01The short version
The full policy is below, but this is the whole of it:
- Everything you do in Redeep stays on your Mac. Sessions, files, boards, notebooks, and keys live in your home folder and your macOS Keychain — not in an account with us.
- There is no Redeep account. Nothing to sign up for, nothing to sign into, so we hold no profile, no history, and no billing record for you.
- Your prompts and code never reach us. When you use a cloud model, the request goes from your Mac straight to the provider whose key you supplied. We are not in that path.
- We receive three things: visits to this website, downloads of the app, and the app asking whether a newer version exists.
- We do not sell or share personal information, and we run no advertising.
- If you connect a Google account, Redeep uses that data for one thing only: carrying out the task you asked for in the app. Never for advertising, never sold, and never used to train AI models. See Google user data.
02Who this covers
Slideform, Inc. ("we," "us") publishes Redeep and operates redeep.app. This policy covers the website, the macOS app you download from it, and the update service the app checks.
It does not cover the services you choose to connect Redeep to — your model provider, the tools you give it credentials for, or an agent CLI you dispatch work to. Those companies decide what they collect, and their own privacy policies govern that data. See Services you connect.
03What stays on your Mac
Redeep is a local application. The things people usually worry about handing to a cloud service are, in Redeep, ordinary files on your own disk:
- Conversations and agent sessions — every message, tool call, and result.
- Your files and repositories, including the git worktrees agents work in.
- Boards, cards, notebooks, and kernel output — charts, tables, and computed results.
- API keys and credentials, stored in the macOS Keychain — never written to a config file, a log, or the repository.
- Your usage and cost ledger, so you can see what each agent spent.
- Logs and diagnostic bundles the app writes for troubleshooting.
Most of this lives under ~/Library/Application Support/redeep. You can read it,
back it up, or delete it at any time — deleting it removes the data for good, and nothing is
mirrored elsewhere. If you build a diagnostic bundle to report a bug, Redeep writes the zip
to your Mac and shows it to you in Finder; it is never uploaded, and it only contains message
content if you explicitly choose the full version.
04What we receive
Three narrow streams, and no others.
1. Website visits
redeep.app uses Google Analytics 4 to count visits and understand which pages people
read. It records the page you viewed, the site that referred you, your approximate location
derived from your IP address, and basic device and browser details. One custom event,
download_click, records that someone pressed a download button, the page and
page section, and the download destination. See Cookies & analytics
to opt out.
2. Downloading the app
The site and the installer are served through Cloudflare. Like any web request, the download produces a standard server log entry: IP address, timestamp, the file requested, and your browser's user-agent string. We use these to know whether downloads are working and to defend against abuse.
3. Update checks
The installed app asks redeep.app/appcast.xml whether a newer version has
shipped. That is a plain HTTP request and carries what any request carries: your IP address
and a user-agent string identifying the app and macOS version. We do not enable the
optional system-profile reporting the updater supports, so no hardware or configuration
survey is sent. You can turn automatic checks off in Settings, and the app will only
look when you ask it to.
Just as important is what we don't receive: no account details, no crash or telemetry reporting, no record of your prompts, files, tools, or which models you run. The app has no channel that would carry them.
05Services you connect
Redeep ships no inference of its own. It becomes useful when you point it at services you already have — and each one you connect receives whatever you send it, under its own terms.
- Model providers. OpenRouter, OpenAI, Anthropic, Google Gemini, the Vercel AI Gateway, or any OpenAI-compatible endpoint. Your prompts, and any file content an agent includes, go directly to the provider whose key you saved. Their terms govern what they do with a request you send them, so it is worth reading how long your provider retains requests and whether it trains on them. (Content from a connected Google account is treated separately and more narrowly — see Google user data.)
- On-device models. Open-weight models run entirely on your Mac through MLX, so the text never leaves the machine. Downloading the weights themselves is a request to the model host, Hugging Face.
- Google Workspace. Connecting a Google account is optional, and grants only what you approve on Google’s consent screen. Requests go from your Mac to Google’s APIs and we receive no copy of them. Because mail and calendar content is sensitive, and because Google holds apps that touch it to a stricter standard, it has its own section: Google user data.
- Tools and integrations. Slack, Cloudflare, Vercel, AWS, BigQuery, Snowflake, Google Drive, and any HTTP API or MCP server you add. Each stores its credentials separately in the Keychain, and each sees only the requests the agent makes to it.
- Browsing and computer use. When an agent visits a page, the site sees an ordinary browser. When it operates your screen, the screenshot it needs is sent to the model you picked for that turn.
- External agents. Handing work to your own Codex or Claude Code CLI runs it on your account and billing. Redeep never injects your API keys into those tools.
We are not a party to any of these exchanges and receive no copy of them.
06Google user data
Connecting a Google account is optional; Redeep works without one, and the mail and calendar features are simply unavailable until you connect. When you do connect one, this section is the whole of what Redeep does with that data.
Redeep uses Google user data for one purpose: to provide the features you asked for inside the app. There is no second use. It is not used for advertising, not sold or transferred to anyone for those purposes, not used to build a profile of you, and not used to develop, improve, or train AI or machine-learning models.
What Redeep accesses, and the feature each permission serves
You approve these on Google’s own consent screen, and Redeep asks for nothing beyond them. Each one exists to power a feature you can see and use in the app:
| Google scope | Data accessed | The feature it provides |
|---|---|---|
openid, email |
The address of the account you connected | Labels the account in Settings and sends each task to the right one when you connect more than one. |
gmail.readonly |
Messages, threads, labels, and drafts you ask a task to look at | Answering the mail question you assigned — summarizing a thread, finding what a client is waiting on, totalling the receipts in your inbox. |
gmail.compose |
Drafts in your Drafts folder | Writing a reply into your Drafts folder for you to read and send yourself, and deleting a draft after you approve that exact deletion. Redeep has no send-mail step and cannot send mail. |
calendar.calendarlist.readonly |
Which calendars exist on the account | Reading the right calendars instead of guessing. |
calendar.events.freebusy |
Busy and free time | Answering “when am I free?” and proposing times that work, including across two connected accounts. |
calendar.events |
Event details on those calendars | Answering schedule questions, and creating, editing, cancelling, or RSVPing to an event after you approve that exact change. |
drive.file |
Content of only the Drive files Redeep creates or that you open with it, including Docs, Sheets, and Slides | Reading or editing a file you pointed a task at, and saving what a task produced. Redeep receives only selected file IDs and cannot browse or search the rest of your Drive. |
Reads happen inside the task you assigned. Anything that creates or changes data stops and shows you the exact change first — see How your data is protected. For a plain-language walkthrough of each permission, see Redeep and Google Workspace.
Limited Use
Redeep’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms:
- Only for the features you use. Google user data is used solely to provide the user-facing features described above, at the moment you run a task that needs them.
- No advertising. It is never used for serving ads of any kind, including retargeting and personalized or interest-based advertising. Redeep shows no ads and runs no ad network.
- No sale, no data brokers. It is never sold or transferred to advertising platforms, data brokers, or information resellers.
- No credit decisions. It is never used to determine credit-worthiness or for lending purposes.
- No AI training. It is never used or transferred to develop, improve, or train generalized or non-personalized AI or machine-learning models — ours or anyone else’s.
- No human review. Nobody at Slideform reads your Google user data. We cannot: it never reaches us, because no server of ours sits in the path and we keep no copy. The only person who reads it is you, in the app that fetched it at your request. The one exception is material you deliberately send us yourself — a diagnostic bundle or a quoted message in a support email — and then we see only what you chose to send.
The one transfer, and why it happens
Redeep ships no AI model of its own. To turn “summarize this thread” into a summary, that thread’s content has to reach the model provider whose key you connected. That transfer is the feature: it happens only when you run a task that needs it, carries only what that task requires, and goes from your Mac to the provider you chose under your own account. It therefore happens only with your consent — you pick that provider and connect its key yourself — and exists solely to return the answer you asked for. It is never for training, advertising, or any other purpose, and no copy comes to us. If you would rather no Google content leave your Mac at all, run the task on an on-device model — then the content stays on the machine.
Beyond that, Google user data is transferred only where the Limited Use policy allows: for security purposes such as investigating abuse, or to comply with applicable law. Should Redeep ever be part of a merger, acquisition, or sale of assets, Google user data would move only with your explicit prior consent.
Google Analytics on this website is a separate thing entirely: it measures visits to redeep.app and has no connection to your Google account or to any data Redeep reads from it. See Cookies & analytics.
How long it is kept, and how to end it
- We keep none of it. Slideform stores no Google user data, so there is nothing on our side to retain or delete.
- On your Mac, what a task read is written into that session’s transcript. Deleting
the session deletes it; deleting
~/Library/Application Support/redeepremoves everything Redeep has stored. - Disconnecting an account in Settings → Connections asks Google to revoke that grant and deletes its stored keys from your Mac, leaving your other accounts connected. You can also revoke at any time from your Google account permissions page. Either way, access ends immediately.
If we ever want to use Google user data in a way this section does not describe, we will update this policy and ask for your consent before doing it.
07How your data is protected
Mail, calendar, and document content is sensitive, so here are the specific mechanisms that protect it. The strongest one is structural: there is no Redeep server and no Redeep account, so there is no database of your data for anyone to breach, subpoena, or mine.
In transit
- Every request to a Google API travels over HTTPS/TLS, directly from your Mac to Google. Nothing is proxied through us.
- You sign in on Google’s own screen using OAuth 2.0 with PKCE. Redeep never sees, handles, or stores your Google password.
- Google returns the authorization to a loopback address on your own machine, so the exchange never crosses the internet to a server of ours.
At rest
- The keys Google issues are stored in the macOS Keychain, encrypted by macOS and unreadable until you unlock your Mac. They stay on that Mac — not synced to iCloud, and never transmitted to us.
- They are never written into a project file, a configuration file, an environment file, or a git repository, and each connected account’s keys are stored separately.
- The long-lived key that keeps a connection alive never leaves the Keychain. A running task receives only a short-lived access key for the account you selected, which expires on its own.
- What a task read is recorded in that session’s transcript on your own disk, under your macOS user account and its file permissions. Turning on FileVault encrypts it along with the rest of your disk.
Access control inside the app
- Least privilege. Redeep requests the narrowest permission that does the job: per-file Drive access rather than your whole Drive, and permission to compose a draft rather than to send mail. Broader Drive reading is a separate, optional grant asked for in context.
- Per-agent grants. A standing agent can reach your Google account only if you switch that on for that agent, and only for the account you named. An agent without the grant gets no access at all.
- Approval before any change. Every write is a two-step operation. The first attempt writes nothing: it stops and returns a summary of exactly what would change — the recipients, subject, and body of a draft, or the account, calendar, time, attendees, and specific fields of an event — for you to approve. Only then does the change go through. For an edit or a cancellation, the version you approved is checked against the live event first, so if someone else moved it in the meantime the change stops instead of overwriting theirs.
- Isolation. Each agent works in its own separate checkout, and shell and code execution run inside a macOS Seatbelt sandbox confined to that session’s workspace.
Reporting a problem
If you find a security issue in Redeep, email james@slideform.co and we will investigate it. If an incident ever affects personal data we hold, we will notify affected people and the relevant authorities as the law requires.
08Permissions Redeep asks for
macOS gates the capabilities agents need, and you grant them one at a time:
- Notifications — so you know when an agent finishes or needs approval. Delivered locally by macOS; nothing is sent anywhere.
- Automation (Apple Events) — only if you enable an integration that drives Messages, Music, or Spotify.
- Accessibility and Screen Recording — only if you use computer use, where an agent clicks and types on your behalf. Screenshots stay on your Mac apart from the ones sent to the model that has to see the screen to act on it.
- Files and folders — shell and code execution run inside a macOS Seatbelt sandbox confined to the session's workspace, and the structured file tools refuse paths outside it unless you opt in.
Every one of these is revocable in System Settings → Privacy & Security.
11How long data is kept
- On your Mac: until you delete it. Deleting a session removes its transcript from disk; deleting the application-support folder removes everything Redeep has stored.
- Website analytics: retained by Google for the retention window configured on the property, then deleted automatically.
- Server logs: kept briefly by Cloudflare under their standard retention for operational and security purposes.
- Google user data: we retain none of it, so there is nothing on our side to keep or delete. What a task read stays in that session's transcript on your Mac until you delete it, and disconnecting the account revokes the grant and removes its stored keys. See Google user data.
12Your rights
Because we hold so little, most privacy requests we receive concern analytics data. Even so, the rights are yours and we will honor them.
If you are in the EEA, the UK, or Switzerland, you may request access to your personal data, correction, erasure, restriction of or objection to processing, and portability. You may also complain to your local supervisory authority.
If you are in California, you may request to know what personal information we have collected, ask us to delete or correct it, and opt out of its sale or sharing — though we neither sell nor share personal information, and we will never discriminate against you for exercising any of these rights.
To make a request, email james@slideform.co. We respond within the period the applicable law allows. Since we cannot link website analytics to a name, include the identifiers you want removed (or simply opt out with the add-on above) so we can act on the right records.
13Where data is processed
Slideform, Inc. operates from the United States, as do the two processors named here — Google (analytics) and Cloudflare (hosting and delivery). If you visit from outside the US, the limited data in What we receive is processed there, under the transfer safeguards those providers maintain, including the European Commission's standard contractual clauses.
This covers only the website data above. If you connect a Google account in the app, that data is processed by Google under your own account, wherever Google processes it — it is never routed through us or stored on our infrastructure.
14Children
Redeep is a professional tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, write to us and we will delete it.
15Changes & contact
If this policy changes, we will update the date at the top of the page, and we will say so plainly on the site when the change is material. Continuing to use Redeep after an update means the revised policy applies.
Questions, requests, or corrections:
- Slideform, Inc.
- james@slideform.co
For how the security model works in practice — sandboxing, the workspace jail, and isolation between agents — see the privacy and security section of the docs.
Redeep