Privacy
Anclave for macOS · updated 20 August 2026
Anclave runs on your Mac and has no account. Everything it reads about your day stays on the machine it was read on: what is playing, what is in your calendar, what you copied, how long you have been at it. None of that is transmitted anywhere.
What it reads
- Calendars. Your events for the day being shown — title, time, colour and any conference link — so the panel can list them and count down to the next one. Read only; Anclave never creates, edits or deletes an event.
- What is playing. Track, artist, artwork and position, from whichever app macOS reports as playing.
- The clipboard. What you copy, kept on your Mac so you can paste it again. Anything an app marks as a password or as transient is skipped and never stored.
- Screenshots. New files in the folder macOS saves screenshots to. The files stay where they are; Anclave keeps a list of paths.
- Which app is in front, and how long since you last touched the Mac, to draw the day’s activity chart and to suggest a break. Optionally, the same figures from macOS Screen Time, which requires Full Disk Access.
Google Calendar
If you sign in with Google, Anclave asks only for calendar.readonly — permission to read your calendars and nothing else. The sign-in happens in your browser; Anclave never sees your Google password.
The token Google issues is stored in your Mac’s Keychain and used only to request the events for the day on screen. Those events are held in memory while the app runs. Nothing about them is written to a server, shared, sold, or used for training or advertising. Signing out in Settings deletes the token.
Who Google user data is shared with
Nobody. Anclave does not share, transfer, sell or otherwise disclose Google user data to any third party. There is no Anclave server: your events travel from Google to your Mac and stop there. They are not sent to the developer, to an analytics service, to an advertising network, or to any human being, and they are never used to develop, improve or train any model, including generalised or artificial intelligence models.
The two things Anclave does send — feedback you write yourself and crash reports — carry no calendar data of any kind. They are described under “What leaves your Mac” below.
Anclave’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How it is protected
- The refresh token Google issues is stored in the macOS Keychain, which is encrypted by the system and unlocked by your login password. It is never written to a file, a log or a preference.
- Every request to Google is made over HTTPS with TLS. There is no other network destination for calendar data, because there is no server to send it to.
- Your events are held in memory only, for as long as the panel is showing that day. They are not written to disk, not cached and not indexed.
- The app is signed with an Apple Developer ID, notarised by Apple, and runs under the hardened runtime, so the copy on your Mac is the copy that was built and it cannot be modified without the signature breaking.
- Anclave is a single-person project with no staff and no contractors. Nobody has an account through which Google user data could be read, because no such account exists.
How long it is kept, and how to delete it
- Events: kept in memory while the app is running and discarded when the day on screen changes or when Anclave quits. Nothing is retained after that.
- The token: kept in the Keychain until you remove it. Press Disconnect in Anclave’s Settings, under Calendar, and it is deleted from the Keychain immediately along with the account address. Deleting the app removes it as well.
- Revoking from Google’s side: you can withdraw Anclave’s access at any time at myaccount.google.com/permissions. Anclave stops reading your calendar the moment you do.
- If you want it gone by hand: write to help@plkv.works and it will be confirmed to you, though there is nothing on any server of ours to delete.
What leaves your Mac
Four things. A check for a new version, against plkv.works. A download when you accept one. Feedback you write and send, which travels to a private issue tracker with the message, the version, your macOS version, and the screenshot of the panel shown in the window before you press Send.
And crash reports: a stack trace when Anclave crashes, and one line each time it starts saying that a copy of this version is running. That second line is how many people use Anclave is counted at all, since a download only says somebody was curious. They go to Sentry, on servers in Germany, with a random id for this installation and without your IP address. Nothing you have read, copied or listened to travels with them. Turn them off under Settings, General, Privacy.
Nothing else.
Contact
Questions, or a request to delete anything you have sent: help@plkv.works.