Sorty never sends us your files, folder names, paths, prompts, AI responses, or API keys. The Mac app only sends anonymous product analytics and crash reports after you explicitly opt in. This website uses cookieless aggregate analytics with a persistent opt-out.
1. Overview
Sorty ("the App") is a native macOS application published by the Sorty open-source project and licensed under the GNU General Public License v3.0. This Privacy Policy explains how the App handles information when you use it.
Sorty is built privacy-first. File scanning and organization run on your device, and the App is designed so that the smallest amount of information necessary leaves your computer. We do not operate servers that process your files. Cloud AI requests go directly to the provider you choose, and anonymous app analytics only starts after an explicit opt-in.
2. Data We Collect
There is no Sorty account and we do not collect names, email addresses, advertising identifiers, file names, folder names, file paths, file contents, prompts, custom instructions, AI responses, API keys, or the names of files involved in an error.
Optional Mac app analytics
After onboarding, the Mac app asks once and does not initialize its analytics SDK until you choose "Share Anonymous Analytics." If you decline, no analytics or crash report is sent and the denial itself is not reported. You can change this choice later in Settings → Advanced → Privacy.
When enabled, the App sends a random anonymous installation identifier, app and macOS versions, named screen visits, feature and sub-feature actions, a small allowlist of important button actions, coarse count and duration buckets, workflow outcomes, and sanitized errors. Crash reports may include exception types, signal names, function names, and stack frames needed to diagnose the crash. Sorty does not create a PostHog person profile, identify you, or send a name, email address, account identifier, advertising identifier, or other information linked to you. This is the lightweight product and reliability telemetry commonly used by apps, limited here to the documented anonymous events.
Cookieless website analytics
This website measures page visits within an anonymous browser-tab visit, named page and section visibility, coarse scroll-depth milestones, meaningful links, buttons, and FAQ opens, coarse traffic-source categories, and sanitized technical errors through PostHog. It uses cookieless mode, does not create a person profile or record session replays or page contents, strips query strings and full referrer URLs, and instructs PostHog to discard IP addresses. You can disable it at any time through "Analytics preferences" in the footer. Global Privacy Control and Do Not Track are honored automatically.
PostHog never receives file or folder names, paths, file contents, prompts, custom instructions, AI responses, API keys, or other user-entered content. If you explicitly enable Deep Scan with a cloud AI provider, any content needed for that request goes directly to the provider you selected, never to Sorty or PostHog.
The following is handled locally on your device only:
- Organization History — records of operations (file paths and metadata), stored locally and not encrypted.
- Settings & preferences — stored in standard macOS UserDefaults, including your app analytics choice. The website stores its analytics preference in local storage and a random anonymous visit identifier in session storage until the browser tab closes.
- Watched Folders — stored as macOS security-scoped bookmarks so access persists across restarts.
- Exclusion rules, personas, and naming presets you create.
3. AI Providers & Your Files
Sorty is provider-agnostic. You choose which AI provider (if any) analyzes your files, and you can switch or disable providers at any time in Settings → AI Provider.
What is sent to cloud providers
When using a cloud-based provider (for example OpenAI, Anthropic, Google Gemini, Groq, OpenRouter, or GitHub Copilot):
- File names and metadata are sent for analysis so the model can suggest a folder structure.
- File contents are NOT uploaded unless you explicitly enable Deep Scan. Deep Scan uploads small content excerpts and should only be enabled for files you are comfortable analyzing remotely.
- All traffic occurs over HTTPS with TLS 1.2+.
- API keys are stored in the macOS Keychain, never logged, and never transmitted outside your chosen provider's endpoints.
For maximum privacy, use a fully on-device provider. Ollama processes everything on your machine, and Apple Foundation Models run on-device via Apple Intelligence (requires macOS 15+). With these options, no file information leaves your Mac.
When you use a third-party AI provider, that provider's own privacy policy and terms apply to the data you send. We encourage you to review the policies of your chosen provider, for example OpenAI and Anthropic.
4. Local Storage & Encryption
- The Learnings Profile — the data Sorty uses to adapt to your style — is stored with AES-256 encryption and protected by Touch ID or Face ID.
- API keys are stored in the macOS Keychain.
- Privacy Mode (enabled by default) blurs sensitive handles until you hover and hides API keys behind a manual reveal toggle — useful for screensharing or streaming.
- Privacy Path Masking redacts usernames from file paths shown in the UI and logs.
5. Network & Update Checks
- The App checks for updates by fetching version data from the GitHub Releases API over HTTPS. Update checks run on app launch (at most once per 24 hours) or manually via the menu.
- Update and AI-provider requests do not include Sorty analytics. When you opt in, anonymous analytics is sent separately to PostHog over HTTPS.
- You can disable automatic update checks in Settings → Updates → Manual only.
6. Sandboxing & Permissions
Sorty runs within the macOS App Sandbox with the following entitlements:
- User-selected file access (read/write) for folders you explicitly grant.
- Network access for AI provider APIs and update checks.
- No system-level access outside the sandbox.
You grant folder access through macOS security-scoped bookmarks. You can revoke access at any time by removing a folder from the Watched list or in macOS System Settings.
7. Third-Party Services
Sorty integrates with the following third-party components and services, each governed by their own policies:
- Sparkle Framework — handles secure in-app updates.
- AI providers — each has its own security and privacy policy (see above).
- PostHog — processes cookieless website events and explicitly opted-in, anonymous Mac app analytics and crash reports in the United States.
- GitHub — hosts releases and the update feed.
Releases are not code-signed with an Apple Developer certificate. You may verify integrity by building from source or checking release notes. See SECURITY.md for full details.
8. Children's Privacy
Sorty is a general-purpose developer and productivity tool and is not directed at children under 16. We do not knowingly collect personal data from children. Sorty analytics is deliberately anonymous and excludes user and file content.
9. Your Rights & Controls
Sorty keeps file-related data local and provides direct controls over the limited anonymous analytics described above:
- Delete your data — use Settings → Troubleshooting → Delete All Data to wipe usage history, watched folders, local caches, and queued analytics data.
- Control app analytics — decline during onboarding or turn off Share Anonymous Analytics in Settings. Turning it off closes the SDK and clears its local queue.
- Control website analytics — use Analytics preferences in the website footer. The site also honors browser privacy signals.
- Reset everything— "Reset All Settings" returns you to the onboarding experience.
- Use on-device AI — choose Ollama or Apple Foundation Models to keep processing on your Mac.
- Disable Deep Scan — keep file contents from ever leaving your device.
- Disable update checks — minimize network exposure.
Because analytics records are anonymous and are not linked to a Sorty account, we cannot reliably locate or delete an individual's previously transmitted records. Turning analytics off prevents future collection from that device.
10. Changes to This Policy
We may update this Privacy Policy as Sorty evolves. Material changes will be reflected in the Changelog and via in-app notifications. The "Last updated" date above indicates when this policy was last revised.
11. Contact
For privacy or security questions, please use GitHub's private vulnerability reporting or open a GitHub Discussion for general questions. For security reports specifically, see SECURITY.md.
© 2026 Sorty. Released under the GPL-3.0 license. Home · Terms · Changelog