Privacy Policy
Effective September 5, 2026
1. Who we are
Rocky is provided by Bald Cactus, LLC (“Bald Cactus,” “we,” “us,” or “our”). This Privacy Policy applies to the Rocky macOS application, rocky.so, api.rocky.so, and related support communications.
2. Information Rocky processes
Content you choose to process
Depending on the features and engines you select, Rocky may process microphone audio, transcripts, prompts, model responses, screenshots, recent conversation context, task instructions, and bounded text or interface context from applications, files, or Rocky's isolated browser profile.
Service, device, and security data
The hosted service processes a randomly generated installation identifier, your Rocky account identifier, authentication tokens, IP address, route and request timing, response status, quota counters, usage category, app version, and technical information needed to operate, secure, troubleshoot, and meter the service. The hosted service requires a Rocky account, which you create from within Rocky. Accounts and sign-in are operated for us by Supabase, and paid credit purchases are processed by Stripe; we never receive or store your card details.
Product analytics
Rocky sends PostHog (US cloud) a fixed allowlist of metadata-only product events: app lifecycle, sign-in and sign-out, voice turn and dictation completion with the selected route and outcome, settings changes, engine crashes (the exit signal or status and whether Rocky was quitting) and internal errors (the source file and line, never the error text), and — from the hosted service — request path, response status, timing, request size, quota position, and coarse country-level location derived at the network edge (never your IP address). These account-linked events never include prompts, transcripts, audio, model responses, screenshots, API keys, or raw error text.
Before you sign in, events are recorded under a random installation identifier. When you sign in, that identifier is linked to your Rocky account so we can understand usage and investigate problems per-account.
Statistics about which AI models handle your requests and roughly how many tokens they use are recorded separately under a pseudonymous identity — a one-way code derived from your account with a secret key. These records connect to each other but do not name your account, carry no location, and use rounded token counts.
Optional conversation sharing (off by default): any account, free or paid, can choose to share conversation content to help improve Rocky via Settings → Privacy → “Share conversations to improve Rocky.” When — and only when — you turn this on, the text of your conversations with Rocky — your prompts and the assistant's replies, on both the Rocky-hosted route and the Local route, with voice conversations included as their text transcripts — is recorded under the same pseudonymous identity described above, not linked to your account. Sharing is text-only: your voice audio itself is never recorded and screenshots are never recorded. You can turn sharing off at any time and it stops immediately. If you never turn it on, no conversation content of any kind is collected.
Product analytics are on by default for all accounts. Paid accounts can turn them off in Settings → Privacy, which stops both the account-linked and pseudonymous events. We do not sell this information or share it with advertisers.
Website analytics
rocky.so uses PostHog to measure page visits, clicks, and downloads so we can understand how people find and install Rocky. This processes page-level activity and technical information such as IP address, browser, and referring page. Website analytics are separate from the application setting described above, are not controlled by it, and do not include your email address or anything you type into the page.
Communications
If you contact us, we receive the contact details and message content you provide so we can respond and maintain a support record.
3. What stays on your Mac
- Rocky's hosted-service token, and the credential for any model account you sign in to, are stored in the macOS Keychain.
- Preferences, privacy settings, and engine selections are stored locally.
- Tasks you ask Rocky to run are kept in a local database in Application Support so they survive a restart and so you can find them again later. Task history is durable: it is paged and searchable rather than cleared when Rocky quits.
- Your Library stores screenshots, saved links, text notes, and research results locally, together with their titles, descriptions, tags, source information, thumbnails where available, and a searchable index.
- Saved window layouts are stored locally and include application names and identifiers, window titles, display identifiers, and window positions and sizes.
- Facts Rocky remembers about you — either because you asked it to or because it observed them — are stored locally in a bounded list you can review and delete entry by entry.
- Your clipboard history is stored locally: an index file plus copied images and thumbnails, kept beside the engine database. Anything an application marks as confidential, such as a password manager entry, is never recorded.
- Rocky's own browser keeps its profile — cookies, history, and website sessions — separate from any other browser on your Mac, until you clear that profile.
- On-device speech models are downloaded and stored locally when you choose them.
These local stores stay on your Mac and are not synced to us. Content needed for a request may be sent as described in “Where content goes” below. You can remove local data by clearing the relevant history, deleting an item permanently, or removing Rocky and its supporting data. Deleting a Library item first moves it to Trash, where it remains recoverable for 30 days before Rocky removes it permanently. You can delete it permanently or empty the Trash sooner.
You can review recent outbound receipts, change capture settings, review and delete individual remembered facts, clear your clipboard history, disable analytics (on paid accounts), and clear Rocky's browser profile from the app.
4. Where content goes
Local speech and privacy features run on your Mac. When a selected feature requires a cloud provider, Rocky sends only the content needed for that request.
- Rocky-hosted route: requests pass through infrastructure operated with Cloudflare and then to OpenAI.
- Local route: requests made with your own signed-in model account go directly from your Mac to that provider and bypass the Rocky-hosted service. If you opted in to conversation sharing, the text of those conversations is still shared as described above.
- Product analytics: allowlisted metadata-only events go to PostHog; paid accounts can turn this off.
- Website analytics: page-level activity on rocky.so goes to PostHog.
- Browser and automation features: websites and applications you direct Rocky to use receive information according to your actions and their own policies.
Rocky's hosted-service database does not intentionally store request audio, transcripts, screenshots, prompts, or model responses. Hosted requests are transmitted to fulfill the request. Cloud and website providers may process and retain data under their own agreements and privacy policies.
5. Why we process information
We process information to:
- provide transcription, conversation, speech, screen understanding, and user-directed automation;
- authenticate installations, apply quotas, prevent abuse, and secure the service;
- maintain local preferences, approved tasks, and privacy controls;
- diagnose failures and improve Rocky when analytics are enabled;
- respond to support requests and comply with legal obligations.
Where applicable, our legal bases include performing our agreement with you, your consent, our legitimate interests in operating and securing Rocky, and compliance with law.
6. How we disclose information
We disclose information to service providers described above only as needed to provide Rocky, and may disclose information when required by law, to protect users or the service, or as part of a merger, acquisition, financing, or sale of assets. We do not sell personal information or share it for cross-context behavioral advertising.
7. Retention
Local data remains until it is cleared by you, expires under an in-app setting, or is removed with the application and its supporting data. Library items moved to Trash remain recoverable for 30 days unless you delete them permanently sooner. Hosted rate counters expire after their security or quota windows. Installation, usage, and ledger records are retained as long as reasonably necessary to operate the service, enforce limits, prevent abuse, resolve disputes, and meet legal obligations. Support communications are retained as needed to respond and maintain appropriate business records.
Third-party providers determine their own retention under the applicable service terms. Requests made with your own model account are governed by the agreement between you and that provider.
8. Your choices and rights
Rocky provides controls for screen capture scope, protected applications, local OCR redaction, review before sending, analytics (on paid accounts), optional conversation sharing (off by default, any account), remembered facts, clipboard history, and local browser data. You can select on-device speech engines or “No screen” mode where available.
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal information, or withdraw consent. Contact us to exercise a right. We may need information sufficient to locate the relevant installation record and verify the request.
9. Security
We use technical and organizational safeguards designed to protect information, including Keychain storage, encrypted network connections, bounded request contracts, local redaction controls, and access restrictions. No system is completely secure, and Rocky's privacy detection is defense in depth rather than a guarantee.
10. Children
Rocky is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided information to Rocky.
11. International processing
Bald Cactus and its providers may process information in the United States and other countries. Those countries may have different data protection laws. Where required, appropriate transfer safeguards apply.
12. Updates and contact
We may update this policy as Rocky changes. The effective date above identifies the latest version. Material changes may also be announced through the app or website.
Privacy questions and requests can be sent to question@rocky.so.