Privacy Policy

Chorsu is developed and published by Sardorbek Rakhimov, an independent developer (“we”). This policy explains what data Chorsu — the Mac App Store edition, the planned Chorsu Direct edition, and this website — handles, and what never leaves your Mac. For anything in this policy, contact s.rakhimov97@gmail.com.

Your content stays on your Mac

Everything you create in Chorsu — projects, tasks, notes, captures, reminders, and dependencies — is stored in a local database on your device. There is no account to create and no cloud sync: Chorsu does not sync your data between devices. The Mac App Store edition and, when available, the planned Chorsu Direct edition each keep their own separate local workspace.

Data that leaves your Mac

Chorsu contains no advertising and does not use advertising identifiers. There is no Chorsu account, and the app itself never asks for your name or email address. It uses RevenueCat for purchase verification and two limited upgrade signals, and Sentry for diagnostics you can turn off. These flows are described below.

Crash and hang reports (both editions)

If Chorsu crashes or stops responding, a diagnostic report is sent to Sentry, hosted in the European Union, so the problem can be found and fixed. A report contains a stack trace, your macOS version, and your Mac’s hardware model. Reports are scrubbed before sending: no task text, project names, or anything else you wrote; no username; no device name. They are not linked to your identity and are not used for tracking. Diagnostics are on by default; turning them off in Chorsu Settings → Diagnostics stops all future reports. Reports are retained on Sentry’s systems as described in Sentry’s privacy policy.

Purchases — Mac App Store edition

Chorsu Pro is a one-time purchase processed by Apple; your payment details stay with Apple and never reach us. To check whether Pro is unlocked, the app verifies the purchase through RevenueCat under a random, anonymous identifier — no email, name, or device identifier is attached, and we cannot tell which purchase record belongs to which person. The app also sends two anonymous product signals through RevenueCat: that the upgrade screen was shown, and that the free tier’s project limit was reached. These exist only to tell whether the upgrade offer works; they are not linked to you and are not used for tracking.

Purchases and licensing — planned Chorsu Direct edition

If Chorsu Direct becomes publicly available and you buy it, checkout is handled by Polar as the merchant of record: Polar collects your email address and payment details under Polar’s privacy policy. Unlike the records above, these are identifiable: we can access your order and license record (including your email address and license key) in Polar’s dashboard, and we use it to fulfill the purchase, administer and enforce the license, help with issues you raise, and meet legal obligations. When you activate a license, the app sends the license key, an activation identifier, and a per-installation identifier for your Mac to Polar to enforce the license’s two-Mac limit; Polar can link an activation to its order through the license key.

Sharing you control

Local AI task access (MCP)

Off by default. If you enable AI task access in Settings, Chorsu runs a listener reachable only on your own Mac (127.0.0.1), protected by a token, so AI clients you configure can read your tasks and preview or apply task plans. What a connected client does with that data is governed by that client’s own terms — connect only clients you trust.

Codex (planned Chorsu Direct only)

Planned for Chorsu Direct, off by default, and not included in the Mac App Store edition. If you select the optional Codex integration in Chorsu Direct, your capture text and project context are sent to OpenAI through your own locally installed Codex and your own account, under OpenAI’s privacy policy. Chorsu never reads or stores your Codex credentials.

This website

The servers that host this website log basic request data — IP address, browser user agent, requested page, and time — as part of serving and securing the site, as any web host does. The site itself sets no cookies and has no analytics, forms, or third-party embeds.

Sentry, RevenueCat, and Polar receive from Chorsu only the data described on this page and are required, under the terms governing their services and applicable law, to protect it to a standard consistent with this policy. Apple and Polar also collect purchase data directly from you at checkout, under their own linked policies. Services you connect yourself — MCP clients and the Codex integration — are chosen by you and governed by their own terms.

Your choices, retention, and deletion

We keep no copy of your content, so there is nothing for us to retain, recover, or hand over. What you can control:

Children

Chorsu is not directed at children, and we do not knowingly collect personal data from children.

Changes to this policy

We may update this policy as Chorsu changes. The current version is posted on this page, with its date above.

Contact

Sardorbek Rakhimov — s.rakhimov97@gmail.com