Legal
Privacy Policy
Last updated September 22, 2026
This policy is the canonical description of how Pacific Machines handles information in the desktop application and related websites.
Scope
This Privacy Policy describes how Pacific Machines ("the app", "we", "us"), operated by Reefo, Inc., collects, stores, processes, and shares information when you use the Pacific Machines desktop application and related websites, including pacificmachines.ai.
It is written for technical readers who want file paths, data flows, and implementation detail. Everyday privacy controls are also available in the Privacy dashboard inside the app.
Summary
Pacific Machines is a local-first productivity app. By default:
- Learning evidence is stored on your computer under
~/.jarbas(the on-disk data folder; the product UI is branded Pacific Machines). - Low mode (the default) keeps app, window, and activity context needed to rebuild your day without continuous screenshots, OCR frames, or video.
- High mode (optional) adds screenshots, OCR text, and richer visual saves.
- Sensitive strings in stored capture text can be replaced with labeled placeholders before Agent or analysis reads them.
- Your full capture library (
db.sqliteand frame files) is not uploaded to a remote "Learning store" by default. - Some features intentionally use the cloud: account sign-in (Clerk), Brain document sync and shared team reports (Convex), and LLM inference when you use Chat or Agent.
Audio is not captured. Meeting transcription is not part of the product today.
Screen capture pipeline
Learning modes
When Learning is enabled and the required operating-system permissions are granted, Pacific Machines runs a local capture engine on your machine. Settings exposes two modes:
| Mode | What is recorded | Default |
|---|---|---|
| Low | App, window, and activity signals (for example clicks, typing pauses, app switches, window focus, scroll, clipboard) stored as structured evidence in local SQLite — enough to reconstruct a day without continuous screenshots or OCR frames | Yes |
| High | Low-mode signals plus periodic screenshots, OCR on those frames, and richer visual/accessibility saves under ~/.jarbas/data/ | No — opt in |
What is not recorded
- Microphone audio or system audio.
- Keystrokes outside of text visible on screen (or text Pacific Machines is configured to capture as UI activity).
- Content from apps or browser tabs on your ignore list while they are in focus.
- Continuous video. Older installs may still have a
~/.jarbas/videos/folder from a prior MP4-based mode; new captures do not write session MP4s.
Capture loop
- Permission check — macOS Screen Recording (or the Windows equivalent) must be granted for Learning. On macOS, Accessibility may also be requested for UI context; Input Monitoring may be requested so Learning notices activity.
- Evidence write — Activity events and metadata are written to
~/.jarbas/db.sqlite. In High mode, screenshot files are also written under~/.jarbas/data/. - OCR (High mode) — When High mode is on, text is extracted from screenshot frames and stored in SQLite tables used by Learning, Brain updates, Opportunities, Reports, and Agent.
- Ignore filters — If the focused desktop app matches an ignored app name, or the active URL matches an ignored domain, capture is skipped for that interval. Desktop rules are app-name scoped; URL rules stay URL-only. Filters are stored in
~/.jarbas/capture-filters.json. Saving an ignore list applies going forward and does not delete past captures.
Local storage layout
All paths below are relative to your home directory unless noted. The product name in the UI is Pacific Machines; the on-disk root remains ~/.jarbas.
Core capture data
| Path | Contents |
|---|---|
~/.jarbas/db.sqlite | Local SQLite database: activity evidence, frame metadata, and OCR text when High mode saved it |
~/.jarbas/data/ | Screenshot files referenced by the database (primarily when High mode persists screenshots) |
~/.jarbas/capture-filters.json | Ignored desktop app names and URL domains |
~/.jarbas/redaction.json | Cleanup run history, enabled category tags, auto-cleanup preference |
Brain and analysis
| Path | Contents |
|---|---|
~/.jarbas/brain/ | Personal Brain Markdown (identity, company, workflows, memory, and related notes) |
~/.jarbas/brain/daily-recaps/ | Daily recap Markdown committed by Update Brain |
~/.jarbas/brain/workflows/ | Workflow notes used by Find Opportunities |
~/.jarbas/schedules/ | Local schedule definitions (including the built-in Update Brain schedule) |
~/.jarbas/analysis-runs/ | Background analysis job output |
~/.jarbas/conversations/ | Ask / Chat conversation state |
~/.jarbas/ask-context/ | Ephemeral context assembled for Chat |
Agent runtime
| Path | Contents |
|---|---|
~/.jarbas/pi-agent/ | Bundled Node agent runtime |
~/.jarbas/pi-config/ | MCP config, bundled skills, settings |
~/.jarbas/pi-sessions/ | Agent session files |
~/.jarbas/skills/ | User-created agent skills |
~/.jarbas/bin/ | Helper binaries the app installs for local agent work (for example sqlite3) |
Integrations
| Path | Contents |
|---|---|
~/.jarbas/composio/ | Cached Composio API key for connected plugins |
Legacy folders
Older installs may still have root-level daily-recaps/, weekly-recaps/, monthly-recaps/, yearly-recaps/, workflows/, or videos/. Newer builds prefer brain/ for recaps and workflows, and do not write session MP4s. Shared HTML reports are cloud-only for the organization and are not kept as a local reports/ tree by default.
Nothing in this table is encrypted at rest by Pacific Machines. Protection relies on your OS user account and disk encryption.
Text cleanup engine
Implementation
Sensitive text cleanup runs locally on your machine. It operates on stored capture text in ~/.jarbas/db.sqlite (including OCR text when High mode saved it).
Matches are found with regular expressions, then replaced with bracketed placeholders such as [EMAIL], [OPENAI_KEY], or [SSN]. Screenshot image files are not modified; only stored text changes. In Low mode there is typically little or no OCR text to scrub unless High mode was used earlier.
When cleanup runs
- Automatic (default): When you end a recording session, if auto-cleanup is enabled.
- Manual: From Privacy → Text cleanup → Clean stored data. You choose a date range and severity tier, preview matches, then apply.
- Preview: The Privacy dashboard demo can preview redaction locally without writing to the database.
What gets logged
Each cleanup pass appends a summary to ~/.jarbas/redaction.json: start/end dates, duration, row counts, and per-category match totals. History is visible under Privacy → Cleanup history.
Database interaction
Cleanup scans stored capture text for the selected calendar range, applies enabled category patterns, and updates matching rows in place. A dry-run preview counts matches without writing.
Detection categories
Categories are grouped into three severity tiers. The default tier is Secrets (fewest false positives).
Secrets tier (default)
Passwords, private keys, connection strings, JWTs, and vendor API keys (OpenAI, Anthropic, Stripe, AWS, GitHub, Slack, and others).
PII tier
Secrets tier plus emails, phone numbers, credit card numbers, SSNs, IBANs, and IP addresses.
Aggressive tier
All defined patterns, including broad API_KEY, AUTH_TOKEN, and ENV_SECRET heuristics that may match non-secret strings.
Pattern types
| Group | Examples |
|---|---|
| Identity | Email addresses, phone numbers, SSNs, IBANs, IP addresses |
| Financial | Credit card numbers |
| Passwords | Literal passwords, masked dots, password field context |
| Credentials | Private keys, JWTs, connection strings, seed phrases, backup codes |
| Vendor keys | Provider-specific token formats (Stripe, Anthropic, OpenAI, etc.) |
| Broad | Generic API key and env-var patterns |
Password context matching also looks for labels like password:, passcode:, or pin: followed by a value on the same line.
Agent and LLM processing
Local reads
Agent, Opportunities, Chat, and Update Brain may read ~/.jarbas/db.sqlite, ~/.jarbas/brain/, and related local folders on your machine. Team Dashboard and organization report surfaces use synced Brain / recap projections for the organization; they do not query another person's local capture database. These features do not require you to paste LLM API keys into Settings; the app supplies model access.
What leaves your device
When you send a Chat message or run an Agent task, relevant context (which may include cleaned or uncleaned capture text, depending on your cleanup settings and timing) is sent to the configured LLM provider for inference. That provider processes the prompt under its own terms.
Asking Chat about your day does not pause Learning; capture keeps running while Chat looks up history.
We do not upload your entire ~/.jarbas folder as part of normal Agent operation. Context is assembled per request.
Plugins (Composio)
If you connect a plugin, Pacific Machines may call that service on your behalf for tasks you approve (for example sending email). Plugin credentials are managed through Composio. A cached project API key may be stored at ~/.jarbas/composio/api_key.
Computer use
Optional desktop control (clicking and typing in other apps) uses separate macOS TCC permissions from capture. On Windows and Linux, separate accessibility toggles are generally not required for desktop automation.
Cloud services
Authentication (Clerk)
Sign-in ties this install to your Pacific Machines account and organization. Clerk receives identity information needed for authentication and organization membership. It does not receive your capture database.
Brain sync and shared team reports (Convex)
When you are signed in, Brain Markdown documents (for example daily recaps, workflows, and related notes) can sync to Convex so organization features and teammates with access can use them. That sync is not your raw capture library: it does not upload db.sqlite or screenshot frame files.
When you generate a report for your organization, the finished report document is stored in Convex so teammates with access can open it. This upload is limited to the report you chose to create.
Billing
Subscription and seat management may use Clerk Billing. Payment details are handled by the payment processor, not stored in ~/.jarbas.
Website and analytics
The pacificmachines.ai website may collect contact information you submit (for example waitlist or booking requests) and may send product analytics events to help improve the product. Analytics payloads are designed not to include raw screen content.
What we do not do by default
- Mirror your capture library (
db.sqlite/ frames) to a remote Learning datastore. - Stream live screen video to the cloud.
- Capture or transcribe microphone audio.
Operating system permissions
Pacific Machines requests the minimum OS permissions needed for each feature.
| Permission | Purpose | Required for |
|---|---|---|
| Screen Recording | Learning / capture (including Low mode activity observation gated by OS screen privacy) | Learning |
| Accessibility (macOS) | Read focused app and UI context | Capture on macOS |
| Input Monitoring (macOS) | Notice clicks and typing so Learning knows when work is happening | Capture on macOS |
| Notifications | Alert when reports or opportunities finish | Optional convenience |
| Accessibility + Screen (macOS) | Desktop control helper | Computer use in Chat |
You can revoke permissions in system settings at any time. Without screen recording, Learning capture stops. Pacific Machines cannot override OS privacy controls.
On macOS, open System Settings → Privacy & Security. On Windows, open Settings → Privacy & security.
Your controls
In the app
- Pause capture: Turn Learning off or revoke screen recording permission.
- Learning mode: Choose Low (default, no continuous screenshots/OCR) or High (screenshots + OCR) in Settings.
- Ignore lists: Add desktop apps or URL domains to skip while in focus. Saving the list applies going forward and does not delete past captures.
- Text cleanup: Choose severity tier, preview, and scrub a date range. Enable or disable automatic cleanup when a recording ends.
- Delete local data: Settings → Storage. Delete a date range or reset all local Pacific Machines data on this computer (
~/.jarbas). - Disconnect plugins: Remove Composio connections you no longer want.
What local deletion does not remove
Brain documents and shared team reports already stored in Convex for your organization. Those must be managed from Team / organization surfaces by someone with access.
Export
The Privacy dashboard and this policy are available in-app and on this website. There is no separate "download my cloud data" flow for the raw capture library because that library is not stored in the cloud by default.
Retention and deletion
Local capture data
You control retention. Data remains on disk until you delete it or uninstall and remove ~/.jarbas.
There is no server-side retention schedule for the raw capture library because captures are not mirrored remotely by default.
Cleanup vs deletion
- Cleanup replaces sensitive substrings in stored capture text. Images remain when they exist.
- Date-range delete removes captures for selected days from local storage.
- Full reset wipes local Pacific Machines state on this machine (database, frames, Brain files, analysis, Agent config).
Cloud artifacts
Synced Brain documents and team reports in Convex persist until deleted by an authorized user. Account records in Clerk persist according to your organization's account lifecycle.
Backups
If you use Time Machine, File History, or another backup tool, deleted local data may remain in backups until those backups rotate.
Known limitations
Regex-only detection
Cleanup uses pattern matching, not semantic understanding. It can miss sensitive data that does not match a rule, and aggressive tiers can false-positive on innocent text.
Images retain visual content
Cleanup edits stored text in SQLite. When High mode (or an older High-mode session) saved screenshots, pixel data in those files may still show sensitive information until frames are deleted.
Timing
If you use Agent or Chat before cleanup runs, prompts may include uncleaned text from recent captures. Enable automatic cleanup on recording stop to reduce this window.
No audio
Pacific Machines does not record meetings or microphone input. Spoken sensitive information is not captured unless it appears as on-screen text or other captured UI text.
Enterprise controls
Organizations processing regulated data (including PHI/ePHI) are responsible for additional controls they provide — for example disk encryption, MDM, DLP, access governance, and contractual safeguards. Contact us for business-associate arrangements when applicable.
Policy updates
We may update this policy when capture, cleanup, or cloud behavior changes. The Last updated date at the top reflects the current version.
Material changes to what leaves your device will be reflected here and, where appropriate, in onboarding or in-app notices.
Contact: hans@pacificmachines.ai