Legal
Privacy Policy
NapCat is built around a simple boundary: your agent work belongs on your Mac. This policy explains the few cases where information leaves it.
Effective August 27, 2026
Who this policy covers
This policy applies to the NapCat Mac app, napcat.app, purchases, license delivery, and support. NapCat is an independent product operated by Huzaifa Saleem, who is the controller of the personal data described here. For privacy questions or requests, email hi@napcat.app.
What stays on your Mac
NapCat reads the local process list and the local session files that supported agent tools already create. It stores your settings and Activity history locally. Prompt text, responses, project names, file paths, and session content are not sent to NapCat’s servers.
You can keep local Activity history for 90 days, 180 days, one year, or two years, and clear it from the app. Removing the app does not automatically remove its local Application Support data.
Optional app connections
- Product analytics is off by default. If you turn it on, NapCat sends fixed event metadata such as an event name, provider, app version, plan state, delivery result, duration, and a random, pseudonymous installation identifier. It has no fields for prompts, responses, projects, paths, email addresses, license keys, or session IDs. These events go to a NapCat endpoint that validates the fixed schema before forwarding them to PostHog for retention and feature analysis. They are retained for up to 400 days. Turning analytics off stops new events and clears the unsent local queue.
- The optional Claude usage meter uses Claude Code’s existing local login to request usage information directly from Anthropic. Neither the credential nor the response is sent to NapCat’s servers.
- Update checks contact napcat.app to look for and download new versions. As with any network request, hosting systems may temporarily process an IP address and basic request data for delivery, reliability, and security.
Website analytics and storage
napcat.app uses Vercel Analytics and Speed Insights to understand page views and performance without advertising cookies or cross-site identifiers. PostHog starts only after you select Analytics only or Accept all. If accepted, it can measure downloads, clicks, scroll depth, navigation, browser and device characteristics, referrers, and approximate network information. It uses a first-party cookie and local storage identifier and may record a masked replay of a visit. Form inputs are masked, and license-key and purchase-recovery areas are excluded from capture.
When the Mac download is requested, NapCat records one aggregate download requested event even if optional analytics is off. It contains the release version and file type but no cookie, campaign query, IP address, or durable visitor identifier. This is used only to count file requests; it cannot prove that installation completed. Signed Polar webhooks also record pseudonymous purchase, refund, and transactional license-email delivery outcomes. Those events never include the buyer’s email address, license key, order ID, or webhook body.
Meta Pixel and the Meta Conversions API start only after you select Accept all. NapCat then sends advertising-measurement events for page views, product views, downloads, checkout starts, newsletter signups, and verified purchases. Depending on the event, Meta may receive the page URL, product and purchase value, IP address, user agent, Meta cookie identifiers, and a one-way hash of the purchase or signup email. NapCat never sends Meta a license key, checkout proof, agent content, prompt, response, project, path, or session identifier. Browser and server events share an event ID so Meta can deduplicate them.
You can reject all optional cookies, allow analytics without Meta, or accept both. Change your choice at any time with Cookie settings in the footer. Withdrawing stops new optional events and attempts to remove first-party PostHog and Meta identifiers; you can also clear website storage in your browser. Rejecting does not prevent downloading or purchasing. Read the providers’ policies at PostHog, Meta, and Vercel.
Newsletter and discount emails
If you ask for the 10% discount code, NapCat sends your email address to Resend, stores it as a newsletter contact, and emails the code plus occasional product updates. Newsletter signup is separate from cookie consent and from purchasing a license: NapCat does not add buyers to marketing email automatically. Every marketing email includes an unsubscribe option. Unsubscribing marks the contact as unsubscribed so future marketing campaigns exclude it; transactional license and support messages may still be sent when requested.
Purchases and licenses
Polar runs checkout and payment processing. NapCat receives the email address, license key, order and customer identifiers, and license status needed to deliver, recover, move, and revoke a license. These records are stored with Supabase. NapCat does not receive or store your full payment-card details. Resend processes the purchase email address and license key to deliver the key directly after checkout or when you request email recovery. Polar may retain transaction data for payment, tax, fraud-prevention, and legal obligations under its own privacy policy. Resend handles license and opted-in newsletter delivery under its privacy policy.
Support messages
If you email support, NapCat receives your email address and whatever you include in the message. Please do not send prompt content, license keys, passwords, or other secrets unless they are necessary to solve the issue. Support messages are kept only as long as needed to answer the request, maintain a useful support history, or meet legal duties.
Why information is processed
NapCat processes purchase and license information to provide the product you requested; support and security data to operate and protect the service; optional app analytics with your choice in the app; website analytics to understand and improve the site; advertising measurement and newsletter marketing with consent; and records needed to meet tax, accounting, fraud-prevention, and other legal obligations. The applicable legal basis may be contract, consent, legitimate interests, or legal obligation, depending on the data and your location.
Sharing and international processing
Information is shared only with providers needed to run NapCat, including Polar for checkout, Supabase for license records, Resend for license and newsletter email, Vercel for hosting and performance, PostHog for product and website analytics, Meta for consented advertising measurement, and service providers used for infrastructure. These providers may process data in countries other than yours under their contractual and legal safeguards. Information may also be disclosed when required by law or needed to protect users, NapCat, or the public.
Your choices and rights
You can leave app analytics off, disable the Claude usage meter, clear local Activity history, unsubscribe from marketing email, and reject or withdraw website analytics or advertising cookies from Cookie settings in the footer. Depending on where you live, you may also have rights to access, correct, delete, restrict, object to, or receive a copy of personal data, and to withdraw consent. Email hi@napcat.app to make a request. NapCat may need to verify that the request belongs to you. You may also complain to your local data-protection authority.
Security, children, and changes
NapCat uses reasonable technical and organizational safeguards, but no storage or transmission system is completely secure. The product is not directed to children under 13, and NapCat does not knowingly collect their personal information. This policy may change as the product or law changes; the effective date above will be updated when it does.