Privacy Policy
Last updated: 23 September 2026
This covers Clausage, Clauswitch, the website at schizm.app, and what happens when you buy
a license or write to support.
The short version
The apps send anonymous telemetry: no account, no login, no profile, just a random id made on your machine. They never send your tokens, your email, your usage percentages, your file paths, or anything Claude returned to you. You can switch it off in one click and the apps work exactly the same.
The only data we hold that is actually about you comes from buying a license or writing to us. Both are described below, with how long we keep them.
1. Who is responsible
Jan Knoflíček, trading as Schizm, Czech Republic (IČO: 01598074), is the data controller. Contact: [email protected].
2. What the apps send
Two separate streams, each independently switchable.
Diagnostics
A caught failure is reported as a category and the layer it happened in, for example a rejected usage request at the endpoint. That is the entire content: no message, no file, no stack trace, nothing you typed. Each distinct kind is sent at most once a day.
If Clausage crashes, macOS writes a crash report to your Mac. On the next launch Clausage sends a reduced summary: the exception type, the signal, which part of the app was involved, a short grouping code, the version that crashed, and how long it had been running. The grouping code is the same for everyone who hits the same bug. It is not a fingerprint. The crash file itself never leaves your Mac unless you attach it to an email yourself.
Product analytics
About one event per day per install, carrying a coarse snapshot with counts rounded into ranges, never exact numbers: how old the install is, free or Pro, whether the companion app is present, how many accounts as a bucket, which data source served most refreshes, how many failures and notifications there were, and a handful of yes/no settings states. Clauswitch’s version of the same event adds bucketed switch counts, how many windows were open, and how many folder rules exist, never what any of them says.
Alongside that, a small set of milestones, each sent once when it happens: activating a license, the first account switch, reaching two accounts, finishing the first-run flow, clicking the companion-app pointer, turning on local-cache-only mode, and an upsell being shown or clicked.
The full list of every event and every property either app can send is published on the transparency page. It is generated from the same contract file the apps’ own tests are checked against.
3. What is never sent
No diagnostics or analytics report ever contains any of the following:
- OAuth tokens or any credential
- Email addresses
- Organization or account names and ids
- File paths, config directory paths, workspace or repository names
- Your folder-rule patterns
- Usage percentages or numbers, in any form, not even bucketed
- Usage-credit settings and amounts
- The raw response from Anthropic’s endpoint, in any form
4. How the anonymity works
- Identity is a random id made on your machine, one per app, connected to nothing. There is no account and no login.
- Events are not tied to any profile, and the location they come from is not recorded.
- The apps ship no analytics SDK. There is no autocapture and no session recording, because neither exists in the app.
- Telemetry is received by PostHog on their EU Cloud region, acting as our processor.
5. Turning it off
Clausage: Settings → Privacy has one switch per stream. The same screen shows your random id and a Reset ID button.
Clauswitch: VS Code’s own telemetry.telemetryLevel is the master switch, and Clauswitch can
only ever be more private than it, never less. Clauswitch’s own clauswitch.telemetry setting can
tighten it further, and setting it to off deletes the random id.
Nothing about the apps’ behaviour changes when telemetry is off.
6. If you write to support
Mail to [email protected] is read by one person, the author. If you choose to attach a crash
report (.ips), it contains stack traces, the list of software loaded on your Mac at the time,
and file paths. The app says this before you send it, and attaching is always your decision.
Support mail and anything attached to it is kept for 12 months and then deleted. It is not forwarded anywhere and not fed into any analytics system.
7. If you buy a license
Lemon Squeezy is the Merchant of Record and handles the checkout, your payment details and the invoice under their own privacy policy. We never see your card details.
From that purchase we record a license record: the license identifier, the name and email address the license is issued to, the dates, the store’s order identifier, the sales channel, and the license key itself. That record is our sales ledger. It exists so the license can be re-issued if you lose it, so support requests can be matched to a purchase, so refunds end the licenses they refund, and so we have our own record independent of the store. The legal basis is performance of the contract and our legitimate interest in keeping our own books.
Your name and email are also inside the signed license file itself.
Where it lives. License records are held in a database at Cloudflare (our processor) in
their Western-Europe region. The license email is sent by Resend (our processor) from
[email protected]. Backup copies exist at Cloudflare and at Backblaze, encrypted on our side
before upload. Those three, plus PostHog for the anonymous telemetry above, are the complete
processor list.
The daily license check (the Terms, section 6). About once a day, an app holding a Pro license confirms it with our server. That request carries your signed license file, and so the name and email above, the app’s name and version, and a random install id the app makes up on your machine. The install id is not tied to your hardware. It identifies nothing but itself and lets us count installs. We keep per-license check-in timestamps and the install ids that have checked in. The connecting IP address is handled like any web request, briefly, for rate limiting. No telemetry rides along, and a free-tier install never contacts the server at all. The exact fields are on the transparency page.
Retention. We keep the license record while the license is active and for 2 years after it ends (refund, chargeback or revocation), then delete it. Check-in rows for ended licenses are removed much sooner. If you ask us to delete your record earlier, we will anonymize it: your name and email are replaced and the install rows deleted. Your license keeps working, but we can then no longer re-issue your key or verify your purchase.
8. The website
schizm.app uses the same PostHog project as the apps and records page views, page exits
(including how far down you read), and clicks on the download and buy links. Unlike the apps,
the site uses an analytics library, which attaches its own standard properties to each event: which
page, where you arrived from, the shape of your screen. The
transparency page lists every event and every property in full.
Autocapture, session replay and location lookup are switched off, and the site sets no cookies, so
there is no cookie banner.
The checkout is the exception. Buying Pro opens Lemon Squeezy’s checkout in a frame on the buy page. Their checkout sets its own cookies on their own domain, as any payment page does. Nothing it stores is readable by this site, and no card details ever reach schizm.app. Lemon Squeezy handles payment data as an independent controller (section 7).
9. Your rights
Under the GDPR you can ask for access, correction, deletion, restriction, objection and portability of personal data we hold about you. In practice that means the license records (including their check-in timestamps and install ids) and any support correspondence, since those are the only places personal data exists.
The telemetry is the exception. It is anonymous, holds nothing that identifies you, and there is no way for us to find “your” events in it.
Write to [email protected]. If you think we have handled your data badly, you can complain to your national supervisory authority. Ours is the Czech Úřad pro ochranu osobních údajů (uoou.cz).
10. Changes
If this policy changes materially, the updated version is published here with a new date, and the change is noted in the app’s changelog.