1. Scope and controller
This notice covers the Choro landing pages, macOS application, Choro Remote iPhone application, coding-agent connections initiated through Choro, and optional Choro Remote relay. Studio designs are stored locally in your project; Choro does not create a hosted design profile. There are currently no Choro-hosted cloud-agent machines, advertising profiles, payment records, or Choro-operated automated decisions about individuals.
For website and relay information, Liran Gabai, who operates Choro under the Future Picnic brand, is the controller. Contact privacy@choro.dev. Information that remains only on your Mac is not received by the Choro operator.
Third-party tools and websites have their own privacy notices. This page describes Choro’s role, not everything a model provider, Git host, database, package registry, website host, or other service may do.
2. Plain-language summary
- Your project data is local by default. Choro reads and writes the files, settings, documents, Git state, and local service information needed for the features you use.
- Studio designs are local. Choro Studio stores designs in your project and does not require a Choro design account or hosted design service.
- You choose when a provider receives context. A coding-agent tool can send prompts, files, diffs, or other selected context to its provider under your account and that provider’s terms.
- Remote access is optional and encrypted by the application. The relay routes opaque ciphertext and keeps active room state in memory rather than a database.
- The launch site has no signup. There is no waitlist or Choro account form.
- No Choro product telemetry is currently built in. Choro does not operate behavioural analytics or automatic crash reporting in the desktop application.
3. Current data map
This table distinguishes information that stays on the user’s device from information received by a Choro-operated site or relay. Hashing or encrypting an identifier does not automatically make it anonymous if it can still be linked to a device, room, or connection.
| Context and data | Purpose and destination | Current retention |
|---|---|---|
| Website requests: IP address, user agent, time, requested page, and error or security logs. | Deliver and protect the site. Received by the production web host; Google Fonts and jsDelivr receive requests for externally loaded assets. | Choro-controlled website logs are retained for no more than 30 days unless longer retention is required for a documented security incident or legal obligation. External providers apply their own retention terms. |
| Website analytics, only with consent: page visits, interactions, browser and device information, referrers, and cookie identifiers. | Understand and improve the public website through Google Analytics. Google processes this information for analytics; the site’s tag disables Google Signals and advertising personalization. | User and event data retention is set to 2 months; the user-data period can restart with new activity. Aggregated reports are not subject to this setting. Your browser stores your consent choice for 180 days. |
| Local workspace data: project paths and files, documents, Git state, agent conversations, attachments, terminal and task metadata, and preferences. | Provide the desktop features the user requests. Stored on the Mac and sent elsewhere only when the user or a connected tool initiates an external action. | Until the user deletes the relevant Choro data, project data, or Mac storage. |
| Local connection data: database connection URIs and issue-tracker account details and API tokens. | Connect from the Mac to services selected by the user. These values are currently stored in Choro’s local application database; provider CLIs keep their own credentials separately. | Until the connection or local Choro data is deleted. Provider CLI retention is controlled by that provider tool. |
| Studio designs: project-local screens, assets, tokens, prototypes, and related metadata. | Create, edit, and export designs in the selected project on your Mac. Choro does not operate a hosted design account for the launch product. | Until you delete the relevant project files or local Choro data. Your own backups or Git history may retain copies. |
| Agent-provider content: prompts, selected files or diffs, command output, attachments, identifiers, and feedback. | Sent through the local agent tool to the provider selected by the user. | Controlled by the user’s provider plan, settings, and contract. |
| Choro Remote phone data: paired-Mac connection details, device credentials, message drafts, selected images, preferences, and local demo content. | Credentials are stored in the iOS Keychain; drafts, copied attachments, preferences and demo state are stored in the app’s private storage. In real use, submitted requests and images travel encrypted to the paired Mac, where the selected agent tool may send them and relevant project context to its AI provider. | Local data remains until it is replaced, cleared or removed with the app’s data. Unpairing removes the saved connection credentials; it does not erase past conversations on the Mac, provider records, or every local draft and copied image. |
| Remote data: room public-key identifier, role and purpose, ephemeral client identifiers, admission-token hashes, timing and connection state, ciphertext, and network metadata. | Authenticate, route, secure, and operate optional Remote connections. The relay operator and infrastructure host receive this information; plaintext remains at the endpoints by design. | Active relay room and token-hash state is in memory for the connection. Choro-controlled relay logs are retained for no more than 30 days unless needed for a documented security incident or legal obligation. Paired-device authorisation records on the Mac expire after 90 days unless renewed or removed sooner. |
4. Website data
The launch site currently displays a disabled "Coming soon" button in place of an installer download. It has no waitlist or Choro account form.
If you allow analytics, the landing site uses Google Analytics 4 to measure visits and interactions, including page views, scrolls, outbound links, and file downloads. Google receives browser and device information, page addresses, referrers, and cookie identifiers to provide these reports. The site has no Choro account form, advertising pixel, or payment flow. The web host may process ordinary request information such as IP address, time, requested page, user agent, and error logs to deliver and protect the site.
Help, roadmap, feature requests, and feedback and support tickets open Choro’s separate Usergist site. The desktop app does not submit feedback or attachments to Usergist automatically. If you choose to sign in or submit something there, Usergist handles that page and Choro can review the information you submit.
The landing pages request fonts from Google Fonts, and the main landing page requests the Tabler icon stylesheet from jsDelivr. Those providers receive network request information such as your IP address and user agent under their own privacy terms. A future build should self-host these assets if eliminating those requests is a release requirement.
5. Data on your Mac
Depending on the features you use, Choro can process project paths and files, documents, agent conversations and attachments, workspace configuration, Git information, terminal output, database connection URIs, local-service metadata, issue-tracker account details and API tokens, and application preferences.
This information is stored on or accessed from your Mac unless you direct Choro or a connected tool to send it elsewhere. Choro needs operating-system and project permissions appropriate to the files and commands you choose. Removing the application does not automatically delete every project file or every record maintained by a third-party CLI.
Database connection URIs and issue-tracker tokens are currently stored in Choro’s local application database and should be treated as sensitive local data. Remote transport keys are stored in the macOS Keychain; paired-device metadata and token hashes are stored in a private local file. Choro does not ask for your model-provider password. Provider CLIs and other installed tools maintain their own authentication material independently of Choro. Review each tool’s storage and sign-out controls.
6. Coding agents and other providers
When you use a coding agent, Choro routes the conversation through the local agent tool you selected. That tool may send prompts, repository context, command output, attachments, identifiers, and feedback to its provider. The provider decides how it processes and retains that data under your provider account, settings, plan, and contract.
If you ask an agent to inspect or implement a Studio design, Choro may include the relevant project-local design context in that agent interaction. The selected coding-agent provider may then receive that context under its own terms.
The same principle applies when you connect Git hosting, issue trackers, databases, deployment platforms, or other services: data you request may travel directly from your computer to that service. Choro does not turn a personal provider subscription into a Choro subscription and does not resell model usage.
7. Local Studio designs
Choro Studio saves design files and assets in the selected project on your Mac. The launch application does not offer Penpot or provision a Choro-hosted design account. You control the project files and any copies you make through Git, backups, exports, or other tools.
Using an agent to work on a design can send selected design content to that agent’s provider, as described above. Choro itself does not receive those local design files unless you separately send them to us, such as in a support request.
8. Optional Choro Remote relay
Remote access connects an authorised device to your running Choro Desktop instance. The relay receives a room identifier derived from the Desktop public key, connection role and purpose, ephemeral client identifiers, hashed admission tokens, timing and connection state, and application-encrypted message envelopes.
The relay is designed not to receive plaintext agent messages, repository contents, commands, device bearer tokens, transport keys, or the Desktop private key. A client sends its admission token to the relay for authentication; the relay hashes it before comparing it with the hashes advertised by the Desktop. Active rooms and token hashes are held in memory, with no relay database, and are removed when the Desktop disconnects or the relay restarts. The relay host may still process network metadata such as IP addresses, TLS connection details, message sizes and timing, and operational logs.
Remote access is off unless you configure and enable it. You can close pairing, revoke a paired device, disconnect the Desktop, or stop using the relay.
Choro Remote on iPhone
The phone app does not require a Choro account or a model-provider password. It stores its paired-device credentials in the iOS Keychain. Connection details, drafts, preferences, copied image attachments and local sample-workspace data are stored in the app’s private storage. The app reads images you select through the system photo picker; it does not upload your photo library automatically.
In real use, messages and selected images are sent to your paired Mac through the encrypted relay. The Mac can then send those messages, images, relevant files, diffs and command output to the AI provider configured for that agent, such as OpenAI for Codex, Anthropic for Claude, or the provider you configure through OpenCode. That provider processes the information under your own account, plan, settings and its privacy terms. End-to-end encryption protects the phone-to-Mac connection; it does not prevent the provider you ask to perform a task from receiving task context.
The local demo is labeled as simulated. It uses synthetic projects and scripted responses, keeps typed messages and attached images on the phone, and does not connect to the relay, a Mac or an AI provider. Reset replaces the active sample workspace; leaving the demo retains that workspace for a later visit. Reset and leaving do not erase every previously copied image or old draft from the app’s private storage. Opening an external link, including this policy, sends an ordinary web request through your browser.
9. Analytics, crash reporting, and cookies
The website loads Google Analytics only after you select “Allow analytics.” Selecting “Reject analytics” keeps it off. You can change or withdraw your choice using “Analytics preferences” in the footer of any main site page. Withdrawing consent stops collection and clears the site’s Google Analytics cookies; it does not erase data already collected.
We store your choice in your browser for 180 days. After acceptance, Google Analytics uses first-party _ga cookies configured with a 180-day expiry, which can be renewed during later visits. We disable Google Signals and advertising personalization in the site’s tag. See Google’s Privacy Policy for how Google handles information.
The desktop and iPhone applications do not include Choro-operated product analytics, advertising SDKs or automatic crash telemetry. Apple may collect diagnostics under your device and App Store settings. Hosting infrastructure and externally loaded assets can still create ordinary server logs or use their own network-level controls. A project opened in Choro may contain its own analytics SDKs, and third-party CLIs may collect diagnostic or usage information under their own settings.
11. Retention
Local Choro data remains until you delete it through the application, remove the relevant local files, clear the associated application-support data, or erase your Mac. Repository and document history may also exist in backups, Git history, or tools you configured.
The relay keeps active room and admission state only in memory for the connection’s lifetime. Paired-device authorisation records on the Mac expire after 90 days, subject to earlier revocation or deletion. Choro-controlled website and relay request or security logs are retained for no more than 30 days unless a longer period is necessary for a documented security incident, legal claim, or legal obligation. Infrastructure providers may apply shorter operational retention periods.
12. Your choices and privacy rights
You can choose which projects and providers to use, avoid remote access, revoke paired devices, sign out through provider tools, and delete local Choro data. Because most desktop data is not sent to Choro, requests about that local data are normally handled directly on your Mac.
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information held by Choro, withdraw consent where processing relies on consent, and complain to a data-protection authority. Choro does not use website or relay data to make decisions about people solely by automated means.
Submit a request to privacy@choro.dev. Choro may request information reasonably necessary to verify your identity and protect other users. Requests will be answered within the period required by applicable law, ordinarily within 30 days.
13. Children
Choro is a professional developer tool and is not directed to children under 16. Do not use Choro to submit a child’s personal information without a lawful basis and appropriate parent or guardian authorisation.
14. Changes and contact
This notice will change when Choro’s data flows change. Material updates will be dated here and, where practical, included with release notes or shown before a new data-using feature is enabled.
For questions, complaints, or rights requests, contact privacy@choro.dev. Legal notices may also be sent to legal@choro.dev.