Privacy
What stays on your Mac, and what goes to your provider
Your history, passwords and agent threads live on your Mac. Rill’s AI features run the Claude Code or Codex you already use, and each one sends what it needs to that provider, under your own account. This page describes Rill 0.1.0.
Who we are
Rill is made by Manifold AI Inc. (“we”). Questions about this page, or about your data: contact@rill.love.
What goes to your provider
In Rill 0.1.0, every AI feature runs the Codex or Claude Code CLI installed on your Mac, signed in to your own account. Codex sends to OpenAI and Claude Code sends to Anthropic, under that account’s terms. Tab groups, day episodes, search, routing and project areas use the provider set in Settings › Agents › Answer with. Tasks use the one in Send tasks to. Nothing from a private window is sent.
| Feature | When it runs | What is sent |
|---|---|---|
| Tab groups | When the start page opens, and after your tabs and your Mac have been quiet for 2 minutes, with 3 or more page tabs open and one not yet grouped (on unless you turn it off); and when you choose Organize tabs | Titles, addresses, hosts and opener links of open tabs in normal windows. A local file’s tab sends its path. No page text. |
| Day episodes | Once 15 of today’s visits are waiting, when History opens with visits waiting, and when you choose Describe this day | For each new visit: title, address, local time, tab numbers and up to 280 characters of page text. Also the day’s last episode. |
| Find a page you remember | When you search with Describe | A read-only agent searches your Rill library (history with page text, day episodes, kept passages, the project index), and what it reads is sent. Exact words searches on your Mac only. |
| Routing a task | Each new request sent without a chosen project | Your request; the page’s address and title with the selection or its first 2,000 characters of text; the project catalog (names, folders, stacks, descriptions, README excerpts, git remotes, latest commit subjects, session titles). |
| Search deeper | When the quick routing pass is unsure, or when you choose it | A read-only agent reads the project index Rill keeps, and what it reads is sent. |
| Project areas | When Projects first has 6 or more projects; again when 8 or more were added or removed, or a fifth of them changed, at most once a day; and when you choose Rearrange Areas | The project index: names, folders, stacks, README excerpts, commit subjects, session titles, and your own moves and area names. |
| Asking about a page | When you ask | Your question, the page’s address and title, and the selection or up to 18,000 characters of its text. |
| A task in a project | When you send one | Your request (with the page, when you sent it from one), and whatever the agent reads and runs in the project. |
| Agent tabs | When an agent opens or reads a page in a background tab | The pages the agent reads. |
Pages with password, one-time-code or card fields are treated as sensitive: no feature sends their page text, and their visits are saved without text.
The CLIs keep their own records of these runs. Codex writes session logs to ~/.codex/sessions and Claude Code to ~/.claude/projects for tasks and page questions, including the request and the page text sent with it. Tab groups, day episodes, routing, project areas and library searches leave no saved session.
What stays on your Mac
Everything Rill keeps is on your Mac, in ~/Library/Application Support/Rill unless a path below begins with ~ or /.
| Data | Where | What it holds |
|---|---|---|
| History | Library/history/YYYY-MM-DD.jsonl | Each page visited in normal windows: address, title, times, how you reached it, tab ids, time on screen and up to 8,000 characters of the page’s text. Sensitive pages and imported visits: address, title and times. |
| Day episodes | Library/index/days/ | Episode titles, summaries and the day’s sentence, written by your provider |
| Project index | Library/projects/ | Project folders, names, stacks, README excerpts, git remotes (credentials removed), latest commit subjects, session titles and the areas |
| Threads | Threads/ | Your requests, the page text sent with them, answers, tool calls and file diffs |
| Tabs and bookmarks | session.json | Addresses and titles of open tabs; bookmarks, with the folder and browser they were imported from |
| Caches | Intelligence/ | Session titles and first messages from Codex and Claude Code logs, the project index cache, tab groups |
| Site icons | Favicons/ | One icon per site visited in normal windows |
| Site permissions | permissions.json | Your camera, microphone and location decisions, per site |
| Downloads list | downloads.json | Each download’s name, where it was saved, its address and the page it came from. Not kept for private windows. |
| Projects you added | projects.json | Folders you added in Projects |
| Run marker | running.json | Process id, launch time and version, while Rill runs |
| Saved passwords | The macOS Keychain | Each login you save or import: the site, the account name and the password. Kept in the Keychain, not in Rill’s files. |
| Settings | ~/Library/Preferences/love.rill.Rill.plist | Preferences, sites where Rill never offers to save a password, sites never saved in history, the downloads folder, per-site download rules and the time of the last update check |
| Cookies, website data, cache | ~/Library/WebKit/love.rill.Rill, ~/Library/HTTPStorages/love.rill.Rill, ~/Library/Caches/love.rill.Rill | Cookies, website data and the cache for normal windows |
| Downloads | Your downloads folder | Files you download, marked so Gatekeeper checks them before they first open |
| Temporary files | /tmp and $TMPDIR | Per-task files while tasks run, and a copy of another browser’s history during an import. Each is removed when its task ends. |
Private windows keep cookies, site data and icons in memory and save no tabs, history or icons. Closing the window discards them. Finished downloads stay in your downloads folder.
Who can read these files
- Your account. Rill’s folders are readable by your account only (0700), and so is every file it writes (0600).
- Other accounts on this Mac cannot read them. Administrators can.
- Any program running as you can, including the agents Rill starts. The files are plain text, so turn on FileVault in System Settings.
- Time Machine backs them up with the rest of
~/Libraryunless you exclude it.
Passwords
- Where. Passwords you save or import are in the macOS Keychain on this Mac, labeled “Rill”.
- Who can read them. You, in Rill, after Touch ID or your Mac’s password: filling, showing, copying and editing ask once per unlock session, and locking or sleeping the Mac ends it.
- Not sent to agents or your provider. Passwords and field values are not part of what Rill sends to Codex or Claude Code, and agents’ tabs are not filled.
- Websites. A page gets a password only when you choose an account in Rill’s list, and only on the site it was saved for. An https password is never filled on an http page.
- Passkeys do not work in Rill yet. Sign in with a password, or open the page in Safari.
Turning features off
Background features run on their own. Everything else runs only when you ask.
- Tab groups
- Settings › Tabs › Group tabs on the start page. Organize tabs still works when you choose it.
- History and day episodes
- Settings › History › Save history. With it off, Rill saves no new visits and writes no new episodes.
- Pages agents open
- Settings › History › Skip pages agents open keeps them out of your history. It is on unless you turn it off.
- How long history is kept
- Settings › History › Keep history: forever, 1 year, 90 days or 30 days. List sites that are never saved there too. Settings › Privacy clears browsing data for the last hour, today or all time.
- Search engine
- Settings › General › Search engine: Google, DuckDuckGo, Bing, Kagi or Ecosia. Searches you submit and search suggestions go to the one you choose.
- Search suggestions
- Settings › General › Show search suggestions. With it off, nothing you type in the address field leaves your Mac until you press Return.
- Which provider answers
- Settings › Agents. Answer with sets the provider for tab groups, day episodes, search, routing and project areas. Send tasks to sets the one for tasks.
- Tasks and page questions
- They run when you send them. Stop (⌥⌘.) ends a task and its website access.
- Clicks and typing on websites
- Agents click and type in their tabs only for a request you send with Allow website clicks and typing turned on.
- The update check
- Settings › General › Check for updates once a day.
Websites
- Websites receive your normal browsing requests.
- Site icons are fetched from the site you visit, without cookies.
- Your search engine (Google unless you choose another in Settings › General) receives the searches you submit from the address field and, while Show search suggestions is on, the words you type there. Never from a private window, and never an address.
- Each agent task gets its own temporary cookie store. Your cookies and logins stay with you.
The update check
Once a day Rill asks rill.love for releases.json, over HTTPS. Its user agent is Rill/0.1.0: the version, and nothing else about you or your Mac. No cookies and no identifier. When a newer version runs on your macOS, a note says so, with Download, which opens its page on rill.love.
This website
rill.love doesn’t set cookies or run analytics, and it loads its fonts, images and film from rill.love.
rill.love is hosted on Cloudflare Pages. Cloudflare handles each request, including your IP address, to serve and protect the site, under its own privacy policy.
Limits
- Prompt injection is reduced, not solved. Text on a page, in a README or in a commit can still steer what an agent says and does within its limits.
- Codex tasks can read any file your account can, and what an agent reads goes to your provider.
- Agents run with Rill’s macOS permissions. If you give Rill Full Disk Access to import from Safari, turn it off after the import.
- Agent tabs can reach local development servers and other devices on your network, such as a router’s page.
- Anything running as your account can read Rill’s files and the CLIs’ logs. Saved passwords are in the Keychain instead.
Security problems
Report a security problem privately to contact@rill.love. Include the Rill version (Rill › About Rill), your macOS version, and the output of codex --version or claude --version when an agent is involved.