privacy

What stays on your Mac.

saferow has no telemetry and no account, and nothing about you or your databases is sent to saferow. This page says exactly what the website logs, what the app keeps and where, the only hosts it talks to, and what buying involves.

Last changed 1 October 2026, before the public beta. This page changes together with the app and the server it describes.

This website

saferow.app and dl.saferow.app are served by Caddy on a server of the seller’s own. Caddy writes every request to an access log: the time, your IP address, the address you asked for, and the request’s headers, such as your browser’s user agent and the page that linked here. Cookies and authorization headers are not logged.

The log is closed and a new one started every day at 00:00 UTC, and whenever it reaches 10 MiB. Closed logs are deleted 7 days after they close, so a line is on disk for at most about 8 days. It is used to keep the site and the update feed running and to spot abuse, and it is never shared or sold.

  • No cookies are set by any page of this site.
  • No analytics: no tracking script, pixel or third-party service, on any page.
  • No third-party requests on the public pages. The fonts and images are served from saferow.app itself.
  • One exception, /buy/: the checkout page loads Paddle.js from cdn.paddle.com and Paddle’s checkout in a frame, only when you go there to buy. Inside it, Paddle’s privacy notice applies, and Paddle may use cookies of its own.

The app

saferow works on your Mac. Your connections, queries and data stay there:

  • Passwords for your databases, ssh keys’ passphrases and AI provider keys go to the macOS Keychain, and are read only by the app’s main process.
  • Everything else saferow keeps is in its folder, ~/Library/Application Support/saferow: your connections (hosts and user names, never passwords), settings, conversations, query history, memory, saved questions, watches, the ledger, and Rewind’s restore points.
  • Restore points are copies of the rows a write changed, saved before it ran so Rewind can put them back. They are kept for 7 days on the free tier and 30 days with Pro, then deleted. Query history older than 180 days is deleted too.
  • “Your month”, the summary in Mission control, is counted on your Mac and never sent anywhere.
  • No telemetry: no analytics, no usage pings, no crash reporter sending anything, no advertising identifier.

Uninstalling: delete the app, the folder above, and the items named “saferow” in Keychain Access.

The only hosts the app talks to

On its own, the app connects to these and nothing else. Your databases are reached only when you connect to them, over your own ssh where you set it up.

Every host, and what goes there
HostWhenWhat it receives
saferow.appLicense activation, once per MacYour license and a one-way id for this Mac; details below
dl.saferow.appUpdate checks and update downloadsA request for the update feed or the update file. No account, nothing about your databases.
huggingface.coModel downloads you startA request for the model file
openrouter.aiOnly when you choose an OpenRouter modelWhat the agent sends that model; see below
api.anthropic.comOnly when you choose a Claude modelThe same, under your own key
api.openai.comOnly when you choose an OpenAI modelThe same, under your own key
127.0.0.1Ollama and LM Studio on this MacStays on the Mac

Remote models

With a local model, your questions, schema and rows never leave the Mac. When you choose a remote model, the agent sends that provider what it needs to answer: your question, the parts of the schema it is working with, and rows it reads. Every turn shows how many bytes left the Mac.

  • The request goes under your own account (OpenRouter) or key (Anthropic, OpenAI), and that provider’s terms and privacy policy apply. saferow sees none of it and resells nothing.
  • For columns saferow recognizes as personal data, you can send the schema only, or mask those columns, before anything leaves the Mac.
  • A connection can be locked to local models; the kernel then refuses to send its rows to any model off the Mac.

License activation

The free tier needs no license. When you activate a paid license on a Mac, the app sends saferow.app, once:

  • the license itself, which carries its id, its plan and the email address it was bought with;
  • a machine id: a one-way hash made on your Mac, which can’t be turned back into anything about it, and is never the serial number;
  • the Mac’s name, so a list of your Macs makes sense when you deactivate one.

The server keeps the Macs a license is active on, with when each was first and last activated, to enforce the 3-Mac limit. Deactivating a Mac in Settings › License tells the server. The license itself is checked offline, by its signature, every time the app starts; if saferow.app can’t be reached, the license works anyway.

Buying

Licenses are sold by Paddle.com, the merchant of record. Paddle collects your payment details, billing country and address, and processes them under its own privacy notice; the seller never sees your card.

When a purchase completes, Paddle tells saferow’s license server, which keeps: your email address, Paddle’s transaction and customer ids, the plan, the number of seats, the license it issued, and when it was issued, emailed, refunded or revoked. The license is emailed to you through an email delivery service. These records are kept for as long as the license exists, so it can be activated, recovered or refunded.

Questions and requests

saferow is made and sold by Deokwon Song, a sole proprietor in the Republic of Korea, who is responsible for this site and the license server. To ask what is held about you, or to have your license records corrected or deleted, write to support@saferow.app. Deleting them ends the ability to recover or move that license.