gulp ← back to gulp
privacy policy

Gulp: Privacy Policy

Effective September 25, 2026

The short version

Nothing leaves your Mac.

Gulp is a scratchpad for your Mac’s menu bar. It does not send any data off your device: no analytics, no telemetry, no crash reporting, no cloud sync and no account. Everything you type or say to the fish stays on your Mac, and only for as long as the note lives.

What Gulp keeps on your Mac

  • Notes that are still alive. Each note’s text, when you fed it, and when it will fade. Nothing else.
  • Your preferences. How long notes last, how many the bowl holds, theme, text size, where the bowl opens, sounds, the fish’s blinking and cursor-following, your keyboard shortcuts and launch at login.
  • A welcome-tour flag, so the tour doesn’t show every time you open Gulp.

Notes live in a single file inside Gulp’s App Sandbox container, which only your user account can read:

~/Library/Containers/com.FoundationModel.Gulp/Data/Library/Application Support/Gulp/bowl.json

The file only ever holds notes that are still alive. When a note fades or you let it go, it is gone from the file on the next save. When the bowl is empty, the file is deleted. When your Mac restarts, the bowl starts empty. There is no history, archive, backup or log of forgotten notes, so there is nothing for anyone, including us, to recover. Deleting the app removes everything.

Speaking to the fish

When you press the voice shortcut, Gulp listens through your microphone and turns your words into text with Apple’s speech model, on your Mac. The audio is held in memory only while you’re speaking (up to a minute), and is never written to disk, saved or sent anywhere. Only the text becomes a note.

The first time you speak, macOS may need to download the speech model for your language from Apple. macOS does that download, not Gulp, and Apple’s privacy policy covers it. None of your audio or text is part of it.

What Gulp does not do

  • Gulp does not connect to the internet. It has no network permission, and the App Sandbox blocks it from sending or receiving anything, even in principle.
  • Gulp does not collect personal information. No name, email, location, contacts, account, login or identifier of any kind is requested or stored.
  • Gulp does not share data with third parties. Nothing leaves your Mac, so there is no one to share it with.
  • Gulp does not use analytics, telemetry, advertising IDs, fingerprinting or cookies.
  • Gulp does not read your clipboard. It writes to it only when you copy a note. Text from other apps reaches Gulp only when you send it: through the right-click Services menu (“Feed the Fish”) or by dropping it on the fish.
  • Gulp does not report crashes to us or anyone else. macOS’s own crash reporter may collect crash data according to your system-wide settings; Apple’s privacy policy covers that, not ours.

macOS permissions Gulp asks for

Gulp uses macOS’s standard permission prompts, and only for the feature each one belongs to. You can change any of them in System Settings › Privacy & Security.

  • Microphone: asked the first time you speak to the fish, and used only while you’re speaking.
  • Speech recognition: asked alongside the microphone so Apple’s on-device model can turn your voice into text.
  • Launch at login: optional. Registers Gulp as a login item through Apple’s SMAppService so the fish is there when you sign in. Turn it off in Gulp’s Settings or in System Settings › General › Login Items.

If you only type, Gulp never asks for the microphone at all. Gulp does not ask for Accessibility, screen recording, full disk access, notifications, contacts, location or the camera. Because it runs in the App Sandbox, macOS enforces these limits: Gulp cannot reach files outside its own container or the network.

Children’s data

Gulp does not knowingly collect data from anyone, including children under 13. Because nothing leaves the device, the app’s design enforces this, not just a promise.

Changes to this policy

If Gulp ever adds a feature that sends data off your Mac, this page will be updated and the effective date above will change before that version ships.

Contact

Questions about this policy or about Gulp: