Skip to content
replaceme
How it worksPrivacyInstall
Download for Mac ↓

Replaceme by TLVG

Privacy Policy

Effective 2026-09-19. Also read the Terms of Service.

  • In short
  • Who we are
  • What Replaceme reads on your Mac, and why
  • What leaves your Mac
  • Who receives it
  • What we store, and for how long
  • Your brief is an iMessage
  • How we protect it
  • Your controls
  • Your rights
  • Where your data is processed
  • Age
  • The website and support mail
  • Changes to this policy

In short

Last updated: 2026-09-19. What changed: clarified that resolved Contacts names can leave the Mac as sender labels.

Replaceme runs on your Mac. It reads the mail, messages, notifications and calendar already on it, and texts you a short brief when something looks like it needs your attention.

To decide what matters, Replaceme sends message content from your Mac to our server and on to the AI providers named below. That content includes full message bodies and sender and recipient addresses. Replaceme is not a local-only app.

Our server does not store your message content. It stores your account record and an operational log of counts, timings, models and costs, which is deleted after 14 days.

Your brief is delivered as an iMessage, so it appears wherever you are signed in to Messages, and it cannot be recalled once sent.

You can pause Replaceme, delete its local history, revoke any macOS permission, delete your account, and remove the app at any time. Write to support@replaceme.app with any privacy, access or deletion request.

Who we are

Replaceme is operated by TLVG (The Startups Generator Tel Aviv Ltd., company no. 515581627), 32 Ben Yehuda St., Tel Aviv, Israel, under licence from the owner of the Replaceme intellectual property.

TLVG decides how and why your personal data is handled in connection with Replaceme, and is the party you should contact about it.

Contact for anything in this policy, including access and deletion requests: support@replaceme.app.

What Replaceme reads on your Mac, and why

Replaceme reads four sources on your Mac: new mail in Apple Mail, recent iMessage and SMS conversations in Messages, recent macOS notification text from the apps on your Mac, and events from your calendars in the next 24 hours. It reads them only to decide whether something appears to need your attention and to write your brief.

Mail, Messages and Notifications keep their data in protected local databases. macOS gates those databases behind Full Disk Access. Full Disk Access is a broad permission: once you grant it, macOS does not limit Replaceme to those three databases. What limits Replaceme is its own code, which reads Apple Mail's Envelope Index and message files, the Messages database, and the notification store, and nothing else. We describe this plainly because the permission you grant is wider than the use we make of it.

Calendar access is requested separately through macOS, and is used for context only — Replaceme never creates, edits or deletes an event. Contacts access is requested separately to resolve sender names on your Mac; those names may also be sent as described below.

You sign in with Google. We use Google only to confirm who you are, through Supabase's standard sign-in flow, which gives us your basic profile and your email address. We do not request access to Gmail, Google Drive or any other Google service. If Gmail messages appear in Replaceme, it is because they are already synced into Apple Mail on your Mac.

What leaves your Mac

When Replaceme runs, it sends the following to our server over an encrypted connection:

For each item it is considering — the sender, the subject or first line, the message body, whether that body was shortened, the time, and a thread identifier. The Mac app sends up to the first 8,000 characters of a body. For mail it also sends the From, To and Cc addresses and whether you were a direct recipient or on copy. For iMessage it also sends whether the message was from you, and up to 20 earlier messages from the same conversation in the previous 24 hours, each up to 2,000 characters.

Names resolved from Contacts can be sent to our server and AI providers as sender labels for iMessage items.

Calendar context — up to 20 events from the next 24 hours, with their title, start and end time, location, attendee names and calendar name. (Our server will also accept a list of reminders; the current Mac app does not send one.)

The instructions you wrote in Settings for what to alert you about and what to ignore, and your first name. We do not send your email address as part of a run.

So, to be direct about it: full message bodies, and the addresses of the people who sent and received them, leave your Mac. These are not excerpts. If that is not acceptable for the accounts on your Mac, Replaceme is not the right app for you.

Separately from a run, the app sends a short status ping (counts, timing and error information, no message content), and — if you use Settings → Feedback — the message you write plus the redacted log excerpt shown to you in that window, which you can edit or clear before sending.

Who receives it

We do not sell your data and we do not share it for advertising. The following service providers receive data because the product cannot work without them.

TypeSafe (the Jev model) — classification. Receives the message body, sender, iMessage thread context, your first name and our classification policy for each item. It is not sent your calendar. Processing takes place in the United States. TypeSafe's published privacy policy states that it does not train or fine-tune on inputs; its retention statement sets no fixed deletion period.

OpenRouter and the model provider it routes to (currently DeepSeek V4 Flash) — writing the short blurbs for flagged items and ranking them, and classification when the TypeSafe route is switched off. Receives the same item fields plus your calendar context. We send every request with data collection denied, so OpenRouter routes only to model providers it classifies as not retaining or training on prompts.

Which of those two handles classification depends on how the service is configured at a given time; both are named here so the answer does not depend on when you read this.

Supabase — sign-in and our database, in the US East region (us-east-1).

Railway — hosting for our server, in Singapore (asia-southeast1).

Google — sign-in only, as described above.

Apple — delivery. Your brief is sent through Messages on your Mac, and travels over Apple's iMessage service under Apple's own terms and privacy policy.

Sentry — crash and error reports from the Mac app and our server, used to find and fix bugs. Processing takes place in the United States. Reports are redacted before they are sent and do not carry the content of your messages.

We do not use your messages to train or evaluate AI models. The evaluation work behind Replaceme's accuracy numbers was done on the founders' own accounts.

What we store, and for how long

On our server, we never store the content of your messages. Once a run is finished, the item text is gone from our side.

We store an operational log row per action: your user id, what happened, which model was used, token counts, cost, and metadata limited to counts, identifiers and reasons. A scheduled job deletes these rows after 14 days.

Feedback you send from Settings → Feedback is stored in that same log and deleted on the same 14-day schedule. Mail you send to support@replaceme.app stays in our mailbox for as long as we need it to deal with your request.

We store your account records — your profile, your registered devices and their public keys, your monthly usage counters, and the scheduling records that stop two devices sending you the same brief twice — until you delete your account.

When you delete your account we remove all of that. One row remains: an irreversible hash of your email address, the date, and whether you or an administrator requested the deletion. We keep it so that we can show a deletion was carried out. It is a hash, not your address.

On your Mac, Replaceme keeps the last 50 reports for up to 14 days so you can see what was sent, in ~/Library/Application Support/app.replaceme.mac. Your sign-in tokens and this device's signing key are kept in the macOS Keychain.

Your brief is an iMessage

Replaceme delivers each report to you as an iMessage, and the report itself contains personal information about you and the people who wrote to you.

Because Messages syncs across your Apple ID, a report may appear in places other than this Mac: lock-screen previews, an Apple Watch, synced iPads or other Macs, devices your family or colleagues can see, the Messages app's own history, and iCloud backups. Once an iMessage is sent, it cannot be taken back — not by you and not by us.

Think about where your Messages account is signed in before you turn Replaceme on.

How we protect it

Traffic between your Mac, our server and every provider we use runs over TLS.

Database access is restricted per user by row-level security, so one account's records cannot be read by another.

Each Mac registers a signing key — held in the Secure Enclave where the hardware supports it — and requests are signed with it, so a stolen access token alone is not enough to make requests as you.

Per-user cost caps limit how much processing any one account can trigger in a day.

Message content is never written to our server logs, and the log files the Mac app writes are redacted as they are written.

We make no claim that your message content is encrypted in a way that prevents us or our providers from reading it — they read it in order to process it — and we hold no security certification such as SOC 2. No system is perfectly secure. This section describes what we actually do, not a guarantee.

Your controls

Pause — from the menu bar. Scheduled and manual runs stop. Nothing is read and nothing is sent until you resume.

Sign out — in Settings → Account & billing. Runs stop, because they require a session. Your account and its records stay until you delete them.

Delete local history — in Settings → Privacy. Removes every locally stored run on this Mac. It does not affect briefs already delivered to Messages, and it does not delete your account.

Delete your account — in Settings → Account & billing, or by writing to support@replaceme.app. Removes your account and the records listed above. Briefs already delivered to Messages stay in Messages; they are your own messages and we cannot reach into Messages to remove them.

Revoke a permission — in System Settings → Privacy & Security. Removing Full Disk Access stops Replaceme reading Mail, Messages and Notifications. Removing Calendar or Contacts access removes that source. Removing Automation access for Messages stops delivery.

Remove the app — quit Replaceme from the menu bar, then drag it from your Applications folder to the Trash. To clear what it leaves behind, open Finder, choose Go → Go to Folder, enter ~/Library/Application Support, and move the app.replaceme.mac folder to the Trash. Sign-in tokens and the device signing key can be removed from Keychain Access by searching for replaceme and deleting the matching items. Removing the app does not delete your account on our server — do that first if you want both gone.

Your rights

Depending on where you live, you may have rights over your personal data — to ask what we hold, to get a copy, to correct it, to have it deleted, to object to or restrict certain handling, and to complain to a data protection authority.

Write to support@replaceme.app and we will deal with your request. In practice the two things we can do quickly are to tell you what we hold for your account and to delete it, and you can do the second yourself from Settings at any time.

Where your data is processed

Replaceme is available worldwide, and the providers above process data outside your country. Our server runs in Singapore. Our database and sign-in run in the United States. TypeSafe processes in the United States. Sentry processes in the United States. OpenRouter routes to model providers in locations it determines.

If you are in a region whose law restricts transfers of personal data abroad, we rely on the transfer being necessary to provide the service you asked us for. We have not put standard contractual clauses or another separate transfer mechanism in place with these providers. We would rather tell you that than imply a safeguard we do not have. If that matters to you, do not use Replaceme.

Age

Replaceme is for people aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has an account, write to support@replaceme.app and we will delete it.

The website and support mail

This website does not set advertising or analytics cookies and does not track you across sites.

If you write to support@replaceme.app, we receive your email address, your message and anything you attach, and we keep it in our mailbox for as long as we need it to handle your request.

Changes to this policy

If we change this policy in a way that materially affects you, we will update the date at the top, note what changed, and — for changes that alter what we send or who receives it — ask you to read and accept the new version in the app before Replaceme sends anything else.

Questions: support@replaceme.app.

Questions about this document? Email support@replaceme.app.

replaceme

Your Mac, working for you.

How it worksPrivacy & dataInstallQuestionsPrivacy PolicyTermsSupport
© 2026 TLVG · ReplacemeMade for Mac. Powered by Jev.