Pop Privacy Policy

Last updated . Applies to Pop for macOS, version 0.25 and later.

The short version

  • No analytics, no accounts, no ads, and no server of mine. I collect nothing.
  • Clipboard history, settings and plugins stay on your Mac. API keys are kept in the macOS Keychain.
  • Your text leaves the Mac only when you use a feature that needs a service you chose: AI (your own endpoint) or DeepL.
  • Pop contacts GitHub to check for updates and, when you open it, to load the plugin library.

Who is responsible

Pop is made and published by whrss9527, an independent developer (“I”, “me”). If you have any question about this policy or your data, email whrss9527@gmail.com.

What I collect

Nothing. Pop has no analytics, no crash reporting, no advertising, no tracking and no user accounts. I don’t run a server for Pop, so there is nowhere for your data to be sent to me. I never see what you do in the app.

What stays on your Mac

Pop keeps everything it needs locally. Apple’s on-device translation, the on-device Apple Intelligence model (macOS 26), text recognition in images, and all conversions run on your Mac.

DataWhere it’s keptNotes
Settings (ring layout, rules, shortcuts, translation and AI settings without keys)UserDefaults (io.github.whrss9527.pop)Can be exported to a file you choose.
Custom plugins~/Library/Application Support/Pop/Plugins/One JSON file per plugin.
Clipboard history~/Library/Application Support/Pop/Clipboard/ (SQLite database and images)Includes text recognized in copied images, for search. Deleted automatically by age and count; items marked concealed by password managers are never recorded; you can exclude apps.
Vocabulary list~/Library/Application Support/Pop/Vocabulary.jsonWords you save from translation cards.
Inbox~/Documents/Pop 收集箱.mdOnly if you use the Inbox tool.
AI API key, DeepL keymacOS Keychain on this MacNever synced or exported.
Files received from your phone~/DownloadsOnly when you use Send to Phone.

When Pop goes online

Pop connects to the following, and only in the situations listed:

ServiceWhenWhat is sent
GitHub (api.github.com, github.com and GitHub’s download servers)At launch and every 6 hours if “Check for updates automatically” is on (the default; you can turn it off), and when you check manually.A request for the latest release information and, when you install an update, the download of the release archive and its checksum file. The request identifies the app and version (Pop/<version> (macOS)). Nothing about you or your data is included.
Plugin library (raw.githubusercontent.com, falling back to cdn.jsdelivr.net)When you open the plugin library or install or update a plugin from it.A request for the library index and the plugin file. Nothing about you.
The AI endpoint you configureOnly when you use an AI feature or an AI plugin.The selected text, your instruction and your API key, sent to the address you entered. Plain http:// is only allowed for this Mac and your local network. If you use Apple’s on-device model on macOS 26, nothing leaves your Mac.
DeepL (api.deepl.com or api-free.deepl.com)Only when you choose DeepL for a translation.The text to translate, the target language and your DeepL key.
The link you’re expandingOnly when you use “expand short link”.A request to that link and each redirect it leads to, so Pop can show the final address.
Your own plugins and scriptsWhen you run them.Whatever the plugin does: open a URL, run a shell script, JavaScript or a Shortcut you wrote or installed. Pop shows shell scripts from the library before installing them, and asks before a pop:// link runs one.
Your phone, on your local networkOnly while Send to Phone is on.Pop serves a temporary page on your Wi-Fi, protected by a random token; it stops when you turn sharing off or after 10 idle minutes. Nothing goes through the internet.

Like any internet request, these connections reveal your IP address to the server you’re connecting to. Those services are run by third parties under their own privacy policies; I don’t receive anything from them about you.

iCloud

The builds published on GitHub do not include iCloud sync. In a build that includes it, and only while it’s turned on, Pop stores your settings and custom plugins in your own iCloud key-value storage so your other Macs can read them. Clipboard history, the vocabulary list and API keys are never synced. That data is held by Apple under your iCloud account, and I have no access to it.

Permissions

PermissionWhy
Accessibility (required)To notice a long right-click, read the selected text in the app you’re using, and paste results back when you choose “Replace”.
Screen RecordingOnly for screenshot OCR and translate, QR scanning, annotation and the screen ruler.
Reminders or CalendarOnly for “Add to Reminders”, the first time you use it.
NotificationsTo tell you about a new version and finished timers.
Local NetworkOnly for Send to Phone.

You can revoke any of these in System Settings › Privacy & Security at any time.

Web searches and links

Search, open-link and map tools hand the text or address to your default browser. Pop itself doesn’t contact those sites.

Where you got Pop

This policy covers Pop however you obtained it — from GitHub, from this website, or through a store or subscription service such as the Mac App Store or Setapp. Such a service handles your purchase or subscription and may process data under its own privacy policy; Pop itself behaves as described here. If an edition ever works differently, this policy will be updated before that edition is released.

Deleting your data

Clear the clipboard history in Pop, delete the folder ~/Library/Application Support/Pop/, and remove the “Pop” items from Keychain Access. Deleting Pop.app and these files removes everything Pop stored.

Children

Pop is a general-purpose utility, not directed at children, and collects no personal information from anyone.

Changes

If this policy changes, the new version will be published on this page with a new date. Pop is open source, so you can also check its behavior in the source code.

Contact

whrss9527 · whrss9527@gmail.com · Pop issues on GitHub