Legal
Privacy Policy
Last updated: 22 July 2026
Nextline is a side project, not a company. There's no funding, no team, and no support desk behind it — just one person (Alex Zhezherau, San Diego, CA, USA) building something worth using and sharing it for free. That matters here because it sets what you should expect: care, but not guarantees. This policy explains what Nextline — the Mac app and the website at thenextline.app — can see about you and where it goes.
The short version
- Your writing never leaves your Mac. Suggestions come from a language model running on your machine. There is no server-side text processing and no copy of your text anywhere but your Mac.
- We never receive your text — so we can't store it, train on it, sell it, or leak it.
- No account, no sign-up. We don't know who our users are.
- The app touches the network only to check for updates, to fetch the language model, and to deliver product analytics if you leave that on. None of these requests include anything you've typed.
- The app shares pseudonymous product analytics — feature use, performance, settings, and hardware basics, never your text. It's on by default (off by default in the EEA and UK) and one switch in Settings changes it. The website uses Google Analytics.
- If any of this ever changes, we'll update this policy and announce the change in the app before it takes effect.
What Nextline can see on your Mac
To finish your sentence, Nextline has to read it. When a text field has focus, Nextline reads the text around your cursor through the macOS accessibility APIs — the same system that powers VoiceOver — and watches your keystrokes so it knows what you've typed and when you accept a suggestion.
Here is what happens to that text:
- It's processed on your Mac, full stop. The model that produces suggestions runs on your machine. Nothing you type is transmitted to us or to any third party, and suggestions keep working with no internet connection at all.
- It stays in memory. Nextline holds the text it reads only as long as it needs to produce the suggestion in front of you, and does not write your typing to disk.
- Password fields are off limits. macOS marks password and other secure fields as protected and does not expose their contents to accessibility apps, so Nextline cannot read them or suggest into them.
- You hold the switch. Nextline only works with the Accessibility permission you grant, and you can revoke it any time in System Settings › Privacy & Security › Accessibility. Quitting the app stops all reading instantly.
When the app uses the network
The Nextline app makes exactly three kinds of network request:
- Update checks. The app periodically fetches its release feed (using the open-source Sparkle framework) to see whether a newer version exists, and downloads updates you approve. These requests carry the app's name and version and — like any web request — your IP address. They contain nothing you've typed and no identifier tied to you. Release files are served from GitHub Pages, so GitHub receives these requests the way any web host receives traffic.
- Model download. On first launch, the app downloads the language model it runs from Hugging Face. This is a plain file download; it includes nothing about you beyond the request itself.
- Product analytics. Unless you turn analytics off, the app sends the pseudonymous usage events described in the next section. These requests never contain your text.
That's the whole list. The app sends no crash reports, and it has no license server to call home to.
Product analytics in the app
To understand which features work and where the app fails, Nextline shares pseudonymous, installation-scoped product analytics. On Macs set to an EEA or UK region it stays off until you turn it on; everywhere else it is on by default. Either way, the first-run welcome screen links to this policy and a single switch in Settings changes it at any time. Here is the entire surface:
- What is shared: feature use, performance timings, selected settings, your Mac's hardware and macOS version, and which apps Nextline is used in (by app identifier — for example, that a suggestion was accepted in your browser).
- What is never shared: what you type or generate, clipboard or screen contents, URLs or domains, document names, or file paths — and no account identity, because none exists. Analytics events cannot carry your text by construction: the app's event schema has no field for it.
- Identity. Events carry a random installation identifier generated on your Mac. It is not derived from your hardware, contains nothing about you, and is not connected to a name, email, or account. Pseudonymous is not anonymous — the identifier persists across sessions so we can count installations rather than events — but we have no way to tie it to you.
- Processor. Events go to PostHog (US-hosted), which receives your IP address as part of transport, like any web request, and may derive a coarse location from it. We do not send IP or location data ourselves.
- Retention. Analytics events are retained for up to one year, then deleted.
- Turning it off stops future collection immediately and deletes any unsent events on your Mac. Events already delivered remain subject to the retention period above; write to us if you want your installation's events deleted sooner.
Data we hold about app users
The pseudonymous analytics events described above — if you leave analytics on — and nothing else. There is no Nextline account system and no database of users; everything else the app knows lives on your Mac, and deleting the app removes it. If you email us for support, we'll have whatever your email contains — that's covered below.
The website
- Hosting. thenextline.app runs on Vercel. Like every host, Vercel keeps short-lived server logs (IP address, requested page, browser user agent, timestamps) used to operate and secure the service.
- Analytics. We use Google Analytics to understand which pages people visit and which lead to downloads. It sets cookies and collects device and usage data — approximate location derived from IP, pages viewed, and the site that referred you. Google processes this on our behalf; see Google's privacy policy. You can block it with a content blocker or Google's own opt-out add-on.
- Downloads. The download button redirects you to the release file hosted on GitHub Pages, so GitHub sees the download request (IP address and user agent), as described in GitHub's privacy statement.
- Embedded posts. Some comparison pages quote a post from X (Twitter). The embed loads from X's servers only if you scroll it into view; when it loads, X receives standard request data and may set its own cookies under X's privacy policy. Until then it's plain text on our page.
- Theme choice. Picking light or dark stores a single value in your browser's localStorage. It never leaves your browser and identifies nothing.
Legal bases (EEA & UK)
Where EU or UK data-protection law applies, we rely on legitimate interests (Art. 6(1)(f) GDPR) to operate and secure the website, serve downloads, and answer messages you send us, and on consent where the law requires it for analytics cookies. For the app's product analytics in those regions we rely on your consent (Art. 6(1)(a) GDPR): when your Mac's region is set to a country in the EEA or the UK, Nextline defaults product analytics to off and sends nothing until you turn them on in Settings, and you can withdraw consent at any time with the same switch. We don't make automated decisions about anyone and we don't use the data for anything beyond the purposes named here.
How long data is kept
- Your writing: never held — it never reaches us.
- App analytics: up to one year with PostHog, as described above.
- Server logs: kept briefly by Vercel per its standard schedule.
- Analytics: Google Analytics retains event data for 14 months, after which only aggregate numbers remain.
- Support email: kept while the conversation is useful, deleted on request.
Your rights
If you're in the EEA or UK, you have the rights to access, correct, delete, restrict, and port personal data we hold about you, to object to processing based on legitimate interests, and to complain to your supervisory authority. For the app, the only data we hold is the pseudonymous analytics described above — turning analytics off in Settings stops collection, and writing to us gets your installation's events deleted. For website or email data, write to us and we'll sort it out.
If you're a California resident: we do not sell personal information and we do not share it for cross-context behavioral advertising. You have the rights to know, correct, and delete; contact us to exercise them. We will never treat you differently for doing so.
Children
Nextline and this website aren't directed at children under 13, and we don't knowingly collect personal information from them. If you believe a child has sent us personal information, contact us and we'll delete it.
Changes to this policy
When this policy changes, we'll post the new version here and update the date at the top. If a change is material — above all, anything that would touch the "your writing stays on your Mac" guarantee — we'll announce it in the app and on this site before it takes effect, not after.
Contact
Privacy questions and requests: privacy@thenextline.app.