Privacy Policy
How PinVari handles your data. Effective August 18, 2026.
PinVari is a macOS app that lets you circle a region of your screen, speak, and turn what you captured into a filed issue. This policy explains exactly what data PinVari touches, where it lives, and when — if ever — anything leaves your Mac. We have written it in plain language because the honest answer here is genuinely simple: the sensitive stuff stays on your machine.
Who we are
PinVari is built and operated by KAK Digital LLC, a company registered in Wyoming, United States, selling to developers and teams worldwide. In this policy, "we", "us", "PinVari" mean KAK Digital LLC. You can reach us any time at [email protected].
The short version
- Your screen captures, circled-region screenshots, and voice recordings are processed and stored locally on your Mac. They are not uploaded to PinVari.
- Speech is transcribed on-device by default using Apple's built-in speech engine.
- Cloud services (Deepgram for speech, OpenRouter for classification) are off unless you add your own API key in Settings — out of the box, with no key, every step runs on your Mac.
- A capture only leaves your Mac when you route it — to your AI coding agent or to a tracker you connected (Linear, GitHub, or Slack).
- Your account details (email, license key, usage counts) live in our database so we can issue your licence and run your account. We never sell your data and we never show you ads.
What stays entirely on your Mac
The PinVari app runs a small local service on your own computer (on port 3402). Everything below is written to your Mac only — to a folder at ~/PinvariCaptures and a local SQLite database — and is never transmitted to PinVari:
- Screenshots of the region you circled (and, depending on your capture, the surrounding screen).
- Voice recordings (the audio you speak while capturing).
- Transcripts of that audio.
- Captured context such as the app name, window title, and — for browser captures — the page URL and title, plus the resolved on-screen UI element.
- Your integration tokens — the Linear API key, GitHub token, or Slack webhook you enter to connect a tracker. These are stored by the local service on your Mac and are never sent to PinVari or returned by our servers.
You can open, review, or delete these files yourself at any time. Deleting a capture in the app, or removing the files in ~/PinvariCaptures, removes it from your Mac.
Focus Privacy
If you turn on "Focus privacy — blur everything except what I circled", the blur is applied on-device before the screenshot is stored anywhere, so the parts of the screen you did not circle are never written to disk in clear form.
When something can leave your Mac
1. Speech transcription (on-device by default)
By default, PinVari transcribes your voice using Apple's on-device speech engine (SpeechAnalyzer on macOS 26, or an on-device SFSpeechRecognizer fallback). This happens on your Mac and your audio is not sent anywhere.
Cloud transcription is opt-in. It happens only if you paste your own Deepgram API key into Settings — in which case the audio is sent to Deepgram (using your key, billed to you) to produce a transcript. If you have not added a key, which is the default, audio is never sent to Deepgram and PinVari uses the on-device result. Turning on "Run fully on-device" keeps everything local even if a key is present.
2. Issue classification
Labelling a capture (its title, type, severity, and area) can use a cloud model through OpenRouter, but only if you paste your own OpenRouter API key into Settings. When you do, PinVari sends the circled-region screenshot (as an image) together with its text context to OpenRouter — using your key, billed to you — to generate the classification. With no key, or with "Run fully on-device" enabled, this step stays on your Mac and nothing is sent to OpenRouter.
3. Routing a capture (only on your explicit action)
When you choose to route a capture, its context leaves your Mac only because you asked it to, and only to the destination you picked:
- To your AI coding agent over a local agent connector (MCP) running on your own machine.
- To a tracker you connected — Linear, GitHub, or Slack — using the token or webhook you entered. That request goes directly from your Mac to that provider, using your credentials. PinVari does not sit in the middle and does not receive a copy.
What those third parties then do with the data is governed by their own privacy policies (see Deepgram, OpenRouter, and the tracker you chose).
Account data we do hold
To sell and run PinVari, we keep a small amount of account and product data on our own infrastructure (the Supabase platform, and Resend for email):
- Your email address, used to sign you in and to send your license key and account email.
- Your license key (a code like
PV-XXXX) and licence status. - Usage counts and product events — high-level counters (for example, how many captures you have made) used for your usage display and to operate plan limits. These are counts and events, not the contents of your captures.
- Contact-form messages — if you write to us through the website, your name, email, message, and the page you were on are stored so we can reply, and are emailed to us via Resend.
- Device details at licence activation — to bind your licence to your device and enforce seat limits, your Mac sends us your license key, a hashed device identifier, your computer's name (which often contains your own name, for example "Alex's MacBook Pro"), and your platform ("macOS"). This happens when you activate a key and again about once a day while the app is licensed. We use it only for licensing — never for advertising or profiling.
We do not receive, store, or have any access to your screenshots, audio, transcripts, or tracker tokens through this account data.
The website and advertising measurement
This is about pinvari.com only — never the app. Like most websites, we measure how our marketing performs:
- Google Analytics counts page visits and checkout steps so we can see what works.
- The Reddit Pixel and Reddit Conversions API tell us when a visit or purchase came from a Reddit ad, so we don't waste money on ads that don't work. When we send Reddit a purchase from our server, your email is hashed (SHA-256) first — Reddit never receives your raw email from us. You can control ad cookies through the cookie banner and your browser settings.
None of this touches what happens inside the app. Your captures, voice, and screen never reach these tools.
What we never do
- We do not sell or rent your personal data to anyone.
- We do not show ads or use your data for advertising.
- We do not upload your captures, voice, or screen contents to PinVari servers.
How long we keep data
- On your Mac: captures stay until you delete them. You are in control of that folder and database.
- Account data: kept for as long as you have an account, and for a reasonable period afterward to meet legal, tax, and accounting obligations. When no longer needed, it is deleted or anonymized.
- Contact messages: kept as long as needed to handle your query and our records of it.
Your rights
Depending on where you live — including under the EU/UK GDPR and the California Consumer Privacy Act (CCPA) — you may have the right to access the personal data we hold about you, correct it, delete it, export it, object to or restrict certain processing, and withdraw consent. California residents have the right not to receive discriminatory treatment for exercising these rights; we do not sell personal information, so there is nothing to opt out of on that front.
Because your captures live on your own Mac, you can already access and delete those yourself. For the account data we hold, email [email protected] and we will action your request. We may need to verify your identity first.
International transfers
We are registered in Wyoming, United States, and the platforms we use (Supabase, Resend, and — only in the fallback cases above — Deepgram and OpenRouter) may process data in the United States and other countries. Where required, we rely on appropriate safeguards for these transfers.
Children
PinVari is a developer tool intended for adults and is not directed at children under 16. We do not knowingly collect data from children.
Changes to this policy
If we change this policy we will update the effective date above and, for material changes, let account holders know by email. Continuing to use PinVari after a change means you accept the updated policy.
Contact
Questions, requests, or concerns about privacy: [email protected].