Back to Support | All Apps | 中文 | Contact Support

RepoPress Studio Privacy Policy

Effective and last updated: July 29, 2026

This policy covers the RepoPress Studio App Store edition and its embedded Safari Web Extension. It explains how local drafts, research, repository files, browser captures, credentials, publishing records, diagnostics, and purchase status are handled.

1. Core Principles

RepoPress Studio is local-first. It has no advertising, behavioral tracking, or third-party analytics SDK, requires no RepoPress Studio account, and does not automatically send drafts, repository files, browser captures, or usage analytics to the developer's servers.

Every user can configure a local model or an OpenAI-compatible HTTPS API. AI does not require RepoPress Pro. The app does not meter AI requests, sell AI credits or provider access, or link to provider purchases.

2. Data Stored on the Device

  • Drafts, Markdown content, front matter, tags, categories, authors, summaries, private flags, and publishing status.
  • EPUB, PDF, Markdown, TXT, HTML, or web content selected by the user, plus locally generated full-text and semantic indexes, annotations, citations, and revisions.
  • Site profiles, repository configuration, sync settings, publishing strategies, publishing and maintenance records, deployment status, and limited history.
  • AI provider configuration, endpoint-consent state, model preferences, and limited conversation state. API keys are stored in macOS Keychain.
  • Browser-extension preferences, limited receipts, the pairing token, and a bounded offline queue.
  • Quick Hide, private-content masking, language preferences, backups, and StoreKit entitlement state.

App workspace data is primarily stored in local Application Support data. Extension data is stored in the corresponding browser's local extension storage. Ordinary app and extension data is not equivalent to end-to-end encrypted storage.

3. Files, Repositories, and Browser Capture

The App Store edition uses App Sandbox. It accesses only repositories, research sources, images, and output locations selected through system panels and restores previously granted access with security-scoped bookmarks.

The embedded Safari Web Extension processes a selected page only after the user clicks the extension, a menu item, a shortcut, or confirms a batch task. Captures enter the app on the same device through the authenticated 127.0.0.1:17843 loopback connection. The connection does not listen on LAN or Internet addresses and does not use a developer server to transport page content.

The app does not install a Native Messaging host or write manifests into browser directories. A complete archive can contain private content visible on a signed-in page at capture time and should be protected like any other local file.

4. Network Access

Local writing, research indexing, content checks, image processing, and most Git inspection happen on the device. The following user-configured or initiated features contact their corresponding services:

  • GitHub, GitLab, or repository remotes for access checks, sync, commits, pull or merge requests, status reads, and user-confirmed rollback.
  • Deployment providers or custom status endpoints for deployment checks and polling enabled by the user.
  • Apple StoreKit for product lookup, purchase, restore, and entitlement verification.
  • User-configured AI services only after the user initiates an AI action and has consented to that remote endpoint. The transfer can include prompts, current article or site context, selected research excerpts, conversation context, and images added by the user.
  • Support, privacy, repository, or deployment pages opened by the user.

AI requests travel directly from the device to the provider selected by the user and do not pass through the developer's servers. Those services process data under their own terms and privacy policies. The developer does not operate a proxy that receives AI content, repository content, or browser captures.

5. Credentials and Payments

GitHub or GitLab tokens, deployment credentials, and user-configured AI API keys are stored in macOS Keychain and separated by site and purpose. The app developer does not receive these credentials.

Apple StoreKit handles purchases and restore. The app receives product information and verified entitlement status; it does not receive or process payment-card details. RepoPress Pro unlocks online publishing and batch publishing only.

6. Data Received by the Developer

The app does not automatically send diagnostics. The developer receives an email address, message, and attachments only when the user sends a support request or shares reviewed diagnostics. This information is used for support, security, and necessary legal obligations, not advertising or sale.

Do not send a complete repository, full token, authorization header, account password, local absolute path, or private article body.

7. User Controls and Deletion

Users can delete local drafts, research, records, site profiles, backups, and credentials; clear the extension queue and disconnect pairing; or uninstall the extension. Deleting the app itself may not remove Application Support data, Keychain items, browser-extension data, backups, or files in selected repositories.

Data committed to a repository or retained by an external service must be managed in the corresponding folder or service. The developer does not operate an account server that stores this content and cannot delete it from a device, repository, or third-party service on the user's behalf.

8. Quick Hide and Private-Content Masking

Quick Hide and private-content masking reduce on-screen exposure. They are not password or Touch ID authentication, disk encryption, or end-to-end encryption, and they do not automatically delete files or remote content.

9. Contact and Changes

If the app, extension, data handling, or App Store privacy disclosures change materially, this page will be updated. Privacy and support contact: support@chengjinfang.com.