Privacy policy
Last updated 24 August 2026
The short version
Braveli runs entirely on your Mac. Your code, your prompts, your terminal output and your agents' work are never sent to us — there is no server for them to be sent to. The only thing that leaves your machine is a small set of anonymous counts, and you can turn those off.
This policy explains that in detail. It applies to the Braveli application and to braveli.app.
What is collected
Anonymous usage counts. If you leave usage reporting enabled, Braveli records a small, fixed set of events — things like the application launching or a session being started. Each event carries only a random identifier generated on your machine, the application version, and your macOS version.
The set of events and the set of properties are both fixed lists in the source code. Anything not on those lists cannot be sent, by construction rather than by policy.
You can turn this off at any time in Braveli's settings, and during first-run setup. Turning it off stops all reporting.
Website analytics. braveli.app is a static site. It sets no cookies and runs no third-party trackers.
What is never collected
None of the following ever leaves your machine:
- Your source code, or any file contents
- File names, directory names or repository paths
- Prompts you write, or anything an agent writes back
- Terminal output
- Task titles, ticket identifiers or issue-tracker content
- Credentials, tokens or API keys of any kind
This is not a promise about how we handle such data. There is no hosted Braveli service, so there is nowhere for it to go.
What stays on your Mac
Projects, tasks, sessions, transcripts, Council threads and settings are stored locally in Braveli's application-support directory. They are yours; deleting the application and that directory removes them.
Credentials are held in macOS's own secure storage. GitHub accounts and tokens are encrypted per project using Electron safe storage, which is backed by your Keychain. Where an agent CLI authenticates against a remote service over MCP, its tokens remain in that CLI's own credential store — Braveli keeps only the server alias and how to launch it.
The agent command-line tools Braveli runs are third-party software with their own privacy policies and their own network access. Braveli launches them on your behalf; what they send, and to whom, is governed by their terms and your account with them.
Who else is involved
Three services, each doing one thing:
- PostHog — receives the anonymous usage counts described above, if enabled.
- Paddle — handles payment and subscription management. When you subscribe, Paddle acts as the merchant of record and collects the billing information necessary to take payment. We do not see or store your card details.
- Cloudflare — hosts this website and serves application downloads, and processes the standard request logs any web host produces.
If you email [email protected], that message is delivered to a personal mailbox and kept only as long as needed to answer you.
Your rights
Because usage counts are anonymous and carry a randomly generated identifier rather than anything identifying you, we generally cannot connect them to a person — which also means we usually cannot locate "your" data on request. The reliable way to stop collection is to turn usage reporting off, which takes effect immediately.
For billing information, Paddle is the data controller and their privacy policy governs. Requests about payment data should go to them, or to us and we will pass them on.
If you are in the UK, EU or another jurisdiction granting rights of access, correction, deletion or portability, write to [email protected] and we will do what we can.
Changes
If this policy changes materially, the updated version will be published here with a new date, and the change will be noted in the changelog.
Contact
Braveli is made by Nika Guladishvili, an individual trading from Georgia. Questions about this policy: [email protected].