Polyviral / Petal

Privacy Policy

Last updated September 17, 2026

Overview

This policy describes what information Petal handles, where it stays, and the choices you have. The short version: Petal runs on your Mac. There is no Petal account, no Petal server, no analytics, and no ads. We do not receive your usage numbers, your provider identity, or anything else about how you use the app.

What Stays on Your Mac

Your connected accounts, their names and colors, and the usage readings Petal has fetched are stored in ~/Library/Application Support/Token Bar/ with owner-only permissions. Sign-in profiles that Petal creates for you live in a folder beside it. API keys are kept in the macOS Keychain and never appear in saved snapshots, widget data, URLs, or logs. None of this is sent to us.

Connecting a Provider

Adding an account opens the provider’s own sign-in in your browser, where you choose the account. Authentication belongs to the provider and its tools; Petal does not read browser cookies, extract credentials, or copy them between accounts. To read your remaining allowance, Petal asks the provider’s own command-line tool for usage, using read-only requests. It does not send prompts or model requests, and it does not read your conversations or local transcripts.

Checking Your Identity

Before accepting a reading, Petal confirms which account the provider is reporting for, so a saved account never shows someone else’s numbers. The email a provider reports is stored locally with that account and used to detect duplicates and changed logins. If you add an OpenRouter key, the email you type is stored locally for the same purpose; OpenRouter does not verify it.

What Leaves Your Mac

Three kinds of request leave your Mac, and no others:

Usage checks go to your providers — OpenAI, Anthropic, or OpenRouter — through their own tools and under your own account. App update checks fetch the update feed and, when you install one, the new version. The optional Codex reset watch, which is off until you turn it on, is a plain request for a public JSON file from codex-resets.com carrying no cookies, identifiers, or account data.

Widgets

Desktop widgets receive only account labels, which account is selected, and the usage snapshots they need to draw. They never receive credentials.

Diagnostics

There is no analytics SDK and no crash-reporting service in Petal. Provider errors are turned into a fixed set of short messages inside the app; raw diagnostic text is not displayed, logged, or transmitted. If you choose to send us a bug report by email, we see only what you put in that email.

Deleting Your Data

Removing an account in Settings deletes its stored readings and signs out the sign-in profile Petal created for it, while leaving your own files and conversations alone. Accounts you connected from an existing login are disconnected without being signed out. Deleting the app and the Token Bar folder in Application Support removes everything Petal has kept. Because none of it reaches us, there is nothing for us to delete on your behalf.

Third Parties

Your providers process your account and usage under their own privacy policies, as they already do when you use them directly. Purchases are handled by our payment provider under its own policy; we never see your card number. Polyviral is independent of OpenAI, Anthropic, OpenRouter, and xAI.

Children’s Privacy

Petal is not directed at children under 13, and we do not knowingly collect personal information from anyone.

This Website

This website uses anonymous, cookieless analytics to count visits. It sets no tracking cookies, collects no personal data, and behaves the same whether or not your browser sends a Do Not Track signal.

Changes to This Policy

If this policy changes in a meaningful way, we will note it here and update the date at the top. Minor clarifications may be made without notice.

Contact

Privacy questions can be sent to privacy@polyviral.org.

© 2026 Polyviral polyviral.org