Privacy Policy
Your code, prompts, and agent conversations stay on your Mac.
Overview
Kelios LLC ("we", "our", or "us") builds Fermata, a native macOS software factory. We are committed to protecting your privacy.
The short version: Your code, prompts, and agent conversations stay on your Mac. Fermata does not send them anywhere. If you turn on cloud sync to use a companion app, session records are mirrored to our servers, with message content encrypted on your Mac first; see Cloud Sync and the Mobile Companion below. The app does include opt-out crash reporting and anonymous usage analytics: Fermata asks about both the first time it runs, they default to on, and both can be toggled off any time in Settings under Privacy. Neither ever collects your code, prompts, file paths, or project names.
What Fermata Does
Fermata is a local desktop application that:
- Spawns Claude Code CLI processes as subprocesses on your machine
- Manages git worktrees and branches in your local repositories
- Saves session and piece data to local
.fermata/folders within your projects - Stores application preferences in
~/.fermata/settings.json
Crash Reporting and Usage Analytics
Fermata includes two forms of telemetry. The app asks about both the first time it runs; they are on by default and can be turned off any time in Settings under Privacy.
- Crash reporting (Sentry): scrubbed stack traces that help us fix crashes.
- Usage analytics (TelemetryDeck): anonymous counts that help us understand which features are used.
Neither ever collects your code, prompts, file paths, or project names. Crash reports are scrubbed stack traces, and usage analytics are anonymous counts. Both carry the same pseudonymous per-install identifier, so crash and usage data from one installation can be counted together, plus basic device information, described under Your Rights. Your code, prompts, and agent conversations stay on your Mac.
Separately from telemetry, the app contacts releases.fermata.run to check for updates. That request carries the app version and no install identifier.
Third-Party Services
Fermata interacts with the Claude Code CLI, which is developed and operated by Anthropic. When you use Fermata to run coding agents, your prompts and code are sent to Anthropic's API by the Claude CLI, not by Fermata. Please refer to Anthropic's Privacy Policy for details on how they handle your data.
Apart from the opt-out crash reporting (Sentry) and anonymous usage analytics (TelemetryDeck) described above, and cloud sync if you turn it on, Fermata does not add any data collection on top of what the Claude CLI already does. Neither telemetry service ever receives your code, prompts, file paths, or project names.
Cloud Sync and the Mobile Companion
Fermata offers an optional cloud sync service and iOS and Android companion apps that let you watch runs and answer approvals from your phone. This policy covers all three. Sync is off unless you turn it on and pair a device, and the companion apps are in a limited beta.
With sync on, Fermata mirrors your session and piece records to Firebase Firestore so your paired phone can read them. Pairing establishes an encryption key that exists only on your Mac and your phone; we never hold it. Not every field is encrypted, so here is the split.
- End-to-end encrypted on your Mac before upload: agent message text, spec and strategy documents, agent descriptions, review notes, and piece summaries and learnings.
- Stored in plaintext, because the push-notification service reads them to build a notification: the opening prompt of a session (its first 200 characters), a preview of the latest message, the piece name and description, and agent names.
- Routing metadata, stored in plaintext: session state, timestamps, token and cost totals, the project name and its path on your Mac (a path that usually contains your macOS account name), the git branch name, the model name, and the name of your Mac.
Fermata never uploads your repository. Code can appear inside an agent's messages, and that message text is encrypted before it leaves your Mac. The encryption depends on the key established at pairing, so the encrypted fields above are encrypted for as long as a device is paired.
Unpairing, in Settings under Mobile, destroys that key on your Mac and cuts your phone's access to the records. It does not delete what is already stored, and it does not by itself switch sync off: to stop new records being written, turn cloud sync off in Settings. To have stored records deleted from our servers, email privacy@fermata.run.
The Websites
fermata.run is a static site hosted on Firebase Hosting. It uses two analytics services:
- Cloudflare Web Analytics: cookieless, privacy-friendly traffic metrics. No personal data is collected.
- Google Analytics 4: event tracking (downloads, subscriptions) to help us improve the site. GA4 sets cookies and loads on every visit; the notice shown on your first visit is informational. You can block it with your browser's cookie controls or a content blocker.
The "Manage cookies" link in the footer re-shows that notice at any time.
docs.fermata.run is the documentation site. It is a separate host, served by our documentation platform, Mintlify. We run neither Google Analytics nor the Cloudflare beacon there and set no cookies of our own on it; Mintlify processes requests in order to serve the pages.
If you request a mobile beta invite or subscribe to updates, we collect your email address and the IP address of the request. The IP is used only to rate-limit signups and block abuse. Both are stored in Firebase Firestore and are never sold or shared with third parties. You can unsubscribe at any time by emailing privacy@fermata.run.
How Long We Keep Data
- Local data (projects, sessions, pieces, preferences): stays on your Mac until you delete it. We hold no copy.
- Subscriber email addresses: kept until you unsubscribe or ask us to delete them.
- Signup IP records: written when you submit the form and only consulted for one hour after the request, which is the rate-limit window. They are deleted with the rest of your data when you ask.
- Crash reports: held by Sentry under its retention policy and dropped when that window ends.
- Usage analytics: held by TelemetryDeck as aggregate counts against a pseudonymous install identifier, under its retention policy.
- Synced sessions and pieces: kept while sync is on, so a newly paired phone can show your history. Unpairing revokes your phone's access but does not delete what is stored; email us and we will delete it.
Service Providers
We use a small set of processors, and each one sees only what its job requires:
- Google (Firebase): hosting for fermata.run, the Firestore database behind the waitlist and cloud sync, and the functions that send push notifications. Google Analytics 4 also runs on fermata.run.
- Cloudflare: DNS, cookieless web analytics for fermata.run, and the storage the app download is served from.
- Sentry: crash reports from the macOS app.
- TelemetryDeck: anonymous usage analytics from the macOS app.
- Resend: the welcome and announcement emails we send to subscribers.
- Mintlify: hosting for docs.fermata.run.
Anthropic is not one of our processors. The Claude Code CLI talks to Anthropic under your own account and Anthropic's terms, as described above.
Your Rights
Your code, prompts, and project data live on your machine, so you control them directly: delete the files and they are gone.
Crash reports and usage analytics carry no name, email, or account, and never your code, prompts, file paths, or project names. They do carry a random identifier created on your Mac the first time the app runs and reused across launches, plus basic device information: device model, macOS version, screen size, timezone, and language. The same identifier appears in both crash reports and usage analytics, so data from one installation can be counted together across the two. It is pseudonymous rather than anonymous: we cannot tie it to you, but it does distinguish one installation from another.
To request access to, correction of, or deletion of any data we hold about you, email privacy@fermata.run. We respond within 30 days. For a waitlist signup or synced sessions, the email address you used is enough to find your records. For crash reports and usage analytics, tell us the approximate dates and we will locate and remove what we can.
Changes to This Policy
We may update this policy as Fermata evolves. Significant changes will be noted on this page with an updated date.
Contact
Questions? Email privacy@fermata.run.