Privacy

What stays on your Mac

Conversations, session history, workspace registrations, preferences, and every file the agent reads or writes live in application data on your Mac. None of it is uploaded to Submergent.

Your Submergent account

Submergent is a paid application and requires an Submergent account. That account exists to license the app and handle billing; it is separate from the provider accounts you connect, and it is not where your sessions or files live.

The account holds only what licensing and billing need:

It does not hold your sessions, prompts, transcripts, file contents, workspace names or paths, or the credentials for any provider you connect. Signing in does not upload anything from your Mac.

Application data is not encrypted at rest by Submergent. It is protected by macOS file permissions. Turning on FileVault is the recommended way to encrypt it. Credentials are the exception: provider API keys are stored in the macOS Keychain.

What goes to your provider

When you send a message, its content — your text, the files the agent reads, and command output it needs — goes from your Mac directly to the provider you selected for that session, under that provider's terms and privacy policy. Submergent does not proxy these requests through a service of ours, and does not keep a copy. Choosing Ollama keeps everything on your Mac, since Ollama runs locally.

Diagnostics

Crash and error reporting is off by default and only turns on if you enable it in Settings. While it is on, reports carry operational fields only: app version, release channel, macOS major and minor version, architecture, provider adapter and version, error class and code, sanitized component and state identifiers, and bounded timing measurements.

Reports never carry:

A report that cannot be shown to be free of these is dropped rather than sent partially.

Email updates

If you enter your address in the “Get notified” form on this site, we store that address, which page you submitted it from, and the time you submitted it, in a hosted Postgres database run by Neon. Nothing else is recorded — not your IP address, not your browser, not where you came from.

That address is used only to tell you about Submergent releases. It is not sold, shared, or used to build a profile, and it has nothing to do with the app on your Mac. Every email includes an unsubscribe link, and you can ask for the address to be deleted at any time at the contact below.

Local logs

Submergent keeps sanitized local logs, bounded in size and count, readable only by your macOS user. You can reveal or delete them from Settings.

Deleting your data

Removing the app and its application data removes everything Submergent stored. Note that deleting a session keeps any git worktree and branch that session created — Submergent discloses the location when you delete it, and removing those is a git operation you perform yourself.

Contact

Privacy questions and deletion requests: to be published before release.