Privacy policy.
Last updated: 15 September 2026
Sesh builds prompts on your Mac. We do not automatically receive your sessions, screenshots, copied text or recordings. This policy explains the local app, optional connections to other services, visits to sesh.be and information you choose to send us.
1. Who is responsible?
Sesh is operated by Bram Nouwen, sole proprietor trading as Sesh, Hassaluthdreef 12A/1, 3500 Hasselt, Belgium, enterprise number 1017.615.815 (VAT BE 1017.615.815). Bram Nouwen is the controller of personal information received in operating the website and support service. In this policy, “Sesh”, “we” and “us” refer to this operator.
For privacy questions or requests, email bram@sesh.be. “Personal information” means information relating to an identified or identifiable person. This policy covers the current Sesh Mac app and sesh.be under the EU General Data Protection Regulation (GDPR).
2. What happens in the Mac app?
Your sessions stay local. Commentary, screenshots, copied text and captured source details are saved on your Mac in ~/.sesh/sessions. Source details can include app names and window titles. Collecting page URLs from browsers is a separate option, off by default; enabling it may require macOS Automation permission. Clipboard capture operates during an active session, according to your settings. The app does not upload this history to a Sesh server or synchronize it to an account.
Dictation is local. The microphone starts when you request speech input. Recognition runs on your Mac after downloading the speech models. Keeping audio recordings for playback is optional and off by default. macOS permissions let you control microphone, screen, keyboard and folder access.
Model downloads contact external servers. Parakeet and Silero files are downloaded from Fluid Inference’s repositories on Hugging Face and its delivery infrastructure. Those services receive ordinary connection information, such as your IP address and the requested file. Your recording is not sent with the model download. Cached models are stored under your user Library’s Application Support/FluidAudio/Models folder.
Update checks contact sesh.be. Public builds may check for newer versions through Sparkle. The check retrieves the update feed and, if you choose to install, downloads the signed archive. System profiling is off. Development builds do not use the production feed. Your sessions and speech models stay on your Mac across updates.
Cloud text cleanup is optional and off by default. If you enable it with your own OpenRouter key, dictated text is sent through OpenRouter to Google’s Gemini model. Audio, screenshots, copied quotes, source metadata and ordinary typed session text are excluded from that request. An explicit cleanup preview sends the sample you enter. Your API key is stored in macOS Keychain. Checking that key contacts OpenRouter to validate it. The providers’ terms, retention settings and privacy policies apply to the text they receive.
You choose the destination. Copying or pasting sends your assembled content to the clipboard and the destination you select. That destination handles the content under its own rules. Sesh does not press Send. Local files and clipboard content remain subject to your Mac’s security and any backup or clipboard-sync tools you use.
The current app contains no automatic usage analytics or remote crash-reporting service. Diagnostic logs remain local unless you choose to share them. We cannot inspect or delete files that remain solely on your Mac.
3. Website visits and support
Website delivery and security. Cloudflare hosts and delivers sesh.be. It processes technical request information such as IP addresses, requested URLs, timestamps and browser information to serve and secure the site. We do not add advertising trackers, cross-site profiling or Google Analytics.
Your display preference. The site saves your chosen light or dark appearance in browser local storage under sesh-site-theme-v3. It stays until you change it or clear site data and is not used to identify you. Cloudflare may use security cookies where required by its protective features; see its cookie information.
Contact and voluntary reports. If you email us, we receive your address, message and any information or attachments you choose to include. Google Workspace handles our email. In-app feedback creates a report for you to review, copy or save; it is not sent automatically. Avoid including private session content or other people’s information unless needed and appropriate.
The current beta does not require a Sesh account, process payments, operate a newsletter signup or make automated decisions with legal or similarly significant effects about you. Providing a support message is voluntary, although we may need enough information to answer it.
4. Why we process information
- Provide requested services and answer service questions: performance of a contract or steps you request before a contract, under Article 6(1)(b) GDPR, where applicable.
- Operate and secure the website, diagnose reported problems and respond to other enquiries: our legitimate interests in a functioning, secure service and useful support, under Article 6(1)(f).
- Comply with applicable legal obligations: Article 6(1)(c), where an obligation requires processing or retention.
Access permissions and optional features remain under your control. They do not give us general permission to collect your session history. We do not sell personal information or use session content for advertising.
5. How long information is kept
- Support correspondence and voluntary reports: up to two years after the relevant communication, as in our business support-retention policy, unless an applicable legal obligation or the establishment, exercise or defence of a legal claim requires longer retention.
- Website technical information: hosting-provider logs follow the applicable service retention settings. Any website security records we retain separately are kept only as needed to investigate or prevent incidents, for no longer than one year after the relevant interaction, subject to the same legal exceptions.
- Local sessions and recordings: controlled through Settings → Library and individual deletion. Deleting a session also removes its stored screenshots and recordings. This can break image paths in previously pasted prompts. Removing the app alone does not erase saved history or model caches.
- External services you use: OpenRouter, the selected model provider, model-download services and your paste destination apply their own retention rules. Deleting a local session does not recall content already shared.
6. Service providers and international transfers
We use Cloudflare for website delivery and security and Google Workspace for email. Access is limited to what is needed to provide these services and handle support. We may also disclose information when required by law or necessary to establish, exercise or defend legal claims.
These providers may process information outside the European Economic Area, including in the United States. Their data-processing terms provide transfer safeguards, including the European Commission’s Standard Contractual Clauses and applicable adequacy arrangements. See the Cloudflare data-processing terms and Google Cloud data-processing terms. Contact us to request information about the safeguards relevant to your data.
Services contacted directly by optional app features or links have their own policies: Hugging Face, OpenRouter and Google. Your AI or other paste destination is a separate service.
7. Your rights
Where the GDPR applies, you can request access to and a copy of your information, correction, erasure, restriction of processing and data portability where the legal conditions apply. You may object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing.
Email bram@sesh.be. We normally respond within one month. If the GDPR permits an extension because of the complexity or number of requests, we will tell you within that first month. Where we have reasonable doubts about identity, we may request only the additional information needed to verify the request.
You may complain to the Belgian Data Protection Authority, Drukpersstraat 35, 1000 Brussels, Belgium, or another competent supervisory authority. This does not affect your right to a judicial remedy.
8. Security and policy changes
We use HTTPS for the website and restrict access to support information. API keys are kept in macOS Keychain. Local history files are protected by your Mac’s access controls; Sesh does not add a separate encryption layer to those files. No system can guarantee absolute security.
We will update this page when the service or its data handling changes and show the revision date above. Material changes will be communicated appropriately. Questions can be sent to bram@sesh.be or to the operator’s postal address above.