Privacy policy
Last updated
In short
- Orcylo has no account and no telemetry. The apps you run, your history and your projects stay on your Mac.
- The app goes online only for your licence, for update checks and for services you connect yourself, with your own keys.
- Claude Code and Codex usage is read from files on your Mac and never uploaded.
- This website counts visits with Google Analytics. It sets no cookies unless you accept, and loads nothing from Google if you decline.
- Payments are handled by Dodo Payments, the merchant of record. We never see your card.
Who we are
Orcylo is made by MerdoAI (“we”, “us”). This policy covers the Orcylo app for Mac and the website at orcylo.app. For anything about your data, email support@orcylo.app.
What stays on your Mac
To show you what your Mac is doing, Orcylo reads system information from macOS: CPU, memory, GPU, disk, network, power and battery, temperatures and fan speeds, sound and Bluetooth devices, the apps and processes you run, dev servers with their ports and project folders, and the files Claude Code, Codex and Grok Build keep on your Mac. It keeps 30 days of history, one point a minute, in a database in your user Library.
None of this is sent to us or to anyone else. Orcylo has no account, no analytics or telemetry, no advertising and no crash-reporting service. We have no server that receives data from the app. You can clear the history in Settings → History & Privacy, and deleting the app and its folder in ~/Library/Application Support removes everything it stored.
Claude Code, Codex and other AI tools
Claude Code limits come from what Claude Code reports to its status line, through a small bridge that Orcylo installs only when you press Connect (Disconnect restores your previous status line). Token history comes from Claude Code’s transcripts and Codex’s session logs on your Mac. Orcylo reads these files locally and never uploads them, and it never opens a login token or credential file. Cursor, Antigravity and Gemini CLI are only detected; Orcylo links to their own dashboards.
When the app goes online
Orcylo connects to the internet only for the following, and only to the service named.
Your licence (Dodo Payments)
Until you activate a licence, nothing about it leaves your Mac. When you activate one, Orcylo sends the licence key and your Mac’s name (so you can tell activations apart) to Dodo Payments’ licence service. It re-checks the key about once a week, and deactivates it when you ask in Settings → License. Like any web request, these reach Dodo Payments with your IP address. The licence is kept on your Mac, in a place only your user account can read.
Update checks
Once a day, unless you turn it off in Settings → About, Orcylo downloads the update feed at https://orcylo.app/appcast.xml. The request carries the app’s version and, as every web request does, your IP address, which our web host records in its server logs (see the website). No system profile is sent. Updates are downloaded only when you agree to install them.
Services you connect in the Analytics tab
The Analytics tab shows visitors, revenue and search data for your own website. It talks directly from your Mac to each service you connect, with the key or sign-in you provide, and to nothing else:
- Your website: when you enter a domain, Orcylo checks it every 5 minutes (status, response time, TLS certificate, page title).
- Visitors: Plausible, Umami or DataFast, with your API key.
- Revenue: Stripe, Lemon Squeezy or Dodo Payments, with your API key. Recent payments can include your customers’ names and countries; names are masked by default.
- Search and traffic: Google Search Console and Google Analytics 4, through Sign in with Google (see below).
- Technical SEO: your site’s public address is sent to Google’s PageSpeed Insights and Chrome UX Report APIs, using Orcylo’s own API key, not your Google account.
- Small helpers: icons of the sites that send you visitors are fetched from those sites themselves, and currency rates for converting revenue come from the public Frankfurter service (
api.frankfurter.app). Neither request includes your data.
Keys and sign-in tokens are stored only on your Mac, in a place only your user account can read. The figures are cached on your Mac so the tab works offline. Nothing from these services is sent to us. Your use of each service is covered by its own terms and privacy policy.
Google user data
If you choose Sign in with Google, Orcylo asks for read-only access to Google Analytics (analytics.readonly) and Search Console (webmasters.readonly), plus your email address (openid, email) to show which account is connected. Sign-in happens in your browser; the tokens are stored only on your Mac, in a place only your user account can read.
Orcylo uses this data only to show you your own Search Console and Analytics reports inside the app, on your Mac. It is cached locally, never sent to us or to any third party, never sold, never used for advertising and never used to train AI models. No person at Orcylo can read it, because it never leaves your Mac. Disconnect revokes the access at Google and deletes the tokens and cached data from your Mac; you can also remove access at myaccount.google.com/permissions.
Orcylo’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Links and macOS
Links you click in the app, such as an AI tool’s dashboard or a dev server’s localhost port, open in your browser. macOS itself may contact Apple to check that the app is notarized; that is covered by Apple’s privacy policy.
The website
orcylo.app runs no advertising and no third-party scripts apart from the optional visit statistics below; fonts and images are served from the site itself. If you pick light or dark appearance, or answer the statistics question, your browser remembers the choice in its local storage on your device; it is never sent to us.
Visit statistics (Google Analytics)
We count visits with Google Analytics 4, a service of Google Ireland Limited and Google LLC, to see which pages and buttons people use, which sites send visitors, and how many people reach checkout. A small notice asks for your choice. Until you answer, the tag runs without cookies: it stores nothing on your device, but Google receives the address of the page you view (without anything after the “?” except campaign tags), the site you came from (its name only), your IP address, from which it derives an approximate location, your browser and device type, and what you click. If you press Decline, or your browser sends a Global Privacy Control or Do Not Track signal, the tag is not loaded and nothing is sent.
If you press Accept, Google also sets the cookies _ga and _ga_* for two years, which recognise your browser on later visits. In both modes we switch off advertising features, ad personalisation and Google signals, and the licence key and email on the thank-you page are never sent. Google keeps the event-level data for two months and data tied to the cookie for up to 14 months; the summed-up reports we read are not personal. The legal basis for the cookies is your consent (GDPR Art. 6(1)(a)) and, for visitors in Türkiye, your explicit consent under the KVKK; the cookie-free count rests on our interest in knowing how the site is used (Art. 6(1)(f)). You can change your answer at any time with “Cookie settings” in the footer, which also deletes the cookies. The data may be processed in the United States under Google’s data transfer terms. See Google’s privacy policy.
When you write to support@orcylo.app, we receive your email address and your message and use them to reply. If you asked to be told about the launch, we email you about it once. We do not add you to a newsletter or share your address. Ask us any time and we delete your messages.
Purchases
Orcylo is sold through Dodo Payments, our merchant of record. Dodo Payments runs the checkout, takes the payment, handles sales tax and VAT, and issues your receipt and invoice. Your card or payment details go to Dodo Payments and its payment partners; we never see them. Their handling is described in the Dodo Payments privacy policy.
From Dodo Payments we receive your name, email address, country, what you bought, and your licence key with its activations. We use this to deliver and support your licence, to answer billing questions, and to keep the records that tax and accounting law require.
After checkout, Dodo Payments sends you to orcylo.app/thanks with your licence key in the address so the page can show it; the key is shown by your browser and never stored by the page. Because it is part of the address, it can also appear in the host’s server logs.
Your rights
Depending on where you live, for example under the EU and UK GDPR or Türkiye’s Personal Data Protection Law (KVKK), you can ask to see the personal data we hold about you, to correct or delete it, to receive a copy, or to object to how we use it. Email support@orcylo.app and we will answer within the time the law allows. You can also complain to your local data protection authority.
We use your data only where the law allows it: to provide what you asked for (your licence, your purchase, a reply to your email), to meet legal duties (tax records), for our legitimate interest in running a secure website (server logs), or with your consent (the launch email).
How long we keep data
- Emails: as long as needed to help you, and deleted when you ask.
- Launch list: until we have sent the launch email, or until you ask us to remove you.
- Purchase records: as long as tax and accounting law requires.
- Server logs: for the limited period set by our web host.
Children
Orcylo is not directed at children, and we do not knowingly collect data from them.
Changes
If this policy changes, we update this page and its date. If a change affects what the app sends, we say so in the release notes of the update that brings it.