Skip to content

Legal

Privacy Policy

Last updated October 8, 2026

This policy explains what information the Plip website and the Plip app for macOS handle, where it goes, and the choices you have. Plip is an open-source project, so you can always check the code to see exactly what it does.

The short version

  • Plip runs on your Mac. We never receive your screen, voice, files or conversations.
  • You sign in to the app with Google once. Your account holds your name and email, nothing you do with Plip.
  • When you ask Plip something, it goes to the AI service you connected, under your own account.
  • This website collects your email only if you join the Pro waitlist or ask for the download link, and uses analytics cookies only if you accept them. No ads.
  • We never sell your data, and we never use it to train AI models.

01What this website collects

  • Your email, if you join the waitlist. When you sign up for Plip Pro early access we store your email address and which form you used. It's kept by our email provider, EmailOctopus, and used only to tell you about Plip Pro and Plip updates. Like most email services, EmailOctopus may record whether an email was opened or a link was clicked. Every email has an unsubscribe link.
  • Your email, if you ask for the download link. On a phone or PC you can have the Mac download link emailed to you. We store that address with EmailOctopus the same way, to send the link and, unless you unsubscribe, the occasional Plip update.
  • Basic server data. The site is hosted on Cloudflare, which processes technical details like your IP address, browser type and the pages you request so it can deliver the site and protect it from abuse. Cloudflare may set strictly necessary security cookies to tell people from bots.
  • Page-load statistics, without cookies. Cloudflare Web Analytics counts visits and measures how fast pages load (for example the page you viewed, the site that sent you, your country, browser and device type, and load times). It doesn't use cookies or local storage and doesn't follow you across sites, so it runs for every visit. We see it only as totals. The Download button also passes through this site, which may count clicks by button, country and type of device, without cookies or any ID.
  • GitHub. The app is downloaded from GitHub, and the maintainer's avatar loads from it, so GitHub sees your IP address when your browser fetches them. Release info and star counts are looked up by this site's server, so your browser doesn't contact GitHub for those.
  • Analytics, only if you accept. The first time you visit, the site asks whether it can use analytics cookies. Until you say yes, nothing is tracked or stored. If you accept, our analytics provider, PostHog, records which pages you view, what you click (such as the download, GitHub and waitlist buttons), how far you scroll, the page that sent you here and any campaign tags in the link, your browser, device and approximate location from your IP address. It also records your session (where you move, click and scroll) so we can see where the site is confusing; everything you type into forms is hidden from these recordings. PostHog keeps a random ID in a cookie and your browser's local storage to recognise your visits. These requests pass through this site's own address on their way to PostHog, so they look like part of the site.
  • Joining the waitlist with analytics on. If you've accepted analytics and join the waitlist, we link your visits to a one-way hash of your email address (not the email itself), so we can see what led to signing up. We don't send your email to PostHog.
  • Changing your mind. Decline, or change your choice any time with the button below. Declining or withdrawing stops tracking and deletes PostHog's cookies from your browser.
  • No ads. We don't use ad pixels or advertising cookies, and our fonts are served from this site rather than a third party. The site remembers your cookie choice in local storage so it doesn't ask again, and, if you accepted analytics, keeps a link's campaign tags in session storage until you close the tab.

02What the Plip app does with your data

Plip runs locally on your Mac. We don't run servers that receive your screen, voice, files, prompts or answers. Here's where your information goes when you use it:

  • Your account. The first time you open Plip, you sign in with Google. Sign-in goes through our account provider, Supabase: Google shares your name, email address and profile picture with it, and we keep your name, email, which provider you used, when you joined and when you last signed in. We don't keep your picture. We ask Google only for basic profile access (openid, email, profile), never your Gmail, Drive, contacts or calendar. On your Mac, Plip keeps your name, email and sign-in session in ~/.config/mcp-vision/account.json, readable only by your user account, and renews the session once each time it starts. What you ask Plip, your screen, memory and history are never sent to Supabase or tied to your account.
  • Your AI provider. When you ask Plip something, it sends your request, the recent conversation and a summary of what Plip knows about you, plus screenshots and a map of the controls on screen when the question needs them, to the service you connected: Claude, ChatGPT, Cursor, Gemini or the Anthropic API. That happens under your own account, and that provider's terms and privacy policy apply, including whether it uses your data for training.
  • What Plip knows about you. Your memory lives in a file on your Mac (~/.config/mcp-vision/memory.json) that only your user account can read. Plip looks for passport, card and Social Security numbers, stores them privately and holds them back from the model. Detection is automatic and may not catch every format, so it's best not to put highly sensitive details in your requests. You can view, edit or delete your memory at any time.
  • Your voice. By default Plip uses Apple's speech recognition, which Apple's privacy policy covers. Switch listening to Parakeet and your voice never leaves your Mac. Parakeet's model is a one-time download from Hugging Face.
  • Optional services. If you add a key for AssemblyAI, ElevenLabs or Typesafe, Plip sends those services what the feature needs (your audio, the text to speak, or your request for routing), under your account with them.
  • Websites Plip opens for you. When Plip searches the web or opens a site like Google Flights for you, that site's own privacy policy applies.
  • Permissions. Plip asks for Screen Recording, Accessibility and Microphone so it can see what you're looking at, click and type for you, and hear you. You can turn them off any time in System Settings → Privacy & Security.
  • Usage history. The Usage tab's record of your requests stays on your Mac.
  • An anonymous daily check-in. So we can count how many people use Plip, the current version of the app sends one event a day to our analytics provider, PostHog: a random install ID and the Plip, macOS and Python versions (PostHog also sees the IP address it came from, which we don't use). It never includes what you say, your screen, files, web addresses or anything about you, and the random ID is never linked to your account. To turn it off, run launchctl setenv MCP_VISION_NO_ANALYTICS 1 in Terminal and reopen Plip (again after each restart). We plan to make this an opt-in choice in setup.
  • Bug reports and feature requests. Only when you press Send in Settings → General, Plip sends what you typed, through PostHog. A bug report can also include your last request if you tick the box; Plip removes emails, phone numbers, long numbers, web page paths, file paths and anything it knows about you first, and shows you the exact text before it's sent.

03How we use information

We use the little information we get to:

  • send you the Plip Pro and product updates you signed up for;
  • sign you in to the app and know who uses Plip;
  • read and reply to bug reports and feature requests;
  • run the website, keep it secure and stop abuse;
  • if you accepted analytics, understand how people find and use the website so we can improve it;
  • count how many people use Plip, so we know what to build next.

If you're in the EEA or UK: we email you, and run website analytics, based on your consent, which you can withdraw by unsubscribing or changing your cookie choice. We handle your account to provide the app you asked to use, and handle bug reports, run and secure the site and count usage based on our legitimate interest in keeping Plip working.

04Who we share it with

We don't sell or rent personal information, and we don't share it for advertising. We only share it with the services that help us run Plip:

  • EmailOctopus stores the waitlist and sends our emails.
  • Cloudflare hosts the website and the waitlist signup, and provides cookieless page-load statistics.
  • Supabase runs sign-in and stores your account (name, email, sign-in dates).
  • Google confirms who you are when you sign in.
  • PostHog receives website analytics (if you accepted them), the app's anonymous daily check-in, bug reports and feature requests.
  • GitHub hosts the source code, downloads and issue tracker.

We may also disclose information if the law requires it, or when it's needed to protect the rights and safety of others.

05How long we keep it

We keep your waitlist email until you unsubscribe or ask us to delete it, and your Plip account until you ask us to delete it. Signing out only removes it from your Mac. Bug reports and feature requests are kept while we work on them, and usage stats only as counts. We keep website analytics only as long as they're useful for improving the site, and delete yours if you ask. PostHog's cookie expires a year after your last visit. Cloudflare and PostHog keep logs for a limited time under their own policies.

06Your rights

Depending on where you live, including the EEA, the UK and US states like California, you may have the right to see, correct, delete or export the personal information we hold about you, and to object to or limit how we use it. You can withdraw consent at any time.

To stop emails, use the unsubscribe link in any of them. For anything else, email team@plip.dev. We aim to reply within 30 days, and we won't treat you differently for using your rights. To delete your Plip account, email us from the address you signed in with. The app's usage stats use a random ID, so we usually can't tie them to you, and they're never linked to your website visits. You can also complain to your local data protection authority.

We don't sell or share personal information for targeted advertising, so there's nothing for a Do Not Track or Global Privacy Control signal to turn off.

Plip's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use your Google name and email only to sign you in and run your account, never for ads, and we never sell it or use it to train AI models.

07Security

The site is served over HTTPS, and keys for our email provider stay on the server, never in your browser. In the app, your memory file is readable only by your user account. No system is perfectly secure, so we can't guarantee the security of information, but we work to protect what we hold.

08International transfers

We and our service providers may process data outside your country, including in the United States. Where the law requires it, they use safeguards such as Standard Contractual Clauses.

09Children

Plip isn't meant for children under 13, or under 16 in the EEA and UK, and we don't knowingly collect their personal information. If you think a child has given us their email, contact us and we'll delete it.

10Changes to this policy

If we change this policy, we'll update the date at the top of this page. If a change is significant, we'll also say so on the site or by email.

11Contact

Plip is an independent open-source project run by its maintainer, Hussain ("we", "us"). Questions or requests about your data? Email team@plip.dev.

Downloading Plip

You're almost there.

  1. 1

    Drag Plip into Applications

    Open the downloaded .dmg and drag Plip into your Applications folder, then open it.

  2. 2

    Sign in with Google

    Plip asks Google only for basic profile info (name, email and picture, which isn't kept). Nothing you ask Plip is tied to your account.

  3. 3

    Allow its permissions

    Screen Recording to see what you're looking at, Accessibility to click and type for you, and Microphone to hear you. macOS may also ask about Speech Recognition, and the first time Plip works in apps like Finder.

  4. 4

    Connect your AI

    Pick Claude, ChatGPT, Cursor or Gemini and sign in to the plan you already have. Claude connects in one click; the others need their command-line app first, and Plip gives you the command.

Then hold ⌃⌥ (Control + Option) and say what you need.

If macOS won't open Plip, go to System Settings → Privacy & Security and click Open Anyway. Download didn't start? Try again. Stuck? Ask on GitHub.