Privacy Policy

This policy explains what Project Browser reads on your Mac, what the optional Team service shares, and which service providers process information.

Effective August 26, 2026

Who we are

Project Browser is provided by Edge Marketing And Design, LLC, 1301 11th Avenue, Suite B, Helena, Montana 59601. Questions and privacy requests may be submitted through the support form.

Local processing

Project Browser reads local Codex task records and user-approved project folders to organize projects, inspect Git repositories, show recent tasks and commits, render Markdown, and calculate personal token analytics. Tags, cached project metadata, Team credentials, and token indexes are stored in the Mac user's Application Support directory.

The free Local features do not require a Project Browser account and do not send this local project index to our Team server.

Optional Team sharing

When Team features are enabled, Project Browser sends only the information needed to match shared repositories and coordinate work. This may include:

  • Team and display names, device identifiers, app version, and membership role.
  • Team-specific repository fingerprints and, for repositories shared by at least two devices, repository name, branch, commit identifier, and activity time.
  • Changed relative file paths, Git change counts, processing state, short work summaries, and recent commit titles.
  • Project-level lifetime and weekly token totals, weekly contribution percentage, and estimated plan value.

Codex conversations, responses, complete task history, thread identifiers, raw source code, and raw Git diffs are not sent to the Project Browser Team server.

Codex-generated summaries

To create a short teammate-safe work summary, the app may run the Codex command included with the Codex or ChatGPT desktop app. It supplies a bounded portion of the latest request, changed-file information, Git diff evidence, and selected untracked text. This processing occurs through the user's existing Codex/OpenAI installation and account. Only the resulting short summary is sent to the Project Browser Team server. OpenAI's handling of that request is governed by the user's agreement and privacy settings with OpenAI.

Billing

Stripe processes Team subscription checkout, payment methods, invoices, and cancellation. We receive Stripe customer and subscription identifiers, plan selection, subscription status, billing interval, and renewal date. Project Browser does not receive or store full payment-card numbers.

Infrastructure and security

Cloudflare hosts the Team API, encrypted Team records, operational logs, and signed application downloads. Connections use HTTPS or secure WebSockets. Team credentials are random, revocable, and stored locally with owner-only file permissions. Cloudflare automatically encrypts Durable Object data at rest and in transit within its network.

No internet service is completely secure. Team members are responsible for protecting Team Keys and securing their Macs.

Retention and deletion

  • Recent Team commit events are retained for approximately 24 hours.
  • Last-reported project activity remains until the device reports a newer state, the installation is removed, or the Team is deleted.
  • Unpaid checkout directories expire automatically, and abandoned unpaid Team-room data is scheduled for deletion after checkout expiration.
  • Billing records are retained by Stripe according to legal, tax, fraud-prevention, and account requirements.
  • A sole Team owner can delete the Team from the app after other members have left or been removed.

Website data

We may enable optional analytics, advertising, remarketing, session-insight, or error-monitoring technologies to understand website use, improve Project Browser, measure campaigns, and reach interested audiences. Depending on the services enabled, providers may include Google Analytics or Google Ads, Meta Pixel, AdRoll, Microsoft Clarity, and Sentry. These providers may process information such as IP address, device and browser details, pages viewed, referring URLs, interactions, campaign information, and provider identifiers according to their own privacy terms.

When optional analytics or marketing tags require a choice, the website displays privacy controls before loading them and lets you accept, decline, or select categories. A first-party consent cookie records those choices for up to six months. You can reset the choice by clearing this website's cookies. Essential hosting and security logs may still process standard request information such as IP address, browser type, requested URL, and timestamps regardless of optional tracking choices.

When you submit the support form, the name, email address, subject, and message you enter are sent to FormFling for delivery to us. We use that information to review and respond to your request and do not ask you to submit Team Keys, credentials, source code, or other secrets.

Your choices

You can use Local features without enabling Team sharing. Team owners and admins can remove installations, and members can leave a Team. You may contact us to request access, correction, or deletion of information associated with the Team service, subject to identity verification and legal retention requirements.

Changes

We may update this policy as Project Browser changes. The effective date above will be revised when material changes are published.