Last updated: 19 July 2026
Sentry Notch runs entirely on your Mac. It does not have an account system, it
does not collect analytics, and it has no server to send your data to.
The app reads your Claude Code transcripts and the tool calls your agents want
to make. That content — source code, shell commands, file paths, client names —
never leaves your machine.
| Data | Why | Where it goes |
|---|---|---|
~/.claude/projects/**/*.jsonl (session transcripts) | To show live session cards and the activity feed | Read into memory only |
Pending tool calls, via the PreToolUse hook | To show you the permission prompt you are answering | Held in memory until you answer |
| Your decisions | Written to a local audit log so you can review what was allowed | decisions.jsonl, on your disk |
| Context-token counts | The analytics trend | tokens.jsonl, on your disk |
| Now-playing track (if the Spotify widget is on) | To draw the widget | Read from the local Spotify app; not stored |
Everything the app writes lives in:
`
~/Library/Application Support/SentryNotch/
`
That directory is created with 0700 permissions (owner-only). It is not inside
iCloud Drive and is not synced anywhere by the app.
It will contain sensitive material. The audit log records the commands and
file paths your agents proposed. On an engagement, that can include client
hostnames and infrastructure detail. Treat it like any other engagement
artefact: it is covered by your disk encryption, your retention policy, and your
scope agreement — not by us, because we never receive it.
You can delete the whole directory at any time. The app recreates only what it
needs.
Three things, all optional and none containing your work:
1. Update check. Once a day the app fetches a static JSON file over HTTPS to
see whether a newer version exists. It is a plain GET with no query string,
no licence key, and no identifier. The request reveals only that some Mac
fetched a public file, plus the IP address inherent in any HTTPS request.
Disable it by blocking the domain; the app keeps working.
2. Album artwork, only if the Spotify widget is switched on. When the track
changes, the app downloads the cover image from Spotify's own CDN
(i.scdn.co) using the URL Spotify's local app hands it. It is a plain image
GET, fetched once per track, carrying no account or licence information — and
it concerns a track Spotify already knows you are playing. Turn the Spotify
widget off in Dashboard ▸ Widgets and no request is ever made.
3. Nothing else. Licence validation is done offline, on-device, using a
signature. The app never transmits your licence key, your email, or a machine
fingerprint. Your transcripts, commands, and decisions are never sent
anywhere at all.
Purchases are handled by our payment provider, who acts as merchant of record.
They collect the billing details needed to process the sale and to meet tax
obligations. We receive your email address and an order reference so we can
issue a licence key and answer support requests. We never see your card number.
The payment provider's own privacy policy governs the checkout. Refunds and
billing questions are handled through them.
An email address and order reference, so a licence can be re-issued if you lose
it. Nothing else. No usage data, no telemetry, no crash reports.
Email sp1r4.work@gmail.com to get a copy of what we hold (an email address
and an order reference), to correct it, or to have it deleted. Deleting it means
we can no longer re-issue your key, but any key already installed keeps working
— it validates offline.
Use email rather than the public issue tracker for anything involving your
personal data: an issue is visible to everyone, and a request to delete your
information should not require you to publish it first.
The app is a developer tool and is not directed at anyone under 16.
Material changes will be noted in the release notes and dated at the top of this
document. The app does not silently start collecting anything.
Bugs and questions: https://github.com/sp1r4/sentrynotch/issues
Privacy and data requests: sp1r4.work@gmail.com