Legal
Privacy Policy
Effective date: 2026-05-24.
This page explains what Costwell does and does not do with your data. We wrote it in plain language because the answer is short: nothing about your usage leaves your Mac.
What we collect
Nothing transmitted to our servers from app usage. We do not run servers that store user data. We have no analytics pipeline, no event tracker, and no account system. We never see your conversations, your token counts, your project names, your Apple ID, or your email address. We learn that someone bought the app only because Apple sends us aggregate sales reports — those reports do not identify you.
What stays on device
The following data lives on your Mac and never leaves it:
- All conversation content read from
~/.claude/projectsJSONL files. - All diagnostics produced by Costwell while it analyzes your usage.
- All index data (the SQLite database and the FTS5 full-text search index) the app builds for fast search.
- All StoreKit transaction records that prove you own the Pro upgrade.
You can delete this data at any time by quitting Costwell and removing its container from ~/Library/Containers/com.solenos.Claude-Usage-Analyzer/.
What our app downloads
Nothing. Costwell makes no network requests at all — no analytics beacon, no remote configuration, no telemetry, no automatic update checker beyond the Mac App Store itself. The app is built without the com.apple.security.network.client entitlement, so the operating system would block any outbound socket the app attempted.
Claude model pricing data ships bundled with the app. When Anthropic publishes new rates, we update the bundled rate sheets and ship a new version through the Mac App Store. Rate sheets are dated and additive, so historical cost calculations remain accurate after updates.
Crash reporting
Crash and performance reports use Apple's MetricKit framework. Reporting is off by default — it only runs if you turn it on under Settings → Data → Diagnostics. It is additionally gated by your system-level "Share with App Developers" setting (System Settings → Privacy & Security → Analytics & Improvements), so even when enabled, nothing leaves your machine if you've turned that off macOS-wide. When reports are sent, MetricKit collects them on your Mac and Apple aggregates the payload for us inside Xcode Organizer. Apple is the only counterparty. We never receive raw payload bytes, IP addresses, device identifiers, or anything we could correlate back to you.
App Store IAP
The Pro upgrade is sold through the Mac App Store. Apple handles the entire purchase. We never see your payment data, card numbers, billing addresses, or Apple ID tokens. After purchase the app receives a Transaction object from StoreKit that says only "owned" or "not owned" for the Pro identifier. That single bit is all we get.
Third-party SDKs
None. Costwell is built on Apple frameworks only — SwiftUI, AppKit, MetricKit, StoreKit, and OSLog — plus our own Swift code. There is no analytics SDK, no advertising SDK, no crash-reporting SDK from a third party, and no remote configuration service.
Children
The app is not directed at children under 13. We do not knowingly collect or process data from children. If you believe a child has used Costwell, please contact us so we can confirm there is no data on our side to remove (there should not be).
Contact
Questions about this policy? Email support@solenos.com.
Changes to this policy
If we update this policy, the next version of Costwell will show a one-time in-app banner that links here. The "Effective date" line at the top of this page will reflect the most recent revision so you can see when the policy last changed.
Last updated: 2026-05-24.