Privacy policy

Last updated: July 26, 2026

The short version: Mushroom is built to keep your data on your Mac. There is no Mushroom account, no analytics, and no tracking. Your chats with the pet run on-device through Apple Intelligence and are never sent to us or anyone else.

There are two exceptions, and you have to switch each on yourself. The first is file sharing. If you turn it on in Settings, Sharing, then a file you deliberately drop on your mushroom is uploaded to our temporary storage, shared through an unguessable link, and deleted after 24 hours. See section 2.8.

The second is messaging your friends. If you turn it on in Settings, Friends, then messages you send are locked on your Mac before they leave and can only be opened by you and the friend you sent them to. They pass through a server of ours, which stores them without being able to read them, and deletes them after 30 days. We never see the text of a message, and the name you give a friend never leaves your Mac. See section 2.9.

If you switch on iCloud sync, some of your data is copied to your own private iCloud so your Macs can stay in step. It goes to Apple, under your Apple Account, never to us. Sync is off until you turn it on. See section 2.7.

A few optional features do reach the internet, because they have to: weather, the news digest, tool plugins you install, the license check, the update feed, and file sharing and messaging if you switch them on. Each is listed below, and none of them sends your chats, reminders, or habit data anywhere.

1. Who is responsible

The controller under the EU General Data Protection Regulation (GDPR) is Alexander Slatina. Contact details and postal address are in the imprint. E-mail: hello@getmushroom.app.

2. The Mushroom app

2.1 Data that stays on your Mac

Everything the app knows about you is stored locally on your Mac in a single database file: reminders, habit logs, chat history, notepad content, pet state, and settings. This data is never transmitted to us, and no file on your Mac is either, unless you switch on file sharing and drop one on the pet yourself (section 2.8). You can export, import, or delete your data at any time in Settings.

Chat and natural-language reminders are processed by Apple's on-device foundation models (Apple Intelligence). Conversations are processed entirely on your Mac and are not sent to us or to Apple's servers by the app.

2.2 Weather, sunrise and sunset

If you ask the pet about the weather, the app looks the place up with Apple's MapKit service and requests a forecast for those coordinates from Apple's WeatherKit. The request contains the coordinates and your IP address. No name, account, or identifier is sent. See Apple Weather attribution.

When you do not name a place, the app uses whichever of these you set up. Neither exists until you create it:

The sunrise and sunset notification is off by default and uses the same location and the same WeatherKit request. Without one of the two sources above it does nothing.

2.2a Daily quote

The daily quote is off until you turn it on. When it is on, the app requests the quote of the day from ZenQuotes (zenquotes.io) once a day. The request contains your IP address and nothing else: no name, account, identifier, or anything about you. The quote is shown exactly as received. See ZenQuotes.

2.3 News digest

The daily news digest is off until you turn it on. When it is on, the app fetches the RSS or Atom feeds you listed in Settings, News, directly from those publishers (the starting suggestions are Kagi News, NPR, and Al Jazeera, and you can remove or replace all of them). Each publisher receives what any feed reader sends: your IP address and the request for the feed file. Nothing about you, your reminders, or your chats is included, and the feed list stays on your Mac. Headlines are read straight from the feed and are never sent to any model or to us.

2.4 Tool plugins

You can add optional tool plugins (small JSON files) that let the pet call web services you choose, for example a public facts API. These requests go directly from your Mac to the endpoint configured in the plugin file. Which services are contacted, and what they receive, is defined entirely by the plugins you install and enable.

2.5 Licensing and updates

The update check belongs to the version downloaded from this site. The Mac App Store version does not make it, because updates arrive through the App Store, and it does not check a licence with Gumroad either, because the App Store purchase is itself the licence.

One exception, on both versions. Friends and file sharing come as a membership, and a membership bought on this site can be added to the Mac App Store version too. If you add a membership key there, that key is sent to Gumroad the same way and on the same schedule as above, so it can be checked. If you never add one, nothing is ever sent to Gumroad from the Mac App Store version. A membership bought inside the app is handled by Apple, and nothing about it goes to Gumroad.

Legal basis for these requests: Art. 6(1)(b) GDPR (performance of the license agreement) and Art. 6(1)(f) GDPR (our legitimate interest in providing updates).

2.6 Features that never leave your Mac

Calendar awareness and appointment reminders read events already on your Mac through Apple's EventKit, after you switch them on and grant access. Access is read only, Mushroom never writes to a calendar, and event titles are never sent to the model or to us. Emergency contacts, the notepad, read aloud, stats, and streaks are entirely local as well. Backups are a copy of the local database written to a folder you pick; if that folder happens to sit in iCloud Drive or a similar service, that service moves the file under its own terms. Backups are separate from iCloud sync (section 2.7) and are unaffected by whether sync is on.

Three optional settings let Mushroom notice something about your surroundings, and all three are off until you switch them on, ask for no permission at all, and send nothing anywhere. "Quiet during calls" asks macOS whether your microphone is currently running, so that nudges can wait; it never opens the microphone, never receives any audio, and cannot tell what is being said or by whom. The dark room nudge reads the ambient light sensor that laptops have and desktops do not, and only to know whether the room has gone dark; it exists only in the version downloaded from this site. The check-in that asks how you are doing keeps your answer on your Mac, where it is counted in Stats and nowhere else.

2.7 iCloud sync (optional, off by default)

Mushroom can keep several of your own Macs in step using Apple's CloudKit. This feature is switched off until you turn it on in Settings under Data, and while it is off nothing at all is sent.

When it is on, the following are copied into the private database of your own iCloud account: your reminders, your emergency and video contacts, your notepad, the settings that are not specific to one Mac, and the content of any optional features you have switched on.

These stay on each Mac and are never synced: your chat history, your stats and streaks, your reminder history, your licence, and anything tied to one machine such as the pet's position and size or your keyboard shortcuts.

We are not a party to this transfer. The data goes to Apple as part of the iCloud service you already use, is stored in the private area of your account, and we have no access to it and no ability to read it. Apple processes it under Apple's Privacy Policy and your iCloud terms. Apple Inc. is a US company; transfers rely on the EU-US Data Privacy Framework and/or EU standard contractual clauses.

Turning sync off in Settings stops any further data leaving your Mac immediately. Copies already in your iCloud are left alone, because your other Macs may still be using them; you can remove them yourself by deleting the app's data in your iCloud settings, or by deleting the records in iCloud. Deleting a reminder, contact or note in Mushroom removes it from your other Macs as well.

2.8 Temporary file sharing (optional, off by default)

This is the only part of Mushroom that puts a file of yours on a server of ours. It is switched off until you turn it on in Settings under Sharing, and while it is off nothing is uploaded and no account is created for you anywhere.

When it is on, dropping a file on your mushroom uploads that file, and only that file, to storage we run on Cloudflare R2. The file is kept in Western Europe. So that uploads are quick wherever in the world you are, Cloudflare may first write it at a location closer to you and copy it across a moment later, and that first location can be outside the EU (see section 4). You get back a link with an unguessable address.

We cannot read the files you share. Since version 1.39.0 your Mac encrypts each file before it is uploaded, and the key is put in the part of the link after the # sign. Browsers never send that part to the server, so the key does not reach us even in a log, and what we hold is a file we have no way to open. When your recipient opens the link, the page we serve them decrypts the file in their own browser. This does mean anyone who has the whole link can open the file, and there is no password on top of it. Treat the link like the file itself and only send it to people you mean to send it to. It also means we cannot inspect a file that is reported to us (section 2.10): we act on the report by deleting the file, not by looking at it.

What is stored while a file is live: the encrypted file, its name, its size, its file type, the time it went up and the time it expires, an identifier for the Mac that uploaded it, a one-way hash of your licence key, and the Gumroad sale number of the purchase. The name and the type are not encrypted, because your other Macs list them for you; the contents are. We never store your licence key itself, only a hash of it. The sale number is kept so that a file reported as harmful can be traced to the purchase behind it, which a hash alone cannot do.

How long: the file stops being downloadable exactly 24 hours after it goes up, and is normally erased from storage within the hour after that. A storage lifecycle rule removes anything still present as a backstop. The bookkeeping record survives up to 7 days longer, with the filename erased, purely so an old link can say "this expired" rather than nothing at all. You can delete any file sooner, from any of your Macs, in the Shared Files window; that removes it straight away and the link stops working.

Because the feature is tied to your licence rather than to one machine, every Mac using the same licence can see the names of, and delete, the files shared under it.

Legal basis: Art. 6(1)(b) GDPR, performing a feature you asked for by switching it on and by dropping a specific file. Cloudflare, Inc. acts as our processor for this storage. Turning the feature off stops any further uploads; files already shared run out their own 24 hours unless you delete them.

Unless you run the server yourself. In both versions, Settings under Data lets you point file sharing and messaging at servers your own organisation runs, which is how a company keeps this data on hardware it controls. You have to type both addresses and confirm the change. While that is set, this section and the next describe your servers rather than ours: nothing in either feature reaches us, we are not the processor, and the server software is open source so you can read exactly what it does before you run it: github.com/qubit999/mushroom-selfhost. It can run in your own cloud account or on hardware you own.

2.9 Messaging your friends (optional, off by default)

This is the only part of Mushroom that carries a message of yours to another person. It is switched off until you turn it on in Settings under Friends, and while it is off no identity is created, nothing connects, and no notifications are requested.

When you turn it on, your Mac creates a messaging identity for itself: a private key that is stored in this Mac's keychain and never leaves it, and a matching public key that our server holds so friends can encrypt to you. Adding a friend works by an invite code you send them yourself, through whatever you already use. There are no usernames, no directory, and no contact discovery: we never read your address book, and nobody can find you without a code you handed them.

We cannot read your messages. Each message is encrypted on your Mac with a key derived from your key and your friend's, using Apple's CryptoKit. Our server receives and stores only the encrypted form. This is end to end encryption, but it does not offer forward secrecy: if the private key on your Mac were taken, messages that Mac already received could be read.

There is a second limit to that promise and it deserves saying plainly, because it is about us rather than about your Mac: our server is also what hands your friend's public key to your Mac. A server that gave each of you a key it held the private half of could read everything you sent, and nothing on either Mac would look wrong. So Friends shows a safety number for every person, in the panel behind the name at the top of a conversation. Read it out to them some other way, on a call or in person. If it is the same on both Macs, nobody is in the middle. Mushroom also checks that the key it is handed for someone really belongs to them, because a person's identity on the server is a hash of their own public key, so once you have a friend their key cannot quietly be swapped for anybody else's. The safety number is what covers the moment you add them, which is the one moment that check cannot.

What is stored on our server while a message is undelivered: the encrypted message, the identities of the sender and recipient, the time it was sent, and its size. What is not stored: the text of the message, the name you gave your friend (that stays on your Mac), your address book, and your license key, of which we keep only a one-way hash.

Separately from any message, our server holds your friend list for as long as each friendship lasts: for every friend, their identity, their public key, whether you have blocked them, and the date you added them. It does not expire on its own, because it is what lets a friend reach you at all. Removing a friend, or deleting the conversation, deletes their entry with it.

How long: a message is deleted from our server 30 days after it arrives, or sooner once you delete the conversation, which removes it from the server as well as from your Mac. The copy on your own Mac is yours and stays until you delete it.

If you switch on "Show when I'm online", our server also knows when your Mac is connected and passes typing indicators between you and your friends. This setting is symmetric: with it off you neither share your status nor see anyone else's. It governs what is sent and shown, not what is noted: when a friend who shares their status connects, the time is recorded next to their entry in your friend list either way, so that switching the setting on has something to show straight away. Whether it is on or off, our server can see that one identity sent something to another, and when. It cannot see what.

Notifications: if a message arrives while Mushroom is closed, we ask Apple's Push Notification service to wake your Mac. That notification contains no message text and no names, only a generic alert that your Mac itself turns into readable words. Apple therefore never receives the content of a message either. Your Mac's notification token is stored so we can reach it, and is removed when Apple tells us it is no longer valid.

Blocking someone stops them sending you anything further and is applied on our server as well as on your Mac. Your messaging identity is per Mac and is not synced anywhere, so replacing your Mac means exchanging invite codes again.

Legal basis: Art. 6(1)(b) GDPR, performing a feature you asked for by switching it on and by sending a specific message. Cloudflare, Inc. acts as our processor for this relay, and Apple Inc. for the notification delivery described above. Turning the feature off closes the connection and stops notifications; messages already on the server run out their own 30 days unless you delete the conversation.

2.10 Reporting a shared file

Anyone who receives a Mushroom share link can report it at getmushroom.app/report. The form is protected by Cloudflare Turnstile, which checks that a person and not a script is submitting it and sets no cookie.

A report stores the link, the reason chosen, anything written in the details box, and the reporter's name and email. The name and email are used only to come back to the reporter about that report, and they are deleted 30 days after the report arrives. The rest of the report is deleted after 180 days. The report is emailed to us at the moment it is made.

The form gives the same answer whether or not the link is real, so it cannot be used to find out whether a given link exists. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in keeping the file sharing feature from being used to distribute harmful or unlawful material, and in some cases Art. 6(1)(c) where the law requires us to act.

3. This website

getmushroom.app is a static site hosted on Cloudflare (Cloudflare, Inc., USA). When you visit, Cloudflare processes the technical data needed to deliver the page, such as your IP address and browser information (server logs). Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in serving the site securely. The site sets no cookies.

For visitor statistics we use Cloudflare Web Analytics. It is cookieless: it stores nothing on your device, does not fingerprint you, and does not track you across sites. We only see aggregate numbers (page views, referrers, country). Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in understanding how the site is used.

When you use a download button, a short notification e-mail is sent to us so we know how often the app is being downloaded. It contains the time, the country and city Cloudflare works out from your connection, the page you came from, and your browser's user agent string. It does not contain your IP address, it is not joined up with anything else, and the download itself works exactly the same whether or not that e-mail succeeds. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in knowing how many people download Mushroom.

Purchases happen on Gumroad's site under Gumroad's privacy policy.

The tool submission form is protected by Cloudflare Turnstile. When you use the form, Cloudflare processes technical data (your IP address and browser signals) solely to tell people from bots. Turnstile does not track you across sites and is not used for advertising. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in preventing spam and abuse.

Tool plugin files you submit through the form are stored privately on Cloudflare R2 and read only by us, to review the tool by hand before we decide whether to publish it. Please do not put personal data or API keys into a submitted file; a plugin file never needs either. To have a submission deleted, write to hello@getmushroom.app. Legal basis: Art. 6(1)(b) and (f) GDPR. For data transfers see section 4.

4. Data transfers outside the EU

Cloudflare, Gumroad, Apple, and ZenQuotes are US companies. Transfers rely on the EU-US Data Privacy Framework and/or EU standard contractual clauses.

5. E-mail contact

If you write to hello@getmushroom.app, we use your e-mail address and message only to answer you (Art. 6(1)(b) and (f) GDPR) and keep the correspondence no longer than needed.

6. Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21). You can also complain to a data protection supervisory authority. Note that for everything stored by the app itself, you are in direct control: the data is on your Mac and can be exported or deleted in Settings.

7. Changes

We will update this policy when the app or website changes in a way that affects your data. The current version is always at getmushroom.app/privacy.