used to track you across other apps or websites.

Google Analytics processes page views, time on page, the path between pages, and clicks on download and store links on this website on our behalf. For its current handling practices, read Google Analytics’s privacy policy.

Device permissions

  • Camera — scans the pairing QR shown by your Mac; no image is retained
  • Photos and files — sends only attachments you select to your paired Mac
  • Face ID, Touch ID, or biometrics — unlocks the optional app lock on-device
  • Notifications — shows a short message naming the event, project, and workspace for events you opt into
  • Local network — reaches the Mac over your tailnet where required by the platform

Credentials for other services

Claude Code, Codex, and Grok authentication belongs to those CLIs on your Mac. GitHub actions use the gh CLI on the Mac. Tailscale manages the network identity. PRCHD receives no password, token, or agent credential for those services.

Company and contact

PRCHD is published by Velzosoft. Questions and privacy requests go to hello@prchd.app.

Deletion requests

Email hello@prchd.app from the address used to connect a Mac when you want the notification-service record deleted. Include enough information to identify the connected Mac record. You can remove local repositories, workspaces, transcripts, and device relationships directly from your own devices because we do not hold them.

Children

PRCHD is a developer tool intended for adults and is not directed to children. We do not knowingly collect personal data from children.

Changes

The updated date at the top changes when this policy changes materially. The revision is also noted in the release history.

Continue

Read the pairing, token, Keychain, and listener mechanisms →