Privacy
Privacy
There are two separate things here: the Actualis application, and this website. They are covered separately because they behave very differently.
The Actualis application
Actualis collects nothing and transmits nothing. It runs entirely on your machine, reads your existing agent transcripts read-only, and makes no outbound network connection of any kind.
- There is no account, no sign-in and no licence check.
- There is no telemetry, crash reporting or usage analytics — none to disable, because none exists.
- The command-line tool is written against the Python standard library and imports no HTTP client or socket library at all.
- Detected credentials are fingerprinted rather than stored, and are never written out in full.
- Nothing is shared unless you deliberately run the share command, which redacts by default and shows you what it will disclose first.
You do not have to take this on faith. The source is AGPL-3.0 and the entire CLI is one auditable file.
This website
The site runs no advertising and no cross-site tracking. It does measure how it is used, with two analytics tools, and this section says exactly what each one does.
Vercel Web Analytics counts page views. It is cookieless, stores no identifier and reports only aggregates — which pages are read, referrer, country, device class.
PostHog records page views and clicks on a few buttons
(Get Actualis, Read the source, and the sponsorship buttons), so we can see
which pages and links lead people to try or support Actualis. Unlike Vercel
Web Analytics, PostHog stores a random identifier in a
first-party cookie and in your browser’s local storage, so repeat visits
from the same browser are counted as the same visitor. Each event includes
the page, the referring site, any campaign tags in the link (UTM
parameters), browser and device type, and an approximate location derived
from your IP address. It does not record your screen, keystrokes or form
contents, and the identifier is not linked to your name or email. Events
are sent through this site (actualis.app/ingest) to PostHog in
the United States, and are shared with no one else. The same PostHog
project also measures our other websites, so a visit to more than one of
them may be recognised as the same browser.
That is a change from an earlier version of this page, which said the site set no cookies and stored no identifier. If you would rather not be counted, any content blocker stops both tools, and you can clear the cookie and local storage for actualis.app at any time; the site works identically without them.
| What | Why | Who |
|---|---|---|
| Server request logs, including IP address | Serving the site and protecting it from abuse. Retained briefly by the host. | Vercel |
| Page views | Which pages get read, so the documentation can be improved. Cookieless and aggregate; no identifier that follows you. | Vercel Web Analytics |
| Page views and clicks on the Get Actualis, Read the source and sponsorship buttons, with referrer, campaign tags, browser, device and approximate location | Which pages and links lead people to try or support Actualis. Uses a random identifier stored in a first-party cookie and local storage. | PostHog |
| Web fonts | Inter and IBM Plex Mono are loaded from Google Fonts, which sees the request. | Google Fonts |
| Contact form submissions | Only what you type: your name, email, message. Used to reply to you. | CirqleSync |
| Payments | Handled entirely by GitHub or Stripe. This site never sees card details. | GitHub, Stripe |
The contact form includes an invisible bot check and rate limiting.
Your data
To ask what we hold from a contact form submission or from analytics, to correct it, or to have it deleted, use the contact form or the issue tracker. Since the application collects nothing, there is nothing held on that side to request.
Changes
If this policy changes materially, the change will be visible in the website’s public git history rather than announced only here.
Last updated 7 October 2026.