Privacy Policy for Filing Agent
Effective Date: September 7, 2026 Publisher: CBAL LLC Contact: support@aj-lancaster.com
This Privacy Policy explains how Filing Agent (“the App”), published by CBAL LLC, handles your data.
The short version: the App collects nothing and sends nothing to us. We operate no servers. Your documents, their names, and the record of where they were filed stay on your Mac.
1. Local Processing and Storage
Filing Agent is a local-first macOS application. Document classification, rules processing, and file management happen on your device.
- We do not operate cloud servers for document storage.
- The App contains no code that sends your documents to us.
- Your files, folder paths, and filing history stay on your Mac — with one exception, entirely under your control: if you turn on Model Assist and choose a hosted AI provider, the text you send goes directly from your Mac to that provider. It never passes through us. Section 2 describes this in full.
- The App runs in Apple’s App Sandbox. It can read and write only the folders you explicitly choose, using macOS security-scoped bookmarks. It has no access to the rest of your disk.
- Your filing history is a database inside the App’s own container. There is no account, no login, and no identifier linking it to you.
2. Model Assist and Third-Party AI Services
Filing Agent offers an optional “Model Assist” feature. It is off by default, and the App classifies documents with a local rules engine that needs no model at all.
If you enable it, you choose where it runs:
- A model on your Mac (for example Ollama): all processing stays on your machine. No document text is transmitted anywhere.
- A provider you bring yourself (for example Anthropic, or any OpenAI-compatible endpoint): the App communicates directly with that provider using your own API key. CBAL LLC does not intercept, proxy, relay, log, or monitor these requests, and we operate no service in that path. Your data is then subject to that provider’s privacy policy and your agreement with them.
Controls that apply whenever Model Assist is on:
- We ask first. Before the App sends anything to a host that is not on your own machine, it asks you in a macOS system dialog naming that host. Your answer is recorded per host with the date, and you can withdraw it at any time.
- Never-send buckets. You can mark any bucket so its documents are never sent anywhere, whatever else is configured. That bucket’s name is withheld from requests too, because the name is often a client’s.
- Only an excerpt is sent, never the file itself.
- Your API keys are stored in the macOS Keychain, never in a configuration file, and are never transmitted to CBAL LLC.
3. Diagnostics
We collect no telemetry. Filing Agent contains no analytics, no crash reporting service, no advertising or attribution SDK, and no code that sends information to CBAL LLC. We operate no servers, so there is nowhere for such data to go.
The App writes a diagnostic log on your Mac, inside its own sandbox container:
- It records errors and significant events. It never records document contents.
- Folder paths and filenames are replaced with short, non-reversible tags before anything is written, and anything shaped like an API key is removed.
- It is capped in size, and older entries are discarded as new ones arrive.
- It never leaves your Mac. It is not uploaded, and the App has no mechanism to upload it. You can read it or delete it yourself at any time; the App shows you where it is.
Apple’s own reporting is separate. If you turn on “Share with App Developers” in macOS System Settings, Apple may send us anonymised crash reports about this App. That is Apple’s mechanism, governed by Apple’s privacy policy, and you control it in System Settings rather than in Filing Agent. We receive nothing else through it — no filenames, no document contents, and no record of what you filed.
4. Purchases
Filing Agent is a free download with an optional in-app purchase, sold through the Mac App Store. Apple processes every transaction. CBAL LLC does not collect, process, receive, or have access to your payment card details, billing address, or Apple ID.
Whether your copy is unlocked is verified on your Mac using the transaction record Apple provides to the App on your device, and is stored in the App’s own container. We do not operate a licensing server, and the App does not check in with us.
5. What We Never Collect
- Your documents, or any part of their contents
- Filenames, folder names, or file paths
- Your filing history
- Names, email addresses, or contact details
- Hardware identifiers, advertising identifiers, or any device fingerprint
- Location data
- Prompts sent to, or responses from, Model Assist
Filing Agent does not track you, does not build a profile, and shares nothing with data brokers or advertisers. The App’s bundled privacy manifest declares no tracking and no collected data types, which you can verify yourself inside the app bundle.
6. Your Rights
Because we hold no personal data about you, there is nothing for us to disclose, correct, export, or delete on your behalf. Your documents and your filing history are on your Mac and under your control: you can read, move, export, or delete them at any time without asking us.
If you believe we hold information about you, write to support@aj-lancaster.com and we will tell you what we have — which we expect to be nothing.
7. Children
Filing Agent is a productivity tool for general audiences and is not directed at children. We collect no data from anyone, including children.
8. Changes to This Policy
We may update this Privacy Policy as we add features or to meet legal requirements. Changes appear on this page with an updated Effective Date. Because we do not collect your contact information, we cannot notify you directly, so please review this page from time to time.
9. Contact
Questions about this Privacy Policy, or about the security architecture of Filing Agent:
support@aj-lancaster.com
CBAL LLC