PittoPalette
日本語Get it

Privacy Policy

Last updated: 2026-09-01

This Privacy Policy explains how Masashi Tsuru (the “Operator”) handles information in the PittoPalette macOS application (the “App”) and on the official pittopalette.app website (the “Site”). The Operator is the controller of personal information received through the Site or support channels.

The App is local-first. Information saved in it is generally processed on your Mac, and the App does not automatically send personal information or usage data to the Operator. Visiting the Site or voluntarily contacting the Operator involves separate communications outside the App.

1. Data stored on your Mac

The App stores palette items, folders, settings, reusable variables, counters, clipboard history, and related images in its local container. Clipboard history can be disabled and cleared.

The App ignores standard concealed, transient, and auto-generated pasteboard markers before reading clipboard content. You can exclude source applications by selecting an application path or entering a bundle identifier. Source-application detection is best effort, and the App does not try to infer whether text is a password or card number.

2. Commands, permissions, and insertion

Command items contain scripts you create. They run locally through /bin/zsh inside App Sandbox after an execution confirmation. Command source, standard output, and standard error are not sent to the Operator. The App has no network entitlement and does not download code.

A user-authored script can access the App container and resources that macOS explicitly grants, such as a folder you select. The App writes a chosen entry to the clipboard, and you paste it with Command-V. The App posts no synthetic keystrokes and asks for no authorization to do so. It never reads or writes another app’s user interface. Section 3 covers PittoPalette Helper, a separate app, if you install it.

3. PittoPalette Helper (a separate app)

PittoPalette Helper is a separate app the Operator distributes free of charge from the Site. Installing it is optional, and the App never fetches, installs, or updates it. Without it the App still works: a chosen entry goes to the clipboard.

When the App asks it to, the Helper posts a Command-V keystroke. macOS asks for authorization before allowing that, and the authorization is granted to the Helper. The Helper never reads or writes another app’s user interface. It posts a keystroke and nothing else; what gets pasted is whatever is already on the clipboard.

Communication between the App and the Helper stays on the same Mac and never leaves it. Before connecting, each end verifies that the other carries the same developer’s signature.

The Helper makes one kind of outbound request. Only when you open the Helper yourself, it reads one static file at downloads.pittopalette.app, where the Operator serves downloads, containing the number of the latest version. It sends an ordinary HTTP request and nothing else: no identifier, no usage data, no palette or clipboard content. It uses no cookies, no storage, and no cache. The response is a version number, and the Helper says so when a newer one exists. Downloading and replacing it is something you do.

The Helper stores no palette items, clipboard history, commands, or backups.

4. Backups and iCloud

Exported backups are JSON files written to a location you choose. Automatic backup can use the PittoPalette iCloud Documents container in your Apple Account or a folder you select. Apple provides iCloud transfer and storage under your Apple Account; the Operator does not receive those backups. Clipboard history is included only when you enable that option.

5. Local diagnostic logs

Normal error logs record operation names and error types, not clipboard contents, palette values, command source or output, or backup contents.

Optional shortcut diagnostic logging is off by default. When explicitly enabled for troubleshooting, it records local timing and key-event metadata and may include characters reported by a key event. Diagnostic logs remain on your Mac and are never uploaded automatically.

6. Information processed on the Site

With your prior permission, the Site uses Google Analytics 4 to understand visits and improve the Site. The Google tag is not requested and no Analytics information is sent before you allow analytics. If you decline, the Site remains fully available. You can change your choice at any time through “Analytics settings” in the footer.

When enabled, Analytics processes the page URL and title, referrer, access time, browser and device characteristics, language, screen information, approximate location derived from the IP address, a randomly generated client identifier stored in first-party _ga cookies, and interactions such as page views, scrolls, outbound-link clicks, and file downloads. The Operator also records purpose-specific events for App Store and feedback-link clicks. The Site does not send form contents, email addresses, account identifiers, User-ID, or other user-provided information to Analytics. Google states that GA4 discards IP addresses before the data is logged.

Analytics cookies expire no later than 395 days after the first consented visit and are not extended on later page loads. The Site stores your allow-or-decline choice in local browser storage for 180 days so it does not ask on every visit; that preference is not transmitted to the Operator or Google. Google Tag Manager, advertising tags, advertising measurement, Google Signals, advertising personalization, account registration, payment features, and marketing pixels are not enabled on the Site.

Cloudflare provides Site hosting, content delivery, traffic routing, and security. In doing so, Cloudflare may process IP addresses, access date and time, requested URLs, referrers, browser and device information, HTTP request headers, routing information, and security signals. Cloudflare may use cookies that are strictly necessary for secure traffic and abuse prevention. Details of each external transmission are listed in the External Transmission Policy.

7. Feedback and support inquiries

The support page links to an optional Google Form managed in the Operator’s Google Workspace. The App never submits information to the form automatically. If you choose to submit it, the Operator receives the category and message, environment details you enter, and an email address only if you provide one.

If you contact the Operator by email, the Operator receives the sender address, email headers, subject, message, and attachments. Do not send Apple Account details, payment information, clipboard contents, authentication credentials, or other sensitive information. App Store purchases, billing, and refunds are handled by Apple.

The Operator processes information only as necessary to:

Where processing relies on consent, you may withdraw it at any time without affecting earlier processing.

9. Service providers and international processing

The following providers process information only for their respective functions and may do so outside your country of residence under their contractual terms, privacy policies, and applicable transfer safeguards:

The App itself does not automatically transmit information to Cloudflare or Google. Site analytics is separate from the App and occurs only after your consent. Other communications occur when you open the Site, a form, or an email channel. If you install PittoPalette Helper, opening the Helper reads one static file at downloads.pittopalette.app (Section 3); that request passes through Cloudflare.

10. Disclosure to third parties

The Operator does not sell or rent personal information. Information is disclosed only to the service providers described above as needed for their functions; with your consent; when required by law or a lawful public-authority request; to protect life, health, property, or legal rights where permitted; or as part of a business transfer subject to equivalent privacy protections.

11. Retention and deletion

Information is retained only for as long as reasonably necessary for the purposes above. The criteria include the nature and sensitivity of the information, the status of an inquiry or defect, the need for follow-up or dispute resolution, security and abuse-prevention needs, and legal or accounting obligations. Cloudflare and other providers may retain technical records according to their policies and the Operator’s service configuration.

Google Analytics user-level and event-level data is configured for deletion after 14 months. This setting does not govern standard aggregated reports, which may remain available for longer. Withdrawing analytics consent stops future collection; the Site also removes Analytics cookies accessible to it from your browser.

You can clear clipboard history, delete individual palette items and variables, reset App data from Data Tools, and delete backup files from their storage location. Removing the App and its sandbox container removes remaining local App data. iCloud and user-selected backup copies must be removed separately from those locations.

12. Your privacy rights

Depending on applicable law, you may request access, correction, deletion, restriction, objection, or data portability for personal information held by the Operator. You may also withdraw consent and lodge a complaint with your local data-protection supervisory authority. The Operator may verify your identity and may limit a request where law requires retention or protects another person’s rights.

13. Security and changes

The Operator uses reasonable administrative and technical safeguards, including access limitation, appropriate provider configuration, and deletion when information is no longer needed. No internet transmission or electronic storage method is completely secure.

This Policy may be updated when the App, Site, providers, or applicable law changes. The revised Policy applies when posted here. Material changes will be communicated on the Site or by another reasonable method before they take effect when required.

Contact

Operator: Masashi Tsuru

Email: support@pittopalette.app