Privacy
The Mac app and this website handle different data in different places. They are described separately below.
Effective date: 23 September 2026. Controller: Owen Cope. Contact for privacy requests: owen.o.cope@gmail.com.
Part 1: the Mac app, on your computer
Everything in this part stays on the Mac where you installed Gaze. The app has no account system for recognition, and recognition works without one.
- Face measurements
- Enrollment captures your face from several angles and stores the resulting measurements encrypted, with the key held in this Mac's Secure Enclave. Only encrypted data is stored. Camera frames are processed locally: no image is kept and nothing is uploaded.
- Saved password
- Automatic unlocking stays off unless you turn it on. If you enable it, Gaze keeps an encrypted copy of your account password on this Mac, never synced and never sent anywhere, in recoverable form so it can type it. After the configured recognition and movement checks pass, it decrypts and submits that password to macOS. You can use recognition-only mode with automatic unlocking off. Your normal password login always remains available.
- Portraits
- Optional profile pictures you choose stay on disk as separate image files, outside the encrypted vault. They are not uploaded and are not used to recognize you.
- Camera use
- Setup, recognition tests, and automatic unlocking can use the camera. Optional walk-away locking checks for your presence while the Mac is idle. You control these features in Settings. Gaze uses the Mac's ordinary camera, not Face ID, and a photograph may fool it.
- Removing your data
- In Settings, remove an enrolled face from the Enrolled faces list, where each face has a Remove control. Remove the stored account password with the Revoke button next to the account password in the Unlocking section; turning automatic unlocking off does not delete it. Face measurements, portraits, and the stored password never leave your Mac.
Part 2: this website
This site keeps its own records about signed-in testers, separate from anything the Mac app stores. Nothing on this site can see your face data.
- Sign-in methods
- Sign-in offers Google and GitHub, each shown only when that provider is configured, plus an email option that sends a six-digit code. The code expires after ten minutes, is single-use, and locks after five wrong guesses. Sending is limited to five codes per address per hour and twenty per network address per hour. Codes are delivered through the Resend email service.
- Account records
- A tester record holds your email address in lowercase, your roles, the date you were added, and, only if provided, a GitHub handle and a note. Site administrators are identified by email address. A tester record is kept only while the person is a tester: removing them from the tester list deletes the entry.
- Cookies
- While an email code is pending, the site sets an httpOnly cookie holding the signed sign-in challenge; it lasts at most ten minutes. Signing in sets a session cookie so the site remembers you. Signing out ends the session.
- Analytics
- The site runs Vercel Web Analytics on its hosted deployment. An admin dashboard reads aggregate traffic (pageviews and visitors by page, referrer, and country) for the last 30 days from the same analytics store. The site keeps no visitor counter of its own.
- Storage
- Tester lists, releases, roles, and settings are kept in a private object store in production, and in local files when the site runs in development. The credits page fetches public GitHub contribution graphs on the server, so browsers never contact GitHub for them.
- Deletion requests
- A tester asks to be removed by writing to the privacy contact above from the address on the tester list, or by asking an administrator in the Discord, and the record is then deleted. The app's face data stays only on the user's own Mac, so there is nothing site-side to delete for it. Requests under Taiwan's Personal Data Protection Act, or the law where the person lives, are handled the same way.