Privacy Policy

Effective September 5, 2026

1. Who we are

Rocky is provided by Bald Cactus, LLC (“Bald Cactus,” “we,” “us,” or “our”). This Privacy Policy applies to the Rocky macOS application, rocky.so, api.rocky.so, and related support communications.

2. Information Rocky processes

Content you choose to process

Depending on the features and engines you select, Rocky may process microphone audio, transcripts, prompts, model responses, screenshots, recent conversation context, task instructions, and bounded text or interface context from applications, files, or Rocky's isolated browser profile.

Service, device, and security data

The hosted service processes a randomly generated installation identifier, your Rocky account identifier, authentication tokens, IP address, route and request timing, response status, quota counters, usage category, app version, and technical information needed to operate, secure, troubleshoot, and meter the service. The hosted service requires a Rocky account, which you create from within Rocky. Accounts and sign-in are operated for us by Supabase, and paid credit purchases are processed by Stripe; we never receive or store your card details.

Product analytics

Rocky sends PostHog (US cloud) a fixed allowlist of metadata-only product events: app lifecycle, sign-in and sign-out, voice turn and dictation completion with the selected route and outcome, settings changes, engine crashes (the exit signal or status and whether Rocky was quitting) and internal errors (the source file and line, never the error text), and — from the hosted service — request path, response status, timing, request size, quota position, and coarse country-level location derived at the network edge (never your IP address). These account-linked events never include prompts, transcripts, audio, model responses, screenshots, API keys, or raw error text.

Before you sign in, events are recorded under a random installation identifier. When you sign in, that identifier is linked to your Rocky account so we can understand usage and investigate problems per-account.

Statistics about which AI models handle your requests and roughly how many tokens they use are recorded separately under a pseudonymous identity — a one-way code derived from your account with a secret key. These records connect to each other but do not name your account, carry no location, and use rounded token counts.

Optional conversation sharing (off by default): any account, free or paid, can choose to share conversation content to help improve Rocky via Settings → Privacy → “Share conversations to improve Rocky.” When — and only when — you turn this on, the text of your conversations with Rocky — your prompts and the assistant's replies, on both the Rocky-hosted route and the Local route, with voice conversations included as their text transcripts — is recorded under the same pseudonymous identity described above, not linked to your account. Sharing is text-only: your voice audio itself is never recorded and screenshots are never recorded. You can turn sharing off at any time and it stops immediately. If you never turn it on, no conversation content of any kind is collected.

Product analytics are on by default for all accounts. Paid accounts can turn them off in Settings → Privacy, which stops both the account-linked and pseudonymous events. We do not sell this information or share it with advertisers.

Website analytics

rocky.so uses PostHog to measure page visits, clicks, and downloads so we can understand how people find and install Rocky. This processes page-level activity and technical information such as IP address, browser, and referring page. Website analytics are separate from the application setting described above, are not controlled by it, and do not include your email address or anything you type into the page.

Communications

If you contact us, we receive the contact details and message content you provide so we can respond and maintain a support record.

3. What stays on your Mac

These local stores stay on your Mac and are not synced to us. Content needed for a request may be sent as described in “Where content goes” below. You can remove local data by clearing the relevant history, deleting an item permanently, or removing Rocky and its supporting data. Deleting a Library item first moves it to Trash, where it remains recoverable for 30 days before Rocky removes it permanently. You can delete it permanently or empty the Trash sooner.

You can review recent outbound receipts, change capture settings, review and delete individual remembered facts, clear your clipboard history, disable analytics (on paid accounts), and clear Rocky's browser profile from the app.

4. Where content goes

Local speech and privacy features run on your Mac. When a selected feature requires a cloud provider, Rocky sends only the content needed for that request.

Rocky's hosted-service database does not intentionally store request audio, transcripts, screenshots, prompts, or model responses. Hosted requests are transmitted to fulfill the request. Cloud and website providers may process and retain data under their own agreements and privacy policies.

5. Why we process information

We process information to:

Where applicable, our legal bases include performing our agreement with you, your consent, our legitimate interests in operating and securing Rocky, and compliance with law.

6. How we disclose information

We disclose information to service providers described above only as needed to provide Rocky, and may disclose information when required by law, to protect users or the service, or as part of a merger, acquisition, financing, or sale of assets. We do not sell personal information or share it for cross-context behavioral advertising.

7. Retention

Local data remains until it is cleared by you, expires under an in-app setting, or is removed with the application and its supporting data. Library items moved to Trash remain recoverable for 30 days unless you delete them permanently sooner. Hosted rate counters expire after their security or quota windows. Installation, usage, and ledger records are retained as long as reasonably necessary to operate the service, enforce limits, prevent abuse, resolve disputes, and meet legal obligations. Support communications are retained as needed to respond and maintain appropriate business records.

Third-party providers determine their own retention under the applicable service terms. Requests made with your own model account are governed by the agreement between you and that provider.

8. Your choices and rights

Rocky provides controls for screen capture scope, protected applications, local OCR redaction, review before sending, analytics (on paid accounts), optional conversation sharing (off by default, any account), remembered facts, clipboard history, and local browser data. You can select on-device speech engines or “No screen” mode where available.

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal information, or withdraw consent. Contact us to exercise a right. We may need information sufficient to locate the relevant installation record and verify the request.

9. Security

We use technical and organizational safeguards designed to protect information, including Keychain storage, encrypted network connections, bounded request contracts, local redaction controls, and access restrictions. No system is completely secure, and Rocky's privacy detection is defense in depth rather than a guarantee.

10. Children

Rocky is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided information to Rocky.

11. International processing

Bald Cactus and its providers may process information in the United States and other countries. Those countries may have different data protection laws. Where required, appropriate transfer safeguards apply.

12. Updates and contact

We may update this policy as Rocky changes. The effective date above identifies the latest version. Material changes may also be announced through the app or website.

Privacy questions and requests can be sent to question@rocky.so.