privacy
What stays on your Mac.
saferow has no telemetry and no account, and nothing about you or your databases is sent to saferow. This page says exactly what the website logs, what the app keeps and where, the only hosts it talks to, and what buying involves.
Last changed 1 October 2026, before the public beta. This page changes together with the app and the server it describes.
This website
saferow.app and dl.saferow.app are served by Caddy on a server of the seller’s own. Caddy writes every request to an access log: the time, your IP address, the address you asked for, and the request’s headers, such as your browser’s user agent and the page that linked here. Cookies and authorization headers are not logged.
The log is closed and a new one started every day at 00:00 UTC, and whenever it reaches 10 MiB. Closed logs are deleted 7 days after they close, so a line is on disk for at most about 8 days. It is used to keep the site and the update feed running and to spot abuse, and it is never shared or sold.
- No cookies are set by any page of this site.
- No analytics: no tracking script, pixel or third-party service, on any page.
- No third-party requests on the public pages. The fonts and images are served from saferow.app itself.
- One exception, /buy/: the checkout page loads Paddle.js from cdn.paddle.com and Paddle’s checkout in a frame, only when you go there to buy. Inside it, Paddle’s privacy notice applies, and Paddle may use cookies of its own.
The app
saferow works on your Mac. Your connections, queries and data stay there:
- Passwords for your databases, ssh keys’ passphrases and AI provider keys go to the macOS Keychain, and are read only by the app’s main process.
- Everything else saferow keeps is in its folder,
~/Library/Application Support/saferow: your connections (hosts and user names, never passwords), settings, conversations, query history, memory, saved questions, watches, the ledger, and Rewind’s restore points. - Restore points are copies of the rows a write changed, saved before it ran so Rewind can put them back. They are kept for 7 days on the free tier and 30 days with Pro, then deleted. Query history older than 180 days is deleted too.
- “Your month”, the summary in Mission control, is counted on your Mac and never sent anywhere.
- No telemetry: no analytics, no usage pings, no crash reporter sending anything, no advertising identifier.
Uninstalling: delete the app, the folder above, and the items named “saferow” in Keychain Access.
The only hosts the app talks to
On its own, the app connects to these and nothing else. Your databases are reached only when you connect to them, over your own ssh where you set it up.
| Host | When | What it receives |
|---|---|---|
saferow.app | License activation, once per Mac | Your license and a one-way id for this Mac; details below |
dl.saferow.app | Update checks and update downloads | A request for the update feed or the update file. No account, nothing about your databases. |
huggingface.co | Model downloads you start | A request for the model file |
openrouter.ai | Only when you choose an OpenRouter model | What the agent sends that model; see below |
api.anthropic.com | Only when you choose a Claude model | The same, under your own key |
api.openai.com | Only when you choose an OpenAI model | The same, under your own key |
127.0.0.1 | Ollama and LM Studio on this Mac | Stays on the Mac |
Remote models
With a local model, your questions, schema and rows never leave the Mac. When you choose a remote model, the agent sends that provider what it needs to answer: your question, the parts of the schema it is working with, and rows it reads. Every turn shows how many bytes left the Mac.
- The request goes under your own account (OpenRouter) or key (Anthropic, OpenAI), and that provider’s terms and privacy policy apply. saferow sees none of it and resells nothing.
- For columns saferow recognizes as personal data, you can send the schema only, or mask those columns, before anything leaves the Mac.
- A connection can be locked to local models; the kernel then refuses to send its rows to any model off the Mac.
License activation
The free tier needs no license. When you activate a paid license on a Mac, the app sends saferow.app, once:
- the license itself, which carries its id, its plan and the email address it was bought with;
- a machine id: a one-way hash made on your Mac, which can’t be turned back into anything about it, and is never the serial number;
- the Mac’s name, so a list of your Macs makes sense when you deactivate one.
The server keeps the Macs a license is active on, with when each was first and last activated, to enforce the 3-Mac limit. Deactivating a Mac in Settings › License tells the server. The license itself is checked offline, by its signature, every time the app starts; if saferow.app can’t be reached, the license works anyway.
Buying
Licenses are sold by Paddle.com, the merchant of record. Paddle collects your payment details, billing country and address, and processes them under its own privacy notice; the seller never sees your card.
When a purchase completes, Paddle tells saferow’s license server, which keeps: your email address, Paddle’s transaction and customer ids, the plan, the number of seats, the license it issued, and when it was issued, emailed, refunded or revoked. The license is emailed to you through an email delivery service. These records are kept for as long as the license exists, so it can be activated, recovered or refunded.
Questions and requests
saferow is made and sold by Deokwon Song, a sole proprietor in the Republic of Korea, who is responsible for this site and the license server. To ask what is held about you, or to have your license records corrected or deleted, write to support@saferow.app. Deleting them ends the ability to recover or move that license.