01Scope and contact
This policy applies to the Shelf macOS app and shelf-finder.site. Shelf is provided by its developer. For privacy questions or requests under applicable law, contact support@shelf-finder.site. This policy describes current data handling; available features depend on your installed version.
02Information stored on your Mac
Shelf stores a local index containing authorized sources and access bookmarks, filenames and paths, file types and modification times, extracted text, full-text search data, embeddings, categories and project relationships, settings, and model-call audit records. Search history is also local and can be cleared or disabled in settings.
Your API key is stored in macOS Keychain, not on this website, in the index database, or in UserDefaults. The app displays its last few characters for identification. Shelf does not create a developer-hosted file-sync account or upload your index to a Shelf server.
03File access and Finder output
Shelf obtains access to selected source folders through the system file picker and reads supported files to build and update an index. It does not move, rename, or delete source originals. The optional Shelf folder requires separate write authorization and contains category folders and Finder aliases. Changes within that output folder can update categories in the index.
Authorized folders may contain your own or other people’s personal information. Only authorize content you are entitled to process, and consider whether its text includes sensitive information.
04Information sent by AI features
With your own OpenRouter API key and the relevant feature enabled, requests travel directly from your Mac to OpenRouter over HTTPS and are processed by the relevant model or service provider. They do not pass through a Shelf server.
| Feature | Main information sent |
|---|---|
| Semantic indexing | Filenames and chunks of extracted file text to generate embeddings. |
| Semantic search | Your search description to generate a query embedding. |
| Online organization | Filenames, file types, text excerpts, category or project names and descriptions; naming and project discovery may also send parts of folder names and child folder names. |
| Key checks and usage information | Your API key for authentication, fixed connection-test text or fictional file examples, and usage or credit information returned by your account. |
The current app does not upload original files as attachments or send full filesystem paths as dedicated model-request fields. Names and file contents may themselves contain personal information or paths, and text chunks can cover much of a document. Providers also receive the IP address, authentication information, and request metadata required to process network requests.
05Third-party processing, retention, and location
Embedding and some generative naming requests set OpenRouter’s zero data retention (ZDR) routing parameter. This constrains routing to the relevant inference providers; it does not mean all third-party data or account metadata is never retained, or that processing is offline. The Jev decision API is subject to its service policies and your account settings. We do not make an absolute zero-retention promise for every AI endpoint.
OpenRouter and model providers may process data outside your country or region. Their retention and data protection practices are governed by their policies and your settings. Review the OpenRouter privacy policy, ZDR documentation, and relevant provider policies. Shelf does not sell your file contents or use them for advertising.
06Your controls and deletion
- Disable semantic search and online organization separately in model settings to stop new requests for those features. In-flight data may already have been sent and cannot be recalled by disabling a feature.
- Removing a saved API key stops new requests that depend on it. It does not revoke the key at OpenRouter or automatically delete your existing local index.
- Revoking a source folder stops its monitoring and removes its associated index without deleting originals. Files also covered by another authorized source may remain indexed.
- Clear search history in settings. Turning off Finder output leaves existing folders and aliases for you to remove manually.
Local index data generally remains until you revoke the relevant sources or remove app data. Diagnostic files rotate by size; macOS controls system-log retention. Uninstalling does not necessarily remove Keychain entries, App Group data, or Finder output. For full cleanup, revoke sources and remove your key first, and contact support for instructions for your version. Use a third party’s own account controls or privacy channels for data it holds.
07Diagnostics and support email
The app records local operational status, counts, timings, resource samples, and error information for troubleshooting. It currently has no developer service for automatic diagnostic or crash-report uploads. Local model-call audits record endpoint, model, types of fields sent, excerpt lengths, timestamps, and related metadata. Review and redact logs or screenshots before sharing them.
When you email support, we process the address, message, and attachments you provide to respond, investigate, or handle a privacy request. We retain them for as long as needed to handle the request and necessary obligations. Messages are forwarded through Cloudflare Email Routing to our email provider, Microsoft Outlook. Do not send API keys, passwords, or unnecessary sensitive files.
08Website access and cookies
Cloudflare hosts this website. To serve pages, cache content, secure the network, and prevent abuse, Cloudflare may process IP addresses, browser information, requested URLs, timestamps, necessary network logs, or security cookies under its privacy policy and applicable service configuration.
This website has no ads, third-party behavioral tracking scripts, login system, or visitor file uploads. The interactive demo uses fictional files; input is processed only within the current browser page, is not sent to an AI endpoint or our backend, and is not saved in local storage. The website does not set analytics or marketing cookies.
09Security, children, and updates
We use safeguards including HTTPS, macOS sandboxing, and Keychain to limit access and protect transfers, but no system can guarantee absolute security. Protect your device and third-party accounts. Shelf is intended for general macOS users and is not directed at children. Contact us about any children’s information that should not be processed.
We publish changes here and update the date. Material changes will be communicated through the app or another appropriate channel, and processing requiring additional permission should obtain that permission. This policy does not limit access, correction, deletion, objection, or other rights provided by applicable law.