1. Scope and controller
This notice covers the Choro landing pages, macOS application, Choro-hosted Design service, coding-agent connections initiated through Choro, and optional Choro Remote relay. Choro Design creates a hosted profile and workspace for each installation. There are currently no Choro-hosted cloud-agent machines, advertising profiles, payment records, or Choro-operated automated decisions about individuals.
For website, Design-service, and relay information, the Choro operator identified on the official download page and in the application’s signed distribution record is the controller. Contact privacy@choro.dev. Information that remains only on your Mac is not received by the Choro operator.
Third-party tools and websites have their own privacy notices. This page describes Choro’s role, not everything a model provider, Git host, database, package registry, website host, or other service may do.
2. Plain-language summary
- Your project data is local by default. Choro reads and writes the files, settings, documents, Git state, and local service information needed for the features you use.
- Design files are hosted. When Choro Design is enabled, Choro provisions a private profile and stores design content and account identifiers on Choro-operated infrastructure.
- You choose when a provider receives context. A coding-agent tool can send prompts, files, diffs, or other selected context to its provider under your account and that provider’s terms.
- Remote access is optional and encrypted by the application. The relay routes opaque ciphertext and keeps active room state in memory rather than a database.
- The beta waitlist is only for beta access. If you join, Choro stores your email address, signup time, and signup source in Google Sheets so the team can manage invitations. It does not subscribe you to a marketing newsletter.
- No Choro product telemetry is currently built in. Choro does not operate behavioural analytics or automatic crash reporting in the desktop application.
3. Current data map
This table distinguishes information that stays on the user’s device from information received by a Choro-operated site, Design service, or relay. Hashing or encrypting an identifier does not automatically make it anonymous if it can still be linked to a device, profile, room, or connection.
| Context and data | Purpose and destination | Current retention |
|---|---|---|
| Website requests: IP address, user agent, time, requested page, and error or security logs. | Deliver and protect the site. Received by the production web host; Google Fonts and jsDelivr receive requests for externally loaded assets. | Choro-controlled website logs are retained for no more than 30 days unless longer retention is required for a documented security incident or legal obligation. External providers apply their own retention terms. |
| Beta waitlist: email address, signup time, and signup source. | Manage beta invitations. Submitted through a Choro-operated Google Apps Script and stored in Google Sheets. The address is not added to a marketing newsletter. | Until beta access is closed, the address is no longer needed for invitations, or a verified deletion request is completed. |
| Local workspace data: project paths and files, documents, Git state, agent conversations, attachments, terminal and task metadata, and preferences. | Provide the desktop features the user requests. Stored on the Mac and sent elsewhere only when the user or a connected tool initiates an external action. | Until the user deletes the relevant Choro data, project data, or Mac storage. |
| Local connection data: database connection URIs and issue-tracker account details and API tokens. | Connect from the Mac to services selected by the user. These values are currently stored in Choro’s local application database; provider CLIs keep their own credentials separately. | Until the connection or local Choro data is deleted. Provider CLI retention is controlled by that provider tool. |
| Design-service data: a random installation identifier, a hash of the installation credential, a generated internal profile email, profile/team/project identifiers, access credentials, design files, components, uploaded assets, and related metadata. | Provision and authenticate a private Choro Design profile and provide design creation, editing, storage, export, and MCP access. Stored on Choro-operated Penpot, database, object-storage, and provisioner infrastructure. Raw installation and Design credentials are also stored in the user’s platform credential store. | Profile and design data remains while the Design account is active or until a verified deletion request is completed. Deleted content may remain in restricted disaster-recovery backups for up to 30 days. Design-service request and security logs follow the 30-day maximum below. |
| Agent-provider content: prompts, selected files or diffs, command output, attachments, identifiers, and feedback. | Sent through the local agent tool to the provider selected by the user. | Controlled by the user’s provider plan, settings, and contract. |
| Remote data: room public-key identifier, role and purpose, ephemeral client identifiers, admission-token hashes, timing and connection state, ciphertext, and network metadata. | Authenticate, route, secure, and operate optional Remote connections. The relay operator and infrastructure host receive this information; plaintext remains at the endpoints by design. | Active relay room and token-hash state is in memory for the connection. Choro-controlled relay logs are retained for no more than 30 days unless needed for a documented security incident or legal obligation. Paired-device authorisation records on the Mac expire after 90 days unless renewed or removed sooner. |
4. Website data
The landing site includes an optional beta-access form. If you submit it, Choro sends your email address, the signup time, and the signup source to a Choro-operated Google Apps Script for storage in Google Sheets. Choro uses that information to manage beta invitations, not to subscribe you to a marketing newsletter. You can request deletion at privacy@choro.dev.
The current landing site does not include a Choro account form, behavioural analytics script, advertising pixel, or payment flow. The web host may process ordinary request information such as IP address, time, requested page, user agent, and error logs to deliver and protect the site.
The landing pages request fonts from Google Fonts, and the main landing page requests the Tabler icon stylesheet from jsDelivr. Those providers receive network request information such as your IP address and user agent under their own privacy terms. A future build should self-host these assets if eliminating those requests is a release requirement.
5. Data on your Mac
Depending on the features you use, Choro can process project paths and files, documents, agent conversations and attachments, workspace configuration, Git information, terminal output, database connection URIs, local-service metadata, issue-tracker account details and API tokens, and application preferences.
This information is stored on or accessed from your Mac unless you direct Choro or a connected tool to send it elsewhere. Choro needs operating-system and project permissions appropriate to the files and commands you choose. Removing the application does not automatically delete every project file or every record maintained by a third-party CLI.
Database connection URIs and issue-tracker tokens are currently stored in Choro’s local application database and should be treated as sensitive local data. Remote transport keys and managed Design installation, API, MCP, and browser-session credentials are stored in the macOS Keychain; paired-device metadata and token hashes are stored in a private local file. Choro does not ask for your model-provider password. Provider CLIs and other installed tools maintain their own authentication material independently of Choro. Review each tool’s storage and sign-out controls.
6. Coding agents and other providers
When you use a coding agent, Choro routes the conversation through the local agent tool you selected. That tool may send prompts, repository context, command output, attachments, identifiers, and feedback to its provider. The provider decides how it processes and retains that data under your provider account, settings, plan, and contract.
If you attach or ask an agent to inspect a Design file, the connected Design MCP tools can retrieve content from the hosted Design service and include resulting design context in the agent interaction. The selected coding-agent provider may then receive that context under its own terms.
The same principle applies when you connect Git hosting, issue trackers, databases, deployment platforms, or other services: data you request may travel directly from your computer to that service. Choro does not turn a personal provider subscription into a Choro subscription and does not resell model usage.
7. Choro-hosted Design service
Choro Design is a Choro-operated deployment of the open-source Penpot software; it is not an account on Penpot’s own cloud service. On first use, the application creates a random installation identifier and credential. The Choro provisioner uses them to create and reconnect a private Penpot profile with a generated internal email address, API token, MCP key, and browser-session credential. Public registration and ordinary Penpot onboarding are disabled.
The service stores the profile, teams, projects, design files, components, assets, and related metadata needed to provide Design. Its database and object storage can therefore contain personal information or confidential material that a user places in a design. Do not place data in a design unless you have permission to use and host it.
The hosted infrastructure receives ordinary network and security information such as IP address, request time, route, user agent, response status, and error details. Choro disables Penpot telemetry in its current deployment. Design credentials must not be placed in prompts or shared; contact security@choro.dev if exposure is suspected.
8. Optional Choro Remote relay
Remote access connects an authorised device to your running Choro Desktop instance. The relay receives a room identifier derived from the Desktop public key, connection role and purpose, ephemeral client identifiers, hashed admission tokens, timing and connection state, and application-encrypted message envelopes.
The relay is designed not to receive plaintext agent messages, repository contents, commands, device bearer tokens, transport keys, or the Desktop private key. A client sends its admission token to the relay for authentication; the relay hashes it before comparing it with the hashes advertised by the Desktop. Active rooms and token hashes are held in memory, with no relay database, and are removed when the Desktop disconnects or the relay restarts. The relay host may still process network metadata such as IP addresses, TLS connection details, message sizes and timing, and operational logs.
Remote access is off unless you configure and enable it. You can close pairing, revoke a paired device, disconnect the Desktop, or stop using the relay.
9. Analytics, crash reporting, and cookies
The desktop application does not include Choro-operated product analytics or automatic crash telemetry. The website does not set Choro marketing or analytics cookies. Hosting infrastructure and externally loaded assets can still create ordinary server logs or use their own network-level controls.
This statement is about the current Choro release. A project opened in Choro may contain its own analytics SDKs, and third-party CLIs may collect diagnostic or usage information under their own settings. If Choro adds telemetry, this notice will be updated before the feature is enabled and, where legally required, an appropriate choice will be presented.
11. Retention
Local Choro data remains until you delete it through the application, remove the relevant local files, clear the associated application-support data, or erase your Mac. Repository and document history may also exist in backups, Git history, or tools you configured.
Hosted Design profiles and content remain while the account is active or until Choro completes a verified deletion request. Removing Choro Desktop does not automatically tell the hosted service to delete the profile. Contact privacy@choro.dev for deletion. Deleted Design data may remain in restricted disaster-recovery backups for up to 30 days and is not restored except for disaster recovery.
The relay keeps active room and admission state only in memory for the connection’s lifetime. Paired-device authorisation records on the Mac expire after 90 days, subject to earlier revocation or deletion. Choro-controlled website, Design-service, and relay request or security logs are retained for no more than 30 days unless a longer period is necessary for a documented security incident, legal claim, or legal obligation. Infrastructure providers may apply shorter operational retention periods.
12. Your choices and privacy rights
You can choose which projects and providers to use, avoid remote access, revoke paired devices, sign out through provider tools, and delete local Choro data. You can request deletion of the hosted Design profile and content through privacy@choro.dev. Because most desktop data is not sent to Choro, requests about that local data are normally handled directly on your Mac.
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information held by Choro, withdraw consent where processing relies on consent, and complain to a data-protection authority. Choro does not use website or relay data to make decisions about people solely by automated means.
Submit a request to privacy@choro.dev. Choro may request information reasonably necessary to verify your identity and protect other users. Requests will be answered within the period required by applicable law, ordinarily within 30 days.
13. Children
Choro is a professional developer tool and is not directed to children under 16. Do not use Choro to submit a child’s personal information without a lawful basis and appropriate parent or guardian authorisation.
14. Changes and contact
This notice will change when Choro’s data flows change. Material updates will be dated here and, where practical, included with release notes or shown before a new data-using feature is enabled.
For questions, complaints, or rights requests, contact privacy@choro.dev. Legal notices may also be sent to legal@choro.dev.