LeMax, LLC

Agent Activity · macOS

Privacy policy

September 24, 2026Effective date
September 29, 2026Last updated
LeMax, LLCPublisher

01 — Summary

Agent Activity has no account. The Mac App Store version has no server of its own; the version downloaded from le-max-app.com also talks to one service of ours, which runs its 14-day trial and its license — see “The license service and updates (Developer ID version)” below. It reads AI-agent transcripts and Xcode build logs on your Mac to show you what your coding agents are doing, and keeps what it reads in its own database on your Mac. No transcript, message or build-log content, no project name and no path from your projects leaves your Mac. There are three exceptions:

  • The only text Agent Activity itself sends from an agent’s files is the name of a record type it doesn’t recognize yet, no more than its first 60 characters. It can be sent in a usage event, and in the recent usage events attached to a crash report.
  • A crash report can include the path where Agent Activity itself is installed. When that is under your home folder, the path includes your macOS account name.
  • A crash report includes the crash’s own error message. Agent Activity’s own code puts no project data into a crash message in the released app, but a message raised by macOS, a system framework or a library the app uses is not written by Agent Activity, and the app cannot control its text.

The first time you open Agent Activity, it asks once — Share or Don’t share — before sending any usage or crash data. If you close that question without answering, the app asks again in its main window until you do; none of it is sent in the meantime. (The Developer ID version’s update checks and license service do not depend on this choice; see their own section.) Your answer sets two switches, independent from then on in Settings → Diagnostics: one sends usage events to Google Analytics, the other sends crash reports and session events to Firebase. Both are keyed to identifiers created for this installation; Agent Activity has no account and never asks for your name or e-mail. (The Developer ID version shows the e-mail of the purchase whose license key you enter; that e-mail comes from the store, not from you, and is never sent to Google.)

From the first launch, whatever you answer, Agent Activity also downloads a public list of AI-model prices — LiteLLM’s, from raw.githubusercontent.com, GitHub’s host for raw files — about once a day, to show what your agent sessions cost at API list prices. That request is described under “What leaves it, and when”.

02 What stays on your Mac

  • Every session, build, test run, screenshot and permission record the app shows you lives in its own database on your Mac. The app never sends that database anywhere.
  • No transcript, message or build-log content, no project name and no path from your projects leaves your Mac. The exceptions are the three in the Summary: the name of a record type Agent Activity doesn’t recognize yet (no more than its first 60 characters, never the record itself), Agent Activity’s own install path in a crash report, and a crash’s error message when macOS, a system framework or a library raised it.
  • A diagnostics bundle is written to a file on your Mac only when you export one yourself (Settings → Diagnostics → Export). The app never transmits it, on any channel, under any setting; what happens to the file after that is up to you.

03 What leaves it, and when

Until you answer the first-launch choice, no usage or crash data is sent and Firebase is not started; if you close that choice unanswered, the app keeps asking in its main window until you do. If you turn both switches off while the app is running, usage events stop at once, but the Firebase components already started stay loaded until you quit, and crash reports and session events stop from the next launch at the latest. A launch that begins with both switches off starts no Firebase service. A crash report or session event already waiting to be sent when crash reports were turned off can still be sent later, though: the Google component that sends them starts with the app, whichever way the switches are set.

With Share usage data on, the app sends these named events. Every parameter is a fixed category, a bucketed count or a short label chosen by the app, except record_type:

  • first_data_found (pillar, minutes_bucket) — once per area (sessions, builds, tests, previews and screenshots, permissions), the first time that area holds data while Share usage data is on, and how long after you first opened the app, in broad bands (under 1, 1–5, 5–30 or over 30 minutes);
  • grant_changed (scope, state) — that a permission grant changed, and to what state;
  • collector_stalled (collector, reason) — that a background task failed, with which one and a fixed reason code;
  • shape_unknown (agent, record_type) — that the app saw a kind of record it doesn’t recognize yet: which agent, and that record’s own type label, no more than its first 60 characters. This is the only value in any event read out of an agent’s file rather than chosen by the app; the rest of the record is never sent;
  • detail_opened (kind) — that you opened a detail pane, and which kind;
  • diagnostics_exported — that you exported a diagnostics bundle;
  • consent_changed (surface, consent, enabled) — which of the two switches changed, and where;
  • retention_changed (retention) — that you changed the storage-retention setting, and to what;
  • offer_shown (surface) — in the Developer ID version, that a price and Buy button were shown, and where (the trial banner, the start window or Settings); once per place per launch;
  • checkout_opened (surface) — that you pressed Buy, and where;
  • notice_shown (code) — that the app showed you a license error, as a fixed code (1–5, could not reach the service, or other); once per code per launch.

Alongside these, the app sets a few properties on your installation: which channel you run (Mac App Store or Developer ID), a bucketed range for how many sessions you have (never the exact count), a short list of which agent kinds you use, and your macOS version.

Google Analytics also collects data by itself, as it does for any app that uses it. Among it:

  • Events: first_open (the first launch after installing), session_start (with a session ID and number), user_engagement (in the foreground), app_exception (a crash Crashlytics reports), all four seen in this app’s data; Google also lists app_update and os_update (app or macOS updates);
  • With every event: the app’s version;
  • Device and system: the device brand and model, the operating system and its version, the screen resolution, and the language setting of your Mac;
  • Coarse location: country, region and city (with the city’s latitude and longitude), continent and subcontinent, derived from the IP address the data arrives from. Google states that for users in the EU, Switzerland and the UK the IP address is used only to derive that location and is then discarded, never logged or stored; for other users Google Analytics also uses it to detect spam, never associates the raw IP address with user identifiers, and discards it after use. Google adds that encrypted IP addresses may flow to a linked Google Ads account; this app’s Google Analytics property is linked to no Google Ads account;
  • Properties: first_open_time and non_personalized_ads, seen in this app’s own data. non_personalized_ads is 1: the app sets ad storage, ad user data and ad personalization to off by default, so Google Analytics marks its data as not for personalized ads.

Google describes these in its help pages (automatically collected events, predefined user dimensions, EU, Switzerland and UK data, IP addresses outside them).

With Send crash reports on, two kinds of data go to Firebase:

  • A session event, whether or not anything crashed. Firebase’s session component sends one when the app launches, and again when the app becomes active after more than 30 minutes inactive — the interval Firebase ships with, which Firebase can change remotely. It carries a new random session ID, your Firebase installation ID, your Mac’s model, your macOS version and the app’s version, among other technical fields.
  • A crash report, only after a crash, sent the next time the app starts with this switch still on. It includes, among other things: your Mac’s model, CPU architecture, total memory and disk space, the memory in use and free at the time, your macOS version, your device’s language and region setting, the app’s version and build number, the time of the crash, the stack trace, and the crash’s own error message. Agent Activity’s own code puts no project data into a crash message in the released app; one raised by macOS, a system framework or a library is not written by it, and the app cannot control its text. It also includes the recent Google Analytics events from that run of the app, with their parameters (Crashlytics calls them breadcrumbs) — which is how a record type’s name can appear in a crash report — and a list of the binaries loaded into the app, which names the file path of Agent Activity’s own executable. If the app is installed under your home folder, that path includes your macOS account name. Google lists what Crashlytics collects at firebase.google.com/support/privacy.

Turning Share usage data off stops usage events at once. Turning Send crash reports off stops crash reports and session events from the app’s next launch at the latest; Google documents that Crashlytics applies this setting at the app’s next run. A crash report or session event already waiting to be sent when you turn it off can still be sent later. Turning crash reports back on first deletes any report still queued from while they were off, so a crash from that window is never sent.

When a switch is on, the hosts the app may contact for it are app-analytics-services.com, crashlyticsreports-pa.googleapis.com, firebaseinstallations.googleapis.com, firebase-settings.crashlytics.com and firebaselogging-pa.googleapis.com — all Google’s, all Firebase’s or Google Analytics’ own. Whatever the switches say, the Developer ID version also contacts le-max-app.com for its license and for update checks, and dl.le-max-app.com to download an update.

Independently of both switches, the app also sends one GET request to raw.githubusercontent.com (GitHub’s host for raw files) at its first launch, and after that about once a day, to download LiteLLM’s public, versioned list of AI-model prices used to show your costs. The request has no body and a fixed address, so nothing from your projects, transcripts or build logs is in it. It carries only standard headers — a User-Agent naming the app, its build number and the versions of macOS’s network library and kernel (for example Agent%20Activity/2 CFNetwork/3860.700.1 Darwin/25.6.0), an Accept-Language listing your Mac’s preferred languages (for example en-US,en;q=0.9), and Host, Accept, Accept-Encoding, Content-Type, Content-Length: 0 and Connection — with no cookie and no identifier the app creates, and GitHub, like any web host, sees the IP address it comes from.

04 Your two switches

The first time you open Agent Activity, it asks once, with two equal buttons — Share and Don’t share — before sending any usage or crash data, next to a link back to this page. Until you answer, none of it is sent. If you close that question without answering, the app’s main window asks it again, the same way, until you answer it there or set either switch yourself in Settings → Diagnostics. Your answer sets both of the following, which you can then change independently, any time, in Settings → Diagnostics:

  • Share usage data — the usage events and properties above, keyed to this installation’s identifiers; off stops the events at once.
  • Send crash reports — crash reports from the app’s own process, and the session events above; off stops both from the next launch at the latest, though one already waiting to be sent can still be sent later.

Turning one of these on or off in Settings before you have answered the first-launch question answers only that switch; the other stays off until you set it there too.

05 The license service and updates (Developer ID version)

The version of Agent Activity downloaded from le-max-app.com runs a 14-day trial, then needs a license key bought through Polar. For that — and only that — it talks to one service of ours at le-max-app.com/api/v1/sync, which runs on Cloudflare Workers. The Mac App Store version contains none of this code and never contacts it. This service is not optional in the Developer ID version, and it is separate from the two switches above.

What the app sends. The app contacts the service when you first open it, when you enter or remove a license key, about once a month to renew the license, and when you press Retry. Each request after the first — which asks only for a one-time challenge — carries:

  • a machine identifier: a SHA-256 hash of your Mac’s hardware UUID, salted for this app so it cannot be matched with any other app’s identifier;
  • a public key created for this installation in your Mac’s Secure Enclave, with a signature proving the installation holds its private half — the private key never leaves the chip;
  • the app’s version, and a fingerprint of the app’s code signature (its cdhash), which says whether this copy is one we released;
  • when you enter a key: the key, and your Mac’s name as set in System Settings → General → Sharing (its first 64 characters), so you can tell your Macs apart in Polar’s customer portal;
  • when renewing or removing a key: the key and its activation ID.

Every request is encrypted to the service on top of HTTPS. No transcript, build log, project name or path is ever part of it.

What the service keeps.

  • For the trial: the machine identifier and the time your trial started. It is deleted automatically 90 days later.
  • For each Mac a key is active on: the machine identifier, the activation ID, Polar’s ID for the key, and a hash of that installation’s public key — until that Mac removes the key in the app. A Mac that never does (one that is gone, freed from Polar’s customer portal instead) leaves the record in place; write to mt@le-max-app.com to have it deleted.
  • A count of requests by kind, result, app version and whether the build is one we released, with nothing that identifies your Mac, your key, you or your IP address. Cloudflare keeps these counts for three months.
  • Cloudflare, which hosts the service, sees each request’s IP address in transit, as any web host does; the service keeps no per-request log — only the type of an error, if one occurs.

What goes to Polar, and back. Polar is the store you buy from, and the merchant of record: your name, e-mail and payment are handled by Polar under its own privacy policy (polar.sh/legal/privacy), not by this app. When you enter a key, the service asks Polar to activate it, with your Mac’s name as the activation’s label and the hash of its public key as a condition; on renewal it asks Polar whether the key is still valid. It then reads from Polar the key’s status, its purchase date, how many of its three Macs are in use, and the e-mail the purchase was made with, and returns them to the app, signed. The app keeps the key and that answer in files on your Mac, encrypted with the Secure Enclave, and shows the e-mail in Settings → License. Nothing from Polar is stored by the service beyond the IDs listed above.

Updates. The Developer ID version checks le-max-app.com/updates/appcast.xml once a day for a new version, and when you install one it downloads it from dl.le-max-app.com. These requests carry no query parameters and no information about your Mac beyond what every web request carries — among it a user-agent naming the app, its version and the updater’s version; which update you are offered is decided on your Mac, not on our server.

The license key, its e-mail and your Mac’s name never reach Google, under any setting.

06 Who processes it

Agent Activity sends this data only to Google, through two Google products under separate terms. The Developer ID version’s license service is described in its own section above; it runs on Cloudflare and talks to Polar.

Firebase Crashlytics handles crash reports, and the session component the Crashlytics SDK brings with it sends the session events. Crashlytics is covered by the Firebase Data Processing and Security Terms (firebase.google.com/terms/data-processing-terms); where European data protection law applies, those terms make Google a processor of that data.

Google Analytics handles usage events and properties. It is a separate service with its own terms (marketingplatform.google.com/about/analytics/terms/us). This app’s Google Analytics account has accepted the Google Ads Data Processing Terms (business.safety.google/adsprocessorterms), and Google processes usage events under them as a processor. Every optional data-sharing setting in this app’s Google Analytics account is off. The Google Analytics terms require this app to disclose that it uses Google Analytics and how Google Analytics collects and processes data: the events and properties are listed above, the identifiers below, and Google describes its own use at How Google uses information from sites or apps that use our services.

What is sent is keyed to identifiers created for this installation, none of them used for advertising. They include:

  • the Firebase installation ID, created for this installation of the app;
  • Crashlytics’ installation UUID, which Crashlytics uses to count how many installations a crash affects;
  • a session ID, a random value Firebase replaces at each launch and whenever the app becomes active after more than 30 minutes inactive (Firebase’s default interval);
  • Google Analytics’ app-instance ID — the identifier Apple’s App Store privacy label lists as Device ID.

Each crash report also carries a random ID of its own, used to recognize duplicate crashes.

Unless a service offers data location selection, Firebase may process and store data anywhere Google or its agents maintain facilities (firebase.google.com/support/privacy). Google complies with the EU-U.S. and Swiss-U.S. Data Privacy Frameworks and the UK Extension to the EU-U.S. Data Privacy Framework for personal information from the EEA, Switzerland and the UK (same page).

Retention. Crashlytics keeps crash stack traces and their identifiers, including Crashlytics installation UUIDs and Firebase installation IDs, for 90 days before it starts removing them from live and backup systems (firebase.google.com/support/privacy). This app’s Google Analytics property keeps event data for 2 months after it is collected; data that reaches that age is deleted automatically, on a monthly basis. “Reset on new activity” is on, so each new event from your installation restarts the retention period of its user identifier. The retention setting does not affect Google Analytics’ standard aggregated reports (support.google.com/analytics/answer/7667196).

What this data is used for. Crash reports and session events: finding and fixing crashes, and measuring how often they happen. Usage events: learning which parts of the app people use, and which data sources fail in the field. Agent Activity uses this data for nothing else and shares it with no one besides Google. Google is bound in how it handles that data by the Firebase Data Processing and Security Terms for crash reports and session events, and by the Google Ads Data Processing Terms for usage events.

You can withdraw consent for either at any time by turning its switch off in Settings → Diagnostics; to ask what Agent Activity has sent about your installation, or to have it deleted, contact mt@le-max-app.com with both identifiers — Settings → Diagnostics shows them while either switch is on, and afterwards the last ones it read. Google Analytics finds your data by the Google Analytics app-instance ID, Crashlytics by the Firebase installation ID.

Agent Activity is a professional developer tool for building software in Xcode. It is not directed at, marketed to, or knowingly used by children.

07 Contact

Questions: mt@le-max-app.com

08 Changes

If this policy ever changes, the updated version will be posted on this page with a new “Last updated” date.

Support

Something not covered here?

Ask directly. Bug reports, refund questions and policy questions all arrive in the same inbox, and a named app plus its version number makes the first reply useful instead of a question.

Contact form
Direct support@le-max-app.com
Response Within 2 business days
App page Agent Activity
Store Mac App Store