Privacy Policy

Last updated on September 9, 2026.

This Privacy Policy explains how Consalik AB collects, uses, discloses, and protects information when you use Hindsight’s website, downloads, macOS application, license activation, updates, documentation, and related services, collectively the Services.

Hindsight is designed to keep your timeline on your Mac. The app captures, processes, transcribes, indexes, searches, and stores your history locally unless you choose to send information to us or a third-party service yourself.

Information Hindsight Processes Locally

Depending on your settings and macOS permissions, the Hindsight app may process information such as:

  • Screen frames and thumbnails captured from your Mac.
  • Text detected from screen captures through local OCR.
  • Microphone audio, system audio, and local audio transcripts when audio capture is enabled.
  • Window titles and app identities, read locally to recognize when you join a video call.
  • Calendar event details, such as event titles, start and end times, and video conference links, read locally to name meeting recordings when Calendar Sync is on and calendar access is granted.
  • Meeting recordings, including full screen video, audio, a local transcript, text recognized from that video through local OCR, and a still frame taken from that video to picture the recording, when you choose to record a meeting.
  • App names, app bundle identifiers, window titles, timestamps, browser URLs, and similar context.
  • Search queries, settings, app exclusions, retention preferences, and local usage state.

This timeline data is stored locally on your Mac. We do not receive your screen images, audio, OCR text, transcripts, window titles, browser URLs, search queries, or local history from the app unless you choose to send that information to us, for example in a support request.

If notifications are allowed, Hindsight may send local status notifications when recording stops without you stopping it, such as when your Mac switches to battery power, when a permission is revoked, or when recording runs into a problem. These notifications say only that recording stopped and why, never what was recorded. You can disable them in Hindsight’s settings or turn off notifications in macOS System Settings.

Local Storage and Security

Hindsight stores local history in encrypted local storage. Encryption keys are stored in macOS Keychain. Local data remains under your control on your Mac, subject to your device security, operating system account, backups, file sharing settings, malware protection, and anyone else who can access your Mac.

You can delete all local data from Hindsight’s settings. This removes everything Hindsight has recorded on your Mac, including screen history, recognized text, audio transcripts, thumbnails, meeting recordings with their video and transcripts, the temporary decrypted copies made for meeting playback, and the local caches and prompt records derived from them. Hindsight removes its local storage entirely rather than emptying it, and discards the Keychain encryption keys that protected it, so the disk space it used returns to your Mac and nothing readable is left behind. A new encrypted store is created the next time Hindsight records something. It cannot be undone. Your account, your settings, and downloaded models, both for transcription and for summaries, are kept, and you can delete downloaded models separately when you want to reclaim disk space. Reducing the retention period may remove older local history automatically.

Private Browsing and App Exclusions

Hindsight can skip supported private browser windows, including Chrome Incognito and Safari Private windows, when private browsing exclusion is enabled. This depends on macOS Accessibility permission and browser window context being available.

Hindsight also includes app exclusions so selected apps do not appear in your timeline. Some sensitive apps, such as password managers, may be excluded by default. You should review exclusions before using Hindsight in environments that contain confidential, regulated, workplace, or shared-device information.

Meeting Detection and Meeting Recording

Hindsight recognizes when you join a video call, such as Zoom, Google Meet, Microsoft Teams, or a Slack huddle, by reading the titles of the windows open on your Mac locally. This works whether the call is in a dedicated app or a browser tab, and it does not require calendar access. Hindsight also has a Calendar Sync setting, on by default and switchable in the Meetings section of settings. When it is on and you grant macOS Calendar access, Hindsight reads your calendar locally to name a recording, to know when the meeting is scheduled to end, and to list your upcoming meetings in the menu bar. Turning Calendar Sync off stops Hindsight from reading your calendar at all, and meeting detection and recording keep working without it. Calendar information is used only on your Mac and is never uploaded to us or shared with anyone.

When you join a meeting, Hindsight asks whether to record it, and records nothing until you answer. It asks once per meeting. Your answer is remembered locally in Hindsight’s app preferences, noted against the calendar event or against the app and window title the call was recognized from, and it expires on its own once the meeting is over. A meeting you have already recorded is not offered again. You can change this in Hindsight’s settings to record automatically or to never ask. Recording others may require their consent, and depending on where you are it may be required by law. Asking everyone in the meeting before you record is your responsibility.

If you choose to record, Hindsight records your screen and audio for the length of the meeting and generates a local transcript, then saves them in the same encrypted local storage as the rest of your timeline. Your regular screen and audio capture pauses for the meeting’s duration, so the meeting recording is what covers that time. The local meeting transcript may be organized by microphone audio, system audio, and combined audio, and may include word-level timing. Hindsight also recognizes on-screen text from the meeting video through local OCR, stores it with the recording, and adds frames sampled from the recording to your timeline, so the meeting appears in your local history and can be searched by what was shown. One still frame from the video is saved in the same encrypted local storage and shown as the recording’s picture when you browse your meetings. All of this processing happens on your Mac. You can turn meeting prompts off at any time in Hindsight’s settings, and you can delete individual meeting recordings.

Meeting Summaries

Hindsight can write a summary of a recorded meeting from its local transcript. Summaries are off until you choose what writes them, in the Meetings section of settings, and nothing is summarized before you do. You can choose a model that runs on your Mac, or one of the command line coding tools you have installed and signed in to yourself, currently Claude Code from Anthropic or Codex from OpenAI.

Choosing a model that runs on your Mac keeps the meeting on your Mac. The Models section of settings lists open-weight models you can download, and downloading one contacts Hugging Face and its content delivery network, which may process technical information such as IP address, app user agent, request time, and requested URL, governed by Hugging Face’s own privacy policy. Nothing about your meetings, your account, or your timeline is sent with that request. Once a model is downloaded it runs on your Mac’s own processor, and writing a summary with it needs no network connection and sends nothing to Hugging Face, to us, or to anyone else.

Choosing Claude Code or Codex instead sends that meeting’s transcript off your Mac. Hindsight runs the tool you installed and signed in to, on your Mac, under your own account with its provider, so the transcript reaches Anthropic or OpenAI under your own agreement with them and is handled under their privacy policy and billed to your account rather than to us. Hindsight never sees a credential for either tool. Only the transcript text and the meeting’s title and length are sent. Your recordings, audio, screen history, and the rest of your timeline are never sent. We do not receive the transcript, the summary, or any record of the request.

A summary is stored with its recording in the same encrypted local storage as the rest of your timeline, along with a note of what wrote it. You can clear a summary from a recording, ask for it again, change what writes summaries, or turn them off entirely at any time. Downloaded models stay on your Mac until you remove them, which you can do individually or all at once in the Models section of settings.

Information We Collect From You

We may collect information you provide directly, such as:

  • Your name, email address, messages, attachments, and diagnostic details when you contact support.
  • Feedback, feature requests, bug reports, or other communications you send us.
  • Information needed to respond to privacy, legal, billing, or security requests.

Please avoid sending screenshots, audio, transcripts, logs, or other sensitive material unless it is necessary for your request.

Account, Purchases, Subscriptions, and Billing

To sign in you enter your email address in the Hindsight app, which creates an account identified by that email. We use your email to send one-time sign-in codes and purchase-related messages. When you enter a sign-in code in the app, our backend issues a device token that the app stores locally in the macOS Keychain to keep you signed in on that Mac; we store only a hashed version of that token on our server. A sign-in code expires after fifteen minutes, works once, and is refused after a small number of incorrect attempts. When you sign out, the app asks our backend to revoke that Mac’s device token and clears the local Keychain session. To prevent abuse, we limit how many sign-in codes can be requested from a given network address or sent to a given email address in a short period, using your IP address and the requested email for that purpose.

You can change the address your account is identified by from within Hindsight. We use the new address to send a confirmation code, and nothing changes unless you enter it in the app. When you do, we replace the email stored against your account rather than keeping both, tell Stripe so receipts and billing correspondence follow, and send a notice to your previous address so a change you did not make cannot pass unseen. If the new address already belongs to another Hindsight account, we tell you so and change nothing. We limit how many change requests an account can make in a short period, which also limits how much can be learned about which addresses have accounts.

To run the free trial fairly, the app also generates a random, anonymous device identifier, stored locally in the macOS Keychain, and sends it when you sign in. Our backend keeps only a one-way hash of it to allow one free trial per Mac and to prevent trial abuse, such as repeatedly deleting an account or signing up with new email addresses on the same Mac. This identifier is not linked to your screen content, audio, or local timeline, and is not used for advertising or for tracking you across other apps or websites. See Retention below for how long we keep it.

One-time payments and subscription billing are handled by Stripe, which sells Hindsight as the merchant of record. Card details are entered on Stripe’s secure checkout and are not collected or stored by Hindsight. Because Stripe is the seller, it also collects your name and billing address so it can calculate the tax that applies where you are, and it handles that information as an independent controller for its own legal, tax, and fraud-prevention purposes rather than only on our instructions. That processing is governed by Stripe’s own privacy policy. We receive purchase type, subscription status, plan, billing period, Stripe Checkout and payment identifiers, payment status, purchase timestamps, and related records that we need to provide or revoke access, prevent abuse, support you, and keep billing records. Stripe’s checkout notifications also pass us the name, billing address, and any tax identifier you entered at checkout. We do not store any of it: the only things we keep about your purchase are your email address and Stripe’s identifier for you.

Our entitlement backend runs on Cloudflare, and sign-in, purchase, and account emails are delivered through Resend. The Hindsight app contacts our backend to request and verify sign-in codes, check paid entitlement status, look up current plan prices, change your account email, and open billing or checkout pages. Our website is not involved in signing in. The price lookup identifies no one: it carries no account information and asks only what the plans currently cost.

Alongside sign-in codes, we send a one-time welcome email when you first sign in, covering setup and how long your free trial runs, and a confirmation email when a purchase completes. To make sure you receive each of these only once, we keep a record of which account emails we have sent you, consisting of your account identifier, the type of email, and the date it was sent. We do not keep a copy of the message itself.

You can delete your account at any time from within Hindsight, including from the screen shown when a free trial ends. This immediately cancels any subscription, removes any lifetime entitlement, deletes your server-side account and device tokens, and asks Stripe to delete your customer record. Because Stripe sells Hindsight as the merchant of record, it still keeps the transaction, tax, and accounting records the law requires it to keep, and deleting your Hindsight account does not remove those. It cannot be undone. See Retention below for what this removes and what we may keep.

Crash Reporting and Diagnostics

If enabled in a configured app build, Hindsight may use Sentry for crash reporting, release health, app hang reporting, limited performance diagnostics, sanitized nonfatal error reports, manual diagnostic breadcrumbs, sanitized diagnostic logs, and sanitized aggregate metrics. Hindsight configures Sentry to avoid sending screenshots, view hierarchy, raw Apple unified logs, automatic network breadcrumbs, automatic personal identifiers, device hostnames, and user records.

Diagnostic events may include technical information such as app version, build number, operating system version, environment, crash details, stack traces, app hang stack traces, anonymous session status, coarse operation names, sanitized error categories, error type names, error domains and numeric error codes, fixed error descriptions written by us rather than taken from error payloads, sanitized diagnostic log messages, sanitized numeric metrics such as counters, gauges, and timing distributions for selected app operations, and limited performance timing for selected app operations. Manual network diagnostics use coarse service labels and status classes, not request or response bodies, headers, sign-in tokens, full URLs, screenshots, transcripts, OCR text, window titles, browser URLs, search queries, or local history. We use this information to find, debug, and fix reliability and performance problems.

Website, Downloads, and Updates

When you visit the website, download Hindsight, or check for updates, our hosting providers, GitHub, Sparkle update infrastructure, or similar providers may process technical information such as IP address, browser or app user agent, request time, requested URL, download metadata, and server logs.

Hindsight uses this information to provide the website, downloads, release notes, update feeds, security checks, troubleshooting, fraud prevention, and basic service operations.

Our website uses Umami for privacy-friendly visitor analytics. Umami does not use cookies, does not store your IP address, and does not follow you across other websites or apps. It records aggregate visit information such as the page you viewed, the referring site, your browser, operating system, device type, screen size, and the country your visit came from. It is configured to leave out anything a page address carries beyond the page itself. None of it is linked to your Hindsight account, your purchases, or anything in your local timeline. Umami’s processing is governed by its own privacy policy. This analytics runs only on our website and is not part of the Hindsight app.

How We Use Information

We use information we collect or receive to:

  • Provide, maintain, update, secure, and troubleshoot the Services.
  • Manage your account and paid entitlement, process payments, prevent abuse, and provide customer support.
  • Investigate bugs, crashes, performance issues, fraud, security events, and policy violations.
  • Respond to support, privacy, legal, and billing requests.
  • Comply with applicable law and enforce our Terms of Service.

How We Share Information

We do not sell your personal information. We do not use your local Hindsight timeline to train AI models. We may share information with service providers that help operate the Services, such as backend hosting (Cloudflare), email delivery (Resend), crash reporting (Sentry), website analytics (Umami), website hosting, downloads and updates, analytics of server operations, or support. Payment information is shared with Stripe, which is not a service provider acting only for us but the merchant of record and seller for your purchase, as described above.

We may also disclose information if required by law, to protect rights and safety, to investigate abuse or security incidents, or as part of a merger, acquisition, financing, or sale of assets, subject to appropriate protections where required.

Retention

Local Hindsight timeline data is retained according to your app settings and remains on your Mac unless you delete it, reduce the retention period, uninstall the app in a way that removes app data, or otherwise remove the files from your device.

We retain information we collect from your account, purchases, subscriptions, payments, support, diagnostics, logs, and legal requests only as long as reasonably necessary for the purposes described in this policy, unless a longer period is required or permitted by law. You can delete your account at any time from within Hindsight, including from the screen shown when a free trial ends. Deleting your account immediately cancels any subscription, deletes any lifetime entitlement, your account, the device tokens we hold, and our record of which account emails we sent you, and asks Stripe to delete your customer record. It does not delete the Hindsight timeline data stored locally on your Mac, which you can clear separately in the app. We delete or anonymize associated personal data except records we or our payment providers must keep for legal, tax, accounting, fraud-prevention, refund, or dispute purposes.

To prevent repeated use of the free trial, we retain the one-way hash of your device identifier after account deletion. This hash cannot be used to recover your identity, email, or any timeline data, and exists solely to enforce one free trial per Mac.

Your Choices and Rights

You can control many privacy choices directly on your Mac, including:

  • Granting or revoking macOS Screen Recording, Accessibility, Microphone, Calendar, and notification permissions.
  • Turning screen or audio capture on or off in Hindsight.
  • Turning meeting record prompts on or off, and deleting individual meeting recordings.
  • Turning Calendar Sync on or off in Hindsight.
  • Adding app exclusions and private browser exclusions.
  • Changing local retention settings, deleting all local data (including meeting recordings), or deleting downloaded transcription and summary models.
  • Deleting your account from Hindsight’s settings, which cancels any subscription, removes lifetime access, and removes your server-side data (local timeline data is cleared separately).
  • Removing Hindsight from your Mac and deleting local app data.

Depending on where you live, you may also have legal rights to access, correct, delete, export, restrict, or object to certain personal information we hold about you. We may need to verify your request before acting on it.

Children

The Services are not directed to children, and we do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact us so we can take appropriate action.

International Transfers

We and our providers may process information in countries other than the country where you live. Where required, we use appropriate safeguards for international transfers.

Changes

We may update this Privacy Policy from time to time. The updated date will show when the policy last changed. If a change materially affects how we handle personal information, we may provide additional notice where practical.

Contact

Questions or privacy requests should be sent to Consalik AB using the support contact listed in the app, on the website, or on your purchase receipt.