Privacy Policy

Last updated: September 26, 2026

Short version: Port42 is local-first. Your ports, their chats and your data stay on your computer. Port42 runs no AI model, never calls a model provider and holds no model API key. Analytics in the app and on this website are opt-in.

The App

Port42 is a native macOS application. Your spaces, ports, port chats and settings are stored locally on your computer. Nothing is uploaded to Port42's servers.

Screen recordings and captures you make through the app are saved locally, in the space's working directory or in Port42's data folder, and are not transmitted anywhere.

Secrets you add for a port to call a web API are stored in the macOS Keychain and sent only to the API you named. They are never transmitted to Port42.

AI companions and model providers

Port42 contains no AI model and never calls a model provider. It reads no provider credential and holds no model API key. Your companions are command-line agents such as Claude Code and Codex, running in terminals on your computer. Each logs in with your own account at its provider (Anthropic for Claude Code, OpenAI for Codex) in its own terminal and sends your prompts to that provider under that provider's terms and privacy policy. Port42 is not in that path.

Access on your computer

Programs reach Port42 through a local gateway that listens only on your computer (loopback). Each program that calls it, such as a companion's terminal or the Port42 CLI, gets its own token, stored as a file readable only by your user account. Port42 asks you before a program first uses a sensitive capability (terminal, screen, camera, clipboard, files, browser, automation). You can see every program and its grants in Settings, Access, and revoke them at any time.

Sharing a port

An invite grants access to one port only, never your whole desktop. Connections between Port42 instances are peer to peer and encrypted in transit. Revoking an invite removes that access and nothing else.

Security status. Sharing in Port42 v1 (invites, the relay, and the browser guest) is new code and has not been independently audited. Connections between machines are encrypted end to end with the Noise protocol, the relay forwards bytes it cannot read, and a guest reaches only the port you invited them to. Those are design properties, not audited guarantees. Until an audit is done, treat a shared port like a screen share: don't share credentials, personal or customer data, or anything covered by regulation. Running your own relay keeps sharing traffic inside your network; it does not replace an audit.

App analytics

App analytics are off unless you opt in. If you opt in, the app sends product usage events (for example, app opened, port created, space created) to PostHog through ph.port42.ai, tagged with a random ID generated on your computer and the app version. Events do not include the content of your ports, chats or files. Screen views and automatic lifecycle capture are turned off. You can opt out at any time in Settings.

Updates

The app checks for updates with Sparkle, which fetches an update feed from GitHub (raw.githubusercontent.com). That request includes your app version, as any update check does.

The Website (port42.ai)

Website analytics are opt-in. When you first visit, a prompt asks if you're willing to share anonymous usage data. If you decline, no analytics events are sent. If you accept, we use PostHog through ph.port42.ai to collect:

We do not ask for your name or email address. Session recording and autocapture are disabled. You can change your preference at any time by clearing your browser's local storage for port42.ai.

Third-Party Services

Port42 does not sell or share your data with third parties. When a port calls a web API, or a companion talks to its model provider, that traffic goes directly from your computer to that service under its own terms.

Children

Port42 is not directed at children under 13 and we do not knowingly collect data from children.

Changes

If this policy changes materially, we'll update the date above and note it in the changelog.

Contact

Questions: [email protected]