plain-language notice
Minimal community analytics.
Ginse collects only the information needed for community features, the optional private scan, moderation, and aggregate service measurement.
Private stack scan
The website cannot inspect your Mac. Your local-capable agent fetches the public skill and asks once for consent before any inspection or lookup. It may read temporary, read-only copies of the last 30 days of Chrome/Chromium history, recent Spotlight app metadata, and the current user's local Screen Time app-duration store.
Full Disk Access is a broad, separate macOS permission: Ginse never grants it, uses sudo, or bypasses a denial. Cloud Screen Time and broader activity databases are not opened. The scan keeps recognized product names, discards page details and unknown identifiers, and falls back to conservative recency when Screen Time is unavailable; missing access is not zero use. Temporary copies are deleted when the scan ends or stops.
Raw history, usage observations, and the private report stay on your Mac. Ginse receives only recognized product names and inferred jobs for replacement requests; external scoring services receive only non-null product origins.
Optional sharing and measurement
Sharing is a separate choice after the report. Before asking, the agent must preview every public field. An unlisted link stores only the percentage, methodology version, and one to three public catalog recommendations with actions. For each recommendation, you may also opt in to publish one or two exact public catalog apps it replaces. Ginse accepts catalog IDs only—not raw inventory, free-form app names, jobs, history, usage, hours, AX details, report text, identity, or device data. Anyone with the link can view it for 30 days; the private token can revoke it earlier, though social previews may remain cached.
If the agent finds an external candidate, submitting it is another separate choice. The preview and pending review record contain only its product name, canonical URL, API/CLI/MCP interface, core-job claim, and first-party evidence URL. No scan data or identity is attached. The candidate is not public, eligible, or ranked unless human moderation later admits it.
Daily aggregate scan events cover skill fetch, prompt copy, consented completion, and recommendation click. They contain no tools, domains, jobs, usage, reports, or device IDs.
Community and analytics
Anyone may read the catalog or submit a report. Votes, comments, and AX reviews require a verified sign-in. Email is used for account enforcement, not published. Approved listing URLs and display names, comments, and review evidence may be public; report notes remain in moderation. Submitted URLs, names, comments, review evidence, and notes are retained to run the index and review queue. Do not submit secrets or unwanted personal information.
Visits and outbound clicks use purpose-specific HMAC hashes, not raw identifiers. Daily hashes use date, IP address, and user agent; rate-limit hashes use IP. Referrer hosts and aggregate counts may remain. Visit analytics are skipped when your browser sends Global Privacy Control or Do Not Track.
Infrastructure
Hosting and data-service providers process ordinary request and application data needed to deliver, secure, and rate-limit Ginse. Their privacy notices describe that processing.