IN DEVELOPMENT · PREPARING A FREE BETA
Handrail data & privacy
What the development build handles, where model requests go, and what you control.
Handrail is not available to download yet. This information describes development work; complete workflow, safety, and release checks remain in progress. Use disposable test content.
Know where your requests go.
Handrail supports local model connections. If you choose a remote text model, messages and relevant Handrail context go to that endpoint, and the provider’s policies apply. Optional external services may charge fees.
A local server may retain or forward requests. The built-in image route is restricted to an explicit local Ollama connection and refuses redirects; the built-in OpenAI-compatible connection rejects images. Custom providers are outside those built-in restrictions.
Data in the development build
- Saved skills
- Skills are readable signed files. They contain steps, labels, values, and expected outcomes, which can reveal content. Owner-only file permissions and macOS file protection are used; Handrail does not add application encryption. Review before saving and remove or archive skills you no longer need.
- Recording and screenshots
- Input events, accessibility information, and frame metadata stay in app memory for review. Retained frame records describe the image without storing its pixels. Full screenshot bytes pass through the helper during capture. The helper is designed to limit capture to the chosen window and suppress sensitive content, but content may change or escape detection. Use disposable content while testing continues.
- Voice
- Optional voice uses temporary audio in an app-owned area for on-device transcription. Handrail attempts to delete its recording after completion, cancellation, or a failed start. Interruption or a deletion failure can leave a file; later voice-recording starts attempt to clean up older app-owned recordings. This is best-effort cleanup, not a guaranteed expiry. Review the transcript before sending it to a model. Exceptional cleanup should identify Handrail-owned audio with the app closed; do not clear the entire system temporary folder.
- Support exports
- Exports are created locally on request. They contain app and macOS information, helper and permission states, the configured server’s connection origin, local paths, and a testing summary. Paths may include your account name. They are designed to omit screenshots, traces, prompts, responses, saved skills, keys, credentials, model identifiers, and detailed provider errors. Inspect before sharing and delete exports when finished. Exporting does not upload them.
- Staged apps and settings
- Staged copies, model settings, and app preferences are separate local data. Reset Staged Apps removes staged copies, not saved skills or every setting. Original applications remain separate. Preserve custom provider settings before resetting them.
- Skill signing identity
- A separate local key is kept in macOS Keychain. Removing it can make existing signed skills untrusted. Deleting app data does not remove this identity, and removing it is not a routine recovery step.
Keeping or removing local data
Quit Handrail before moving its files. Keep private backups only of what you need. Saved skills, support exports, and staged apps live in Handrail’s application-support folder; settings, permissions, and the Keychain signing identity are separate.
Removing the app does not automatically erase those files, preferences, permission grants, or signing identity. Decide what to keep before uninstalling. See Help with Handrail for recovery guidance.
What remains under review
The reviewed source does not implement analytics or automatic diagnostic uploads. That is not an independent network audit of a final distributed app. Optional providers have their own data handling, and local does not guarantee that no data leaves your computer.
Capture isolation, sensitive-input handling, cleanup, accessibility, and the final release are still being validated. These development disclosures do not certify every secret, changing screen, or third-party provider as safe.