Privacy policy
SessionFolio keeps your conversations on your Mac.
SessionFolio is a local-first macOS application operated by its independent developer (“SessionFolio”, “we”, or “us”). This policy explains what the app processes locally, what information reaches us when you submit feedback or contact us, and how the website is delivered.
1. Information processed locally
SessionFolio reads supported local coding-agent history from Claude Code, Codex, Gemini CLI, and OpenCode so you can browse, search, preview, and resume sessions. This may include conversation text, session titles and identifiers, timestamps, project names and paths, and source metadata.
The app stores its normalized library and full-text search index in a local SQLite database on your Mac. Preferences and limited diagnostic events are also stored by macOS locally. SessionFolio does not operate an account service or cloud conversation database, and the app does not upload your prompts, responses, code, or tool results to us.
2. Source access, resume, and deletion
Indexing is read-only and does not modify original agent history. When you choose Resume, SessionFolio may use macOS Apple Events to open your selected terminal and run the supported agent's resume command.
A confirmed permanent-delete action may delete both the SessionFolio copy and the original agent session when that source supports deletion. The confirmation shown by the app describes the scope before anything is deleted. These actions are initiated only by you and may not be reversible.
3. Feedback and support
When you press the submit button in an in-app feedback form, we receive the feedback, bug report, or feature request you entered; the affected agent source you selected; the SessionFolio version and build number; and an optional contact email. If the “Include basic system information” option is enabled, we also receive your macOS version and Mac architecture. The form does not automatically include conversations, session identifiers, titles, project paths, search terms, source code, or logs.
Feedback is delivered through Supabase infrastructure in the United States. For abuse prevention, the feedback endpoint derives an hourly salted hash from network request information such as an IP address. We store that temporary hash—not the address itself—in a rate-limit table. Entries more than two hours old are deleted during later feedback submission processing. Supabase may retain ordinary platform request or security logs under its configured service policies.
When you separately email us, we receive your email address, message, and anything else you choose to include. We use submitted information to respond, diagnose problems, improve SessionFolio, and maintain necessary support records. Please do not send conversations, source code, credentials, API keys, project paths, or other sensitive material.
4. Website and download requests
We do not use advertising trackers or cross-site behavioral analytics. When you request an app download, our Supabase download endpoint records the request time, SessionFolio release version, a limited source label, the referring site's domain when available, broad operating-system and browser families, and whether the request appears to be automated. We do not store a complete referring URL.
To estimate daily unique downloads without creating a persistent identifier, the endpoint derives a daily salted hash from temporary network request information such as the IP address and browser user-agent. We store the resulting hash, not the IP address, and the hash changes each day so it cannot be used to follow a download request across days. The endpoint then redirects your browser to the requested file in Vercel Blob storage.
After a download event classified as a non-automated macOS request is stored, we send the maintainer a real-time notification through WxPusher containing the release version, source label, referring domain, broad operating-system and browser families, navigation category, and request time. Requests classified as automated or originating from another operating-system family do not trigger this notification. The notification does not include your IP address, daily hash, complete referring URL, or complete browser user-agent.
Our website and downloads are hosted using Vercel services. Like most hosting providers, Vercel and Supabase may process limited request data—such as IP address, browser or user-agent information, requested URL, request time, and security or error events—to deliver and protect the site and download files.
5. Service providers
Supabase provides feedback, download-request, and database infrastructure in its US East (Ohio) region. Google provides the Gmail service used for support correspondence. Vercel provides website, content-delivery, and download infrastructure. WxPusher delivers download notifications to the maintainer. These providers process information under their own terms and privacy commitments and may process data in countries other than yours. We do not sell personal information or share it for cross-context behavioral advertising.
6. Retention
Local app data remains on your Mac until you delete it. We generally delete resolved feedback submissions and support correspondence within 180 days. Temporary feedback rate-limit hashes become eligible for cleanup after two hours. Raw download-request events and daily download hashes become eligible for cleanup after 30 days; non-identifying aggregate download counts may be retained longer. We may retain limited records longer when reasonably necessary for security, legal compliance, or establishing or defending legal claims. Hosting-provider logs follow each provider's configured retention periods.
7. Your choices and deletion
You control the app's local data. SessionFolio's database is stored at~/Library/Application Support/SessionFolio/. Quit the app before removing that folder. If you open the app again, sessions still present in supported source applications may be imported again.
You may ask us to access, correct, or delete feedback or support correspondence associated with your email address or feedback reference ID, or ask us to stop follow-up contact. Send a message with the subject “SessionFolio Privacy Request”. Rights and exceptions may vary by jurisdiction.
8. Security and children
We use reasonable measures intended to protect information we receive, but no network or storage system is completely secure. SessionFolio is a developer tool and is not directed to children under 13. We do not knowingly collect personal information from children.
9. Changes and contact
We may update this policy as SessionFolio changes. The latest version and effective date will appear on this page. Material changes will be described prominently where appropriate.
Questions and privacy requests can be sent to wenghang1228@gmail.com.