01
Scope and the core boundary
This policy applies to the Grasses macOS application provided by Brain Beats ("Grasses") and its official product page. Grasses is an English reading utility that uses AI service credentials supplied by you.
Brain Beats does not operate a relay server that receives your reading content. The app connects from your Mac directly to the AI Provider or Base URL selected in Settings. Grasses Pro activation separately connects to the Brain Beats License service, but reading content never enters that service. We do not sell personal information or use app data for advertising, cross-app tracking, or user profiling.
02
Data Grasses processes
The following reflects how the current version handles each data category, including where it is processed and whether it leaves your device.
Reading text
Text you actively read from a selection or the clipboard, plus OCR-recognized blocks you choose to analyze. It is used for word and phrase analysis, translation, and grammar analysis.
Destination: Sent to your configured AI service. Grasses does not store a copy on a developer-operated server.
Screenshots and clipboard images
A screen region you manually capture or an image you actively read from the clipboard. Images are used on-device for Vision OCR, coordinates, and clickable text blocks.
Destination: The image itself is not included in AI requests and is not uploaded by Grasses. A selected screen capture is briefly written as a PNG in the macOS temporary directory, and Grasses attempts to delete it immediately after loading. Grasses does not write clipboard images to persistent files.
AI results
Lexical analysis, translations, and grammar analysis returned by your provider. Results appear in the result window and current reading session.
Destination: Kept only in current-session memory by default. After the first completed result, Grasses explicitly asks whether to enable local reading history. Only after consent are the original text and completed display result stored in local app data. Screenshots, API keys, transient stream state, errors, and Provider configuration are excluded from history, and full responses are not written to logs.
System speech
When you press the pronunciation button, Grasses passes the current word or phrase to macOS system speech synthesis.
Destination: Speech is produced on-device. The speech action itself sends no additional request to your AI Provider.
API keys
Credentials you provide for each AI Provider. They are stored in the macOS Keychain with this-device-only accessibility.
Destination: Sent only to the matching API endpoint as an Authorization header. Brain Beats does not receive the credential.
License activation data
The sale License you actively submit, plus a GDF1 device fingerprint that Grasses derives on-device from IOPlatformUUID using an app-specific context and SHA-256. Grasses does not send the original IOPlatformUUID.
Destination: The full License is used only for the current activation request and is not written to the License database. The License service stores License registry fields and status, and stores up to two device slots per License; each slot contains the device fingerprint and first and most recent activation times. The Activation Token contains no name, email address, or original hardware identifier, but includes a GDB1 device-binding value for offline validation on this Mac and stays only in the local macOS Keychain.
Pro Trial status
Grasses stores the trial campaign version, credit limit, successfully used feature types, random use IDs, and local timestamps in macOS Keychain on the current Mac. The record contains no reading text, screenshots, OCR text, or AI responses.
Destination: Trial status stays on-device, is not uploaded by Grasses, and is not sent to the License service or an AI Provider. The 20 credits unlock Pro feature uses, not AI tokens; AI requests still use your own API key.
App settings
Provider, Base URL, model, text limit, language, theme, grammar colors, window position, and launch-at-login preferences.
Destination: Stored locally using macOS UserDefaults and not uploaded to a Grasses server.
Local diagnostic logs
Operational details such as timestamps, action type, character count, provider host, model, request status, duration, and error category.
Destination: App-managed log files are stored in ~/Library/Application Support/Grasses/Logs. If a file write fails, Grasses writes a file-write failure notice without reading content to the macOS unified log. Logs exclude API keys, screenshots, full selected or OCR text, and full AI responses, and are not uploaded automatically by Grasses.
03
Service providers and third-party processing
Grasses currently includes default configurations for SiliconFlow, DeepSeek, Zhipu, Kimi, Mimo, and Qwen, and lets you edit the Base URL. An AI request contains the relevant reading text, analysis instructions, selected model, required request parameters, and API key authentication.
Your AI Provider or custom endpoint processes requests under its own terms. It may log request content, IP address, usage, or account information and may process data in other jurisdictions. Brain Beats does not control its retention, training use, deletion, or security practices. Before submitting sensitive content, review the selected service's privacy policy and account settings.
The License service runs on Cloudflare Workers and D1. Cloudflare may process IP addresses and standard request metadata for delivery, security, and operations. Sale Licenses are not sent to AI Providers. Grasses does not collect an activation email address or send activation mail.
Connection boundary
Default API endpoints use HTTPS. Because the Base URL is editable, configure only a trusted HTTPS endpoint. You and the endpoint operator are responsible for the transport security and data handling of a custom endpoint.
04
macOS system permissions
- Accessibility
- Used to simulate Copy after you trigger Read Selection. Grasses snapshots the clipboard, reads the newly copied text, and restores the previous clipboard contents.
- Screen Recording
- Lets macOS provide the screen region you manually capture after triggering Read Image. Grasses does not continuously record or scan the screen in the background.
- Launch at Login
- Uses the macOS login-item mechanism only when you enable it. This does not cause additional data collection.
macOS controls these permissions. You can revoke them in System Settings at any time. The related feature will stop working, while other Grasses features remain available.
05
Retention and deletion
- Reading content and AI results: Before you consent to reading history, they remain only in current-session memory. After you enable it, original text and completed display results are stored in
~/Library/Application Support/Grasses/History. Grasses automatically keeps at most 500 non-favorite entries; favorites are not automatically pruned. Turning history off stops new writes without deleting existing entries. Privacy Settings can permanently delete all history. Viewing a cached result does not contact an AI Provider or consume a Pro Trial credit.
- Screenshots and clipboard images: A selected screen capture briefly exists in the macOS temporary directory, and Grasses attempts to delete it immediately after loading completes or capture fails. Images and clipboard images are kept only for the current processing flow, with no image history.
- Diagnostic logs: An app-managed file rotates at 5 MB, with at most five files. Delete the Logs folder above to remove them immediately. macOS retains and manages the fallback failure notice produced when a file write fails.
- App settings: Remain locally until you restore defaults or remove the corresponding app data.
- API keys: Remain in macOS Keychain. Restore Defaults does not delete Keychain credentials, and uninstalling the app may leave them behind. Use Keychain Access to delete items with the service name
pro.brainbeats.Grasses.credentials.
- Activation Token: Remains only in the local macOS Keychain. Restore Defaults does not delete the item, and uninstalling the app may leave it behind. Use Keychain Access to delete the item with service name
pro.brainbeats.Grasses.license.
- Pro Trial status: Remains only in macOS Keychain on the current Mac. Restore Defaults does not delete trial status, and uninstalling the app may leave it behind. You can use macOS Keychain Access to manage or delete Grasses' local trial record.
- License service data: License registry fields, status, up to two device fingerprints, and their first and most recent activation times support activation validation, enforce the device limit, and prevent a revoked or refunded License from activating again. This data remains with the License registry record. Contact support for device-slot or deletion requests. Cloudflare retains infrastructure data under its policy.
- AI Provider data: Retained under the selected Provider's or custom endpoint's policy. Direct access, correction, or deletion requests to that service.
06
Official product page
The Grasses product page is a static website with no accounts, forms, advertising, or product analytics. It stores only your language preference in your browser until you change it or clear this site's browser data. You can remove it through your browser's site-data settings.
Like ordinary websites, hosting and content-delivery infrastructure may process standard access logs such as IP address, User-Agent, requested URL, and timestamp for delivery, security, and troubleshooting. Brain Beats does not use this information to build user profiles. Log retention and deletion follow the infrastructure provider's policy.
07
Security measures and your choices
Grasses stores API keys in macOS Keychain and accesses AI services through an ephemeral network session with no disk URL cache. No network or local storage method can guarantee absolute security. Avoid analyzing content that should not be sent to your selected Provider.
You can choose not to configure an AI service, limit the text length sent in each request, change Providers, leave reading history off or disable it, delete all reading history, revoke system permissions, delete local logs and Keychain credentials, or stop using Grasses. Grasses requires no account, so Brain Beats holds no Grasses account profile for deletion.
Children's privacy
Grasses is a general-purpose reading utility and is not directed to children under 13. We do not knowingly collect children's personal information. Guardians should use the selected AI Provider's age requirements and privacy terms when deciding whether a child may use that service.