Privacy Policy
Last updated: October 3, 2026
The short version
Kitbar runs on your Mac. It has no account of its own, and no server of ours in the middle. It talks to the services you connect, directly, with the keys you give it, and to a few places of ours listed below. Nothing else.
The tools you connect
Each tool is connected with a key you make in that tool's own dashboard. The key is kept in the macOS keychain, in an item of Kitbar's, and is sent only to the service it belongs to, over HTTPS, as often as you choose in Settings (every 30 seconds by default). Kitbar never sends a key anywhere else, and we never see it.
- Vercel (api.vercel.com): your projects and their deployments; a redeploy when you ask for one.
- Cloudflare (api.cloudflare.com): your Pages projects, Workers and their builds; a retry or a new build when you ask for one.
- GitHub (api.github.com): your repositories, their commits, workflow runs, commit statuses and deployments; a re-run when you ask for one. Your avatar comes from github.com.
- GitLab (gitlab.com): your projects, pipelines and jobs; a retry when you ask for one.
- Stripe (api.stripe.com): your account's name and the latest charges, with the customer's name and email as Stripe holds them. Nothing can be changed from Kitbar.
- Polar (api.polar.sh): your organization and the latest orders, with the customer's name and email as Polar holds them. Nothing can be changed from Kitbar.
- Claude, with an admin key (api.anthropic.com): your organization's cost and usage reports.
- Codex, with an admin key (api.openai.com): your organization's cost and usage reports.
A project's icon is fetched once per launch from the website the project is live on (the page's own icon), without any key. That is a request to your own site.
Claude Code and Codex on your Mac
Claude Code and Codex connect without a key. Kitbar never reads the sign-in either of them keeps. Instead:
- Kitbar sets its own small script as Claude Code's status line (in ~/.claude/settings.json, keeping a copy of the file as it was). The script saves the limits Claude Code reports to a file in ~/Library/Application Support/8tool, and Kitbar reads that file. Disconnecting puts the settings back.
- To keep the numbers fresh while you are not in a terminal, Kitbar has Claude Code answer one very short message, as often as you choose in Settings. That uses a little of your plan, about a thousand tokens of the smallest model, and twice an hour of your own model. It runs in a sandbox that cannot read your Desktop, Documents or Downloads folders, with your hooks, plugins and MCP servers switched off.
- Codex is asked through its own app server, the way its editor extension asks it, for your limits and the account that is signed in.
Requests to us
- License activation and validation. Your license key, the name of your Mac and an anonymous device identifier (a one-way hash of your Mac's hardware ID) are sent to our payment provider, Polar, to activate the license and to check every few days that it is still valid.
- Update checks. The app fetches a small file from voprexlabs.com/8tool to see whether a new version is available, and downloads the update from the same site. The app's What's New window reads its notes from there too.
- Usage statistics. To improve Kitbar, the app sends us which features you use, the app and macOS version, and error codes, through Open Analytics. They are linked to your license and never include your keys or anything from your tools. You can turn this off in Settings.
- Feedback. If you choose to send feedback from the app, your message, the app version, your macOS version and the email address you typed (if any) are sent to us by email. Nothing is sent unless you press Send.
What Kitbar keeps on your Mac
Your keys, in the keychain. Your settings, in the app's preferences. The limits Claude Code reports, in ~/Library/Application Support/8tool. The latest answers of each tool, in memory only, until you quit.
This website
voprexlabs.com uses Open Analytics for aggregate, privacy-friendly visit statistics.
Payments
Purchases are processed by Polar as merchant of record. Your payment details go to Polar, not to us. Their privacy policy is at polar.sh/legal/privacy.
Changes
If this policy changes, the new version is published on this page with a new date.
Contact
Questions? Write to [email protected].