Your files never leave your Mac.
Written against how Lyndran is actually built, not copied from a template. Where something is unfinished, it says so.
- Your files are never uploaded to us. Reading them — the text out of a PDF, a Word file, a spreadsheet, and a scan read with your eyes’ worth of accuracy — happens on your own machine, in the app itself. When you ask a question about what was read, the part it has to think about goes to the model for that one thought, and the app says so as it happens, with a count of the words going. Exactly how much, and when, is below.
- Lyndran can only see six folders, plus any you add yourself. Documents, Downloads, Desktop, Pictures, Music, Movies — and folders you choose in Settings, by hand, up to twenty. Your home folder itself is excluded, on purpose, and no task can add a place.
- We keep no history of your tasks on our servers. Your tools, your results and your history live in a folder on your Mac that you can open in Finder. The three small exceptions, all things you switch on yourself, are named below.
- No advertising, no analytics SDKs, no third-party trackers, no cookies on this site or in the app. We do not sell or share anything about you, ever.
- “Forget everything about me” is one press, and it means it.
What stays on your Mac
Lyndran is a native macOS app. It is not a website wearing a window, and it is not a thin client for a server that does the real work. The work happens here.
Everything the product accumulates about you is stored in ordinary files on your own disk, inside the app’s support directory, and you can open it in Finder:
- The tools you build, which are the saved shape of a task that worked.
- The results of past tasks — the tables, ledgers and drafts Lyndran hands back.
- Your reminders and schedules, in a plain JSON store.
- Your preferences, including which tasks you have granted a standing “always allow.”
- A short digest of recent turns so follow-up questions like “open the third one” resolve. See below for what is in it — it is smaller than you would expect.
None of this is synchronised to us. There is no account you can log into on a website to read your Lyndran history, because that history does not exist anywhere but your machine.
What leaves your Mac, and exactly when
Lyndran needs a language model to plan a task. That is the one moment anything travels, and it travels for the length of one request.
The reply is a plan: a short list of steps in a fixed format. Your Mac then runs those steps locally. Finding your files, reading the text out of a PDF, reading a scan, searching inside documents, taking the screenshot, doing the tidying — all of it happens on your machine.
Reading is the app’s own work in one more place than it used to be. A Word file, a spreadsheet or a LibreOffice document was until recently handed to macOS’s Spotlight importer, a system service, which read it and passed the text back. Lyndran now parses those bytes itself, inside its own process. Opening a document to read it involves no other program and no network at all.
We want to be exact about the last row of that table, because the older version of this page was not. “Find the invoice they sent in March and open it” sends nothing out of the invoice. “What are the payment terms on this contract?” has to send the part of the contract that answers it — there is no way to answer a question about a document without reading the document, and the reading has to reach whatever is doing the thinking. What is capped is how much, and how many things at once. Reading and searching a document are now local from end to end, which makes that exception sharper rather than softer: the only words of yours that travel are the ones answering a question you asked, and you now watch them being counted as they go.
If you switch on “Work step by step”, more of what Lyndran reads goes to the model, and it tells you each time. It is off unless you turn it on, in Settings. With it on, Lyndran looks at each result before choosing its next step, which is what makes it better at jobs with surprises. Looking means sending: the start and end of each reading, up to about 6,000 characters of it, goes to the model so it can decide what to do next, where otherwise only the part needed for a question you asked would go. Each time, the app shows how many words are going, at the moment they go. What it reads is still read on your Mac, your files are still never uploaded to us, and nothing it learns from a page, an email or a file can make it act without your press.
The digest limit is deliberate and doubles as a security control. An unbounded label is how someone smuggles instructions into a model through a filename or a page title, so the length cap is enforced in code, not in a prompt. There is more on that on the security page.
What never leaves, under any circumstance
- Your files themselves. No document, image, PDF or spreadsheet is ever uploaded — not to us, and not to the model. Only the passage needed to answer a question you asked about one, within the cap above.
- Anything at all, when the task does not need thinking. Finding, opening, renaming, tidying, converting, extracting, searching inside and reading are local from end to end.
- The contents of web pages it reads on your behalf, beyond the clipped labels described above.
- Screenshots. A screen capture is downscaled and handed to the local step that needs it.
- Text read off a scan. Reading the words out of a photographed or scanned page uses a reader that ships inside macOS and runs on your machine. The image does not go anywhere.
- Your emails, messages, calendar entries or reminders. These are read and written through macOS itself, on your machine.
- Your passwords, keys, keychain or browser profile. A login you save for a site goes into the macOS Keychain; the model only ever sees a name for it, never a value, and the value is substituted in Rust one step before it is typed.
The folder boundary
File access is limited, in Rust, to six roots: Documents, Downloads, Desktop, Pictures, Music and Movies. Your home folder itself is excluded, because it is where .ssh, .aws, browser profiles and keychains live. Paths are resolved to their real location before the check, so a symlink or a ../ cannot be used to walk out of a root.
You can add more places yourself, in Settings, one at a time, through the Mac’s own folder chooser — up to twenty, kept in a file only you can read, and gone the moment you remove one. Nothing else can put a folder on that list: there is no capability, no task and no plan step that adds a place, so the model has no route to widening its own map. Your home folder, anything named as holding credentials, every hidden folder and macOS itself are refused even when you pick them by hand.
There is one way past the map, and it is yours: a file you attach yourself, through the Mac’s own open dialog, can be read wherever it lives for the rest of that conversation. It cannot be written to, moved or renamed, and the permission ends with the conversation.
What Mainspring stores, and why
Mainspring is the company behind Lyndran. On our own servers we hold as little as we can while still being able to run the thing and bill for it honestly.
If you bring your own model key
Lyndran talks to the model provider directly from your Mac. Your asks do not pass through us at all, and we hold nothing but your account record, if you made one.
If you are on a membership
Requests are relayed through our API so that usage can be metered. In that case we record, per request: your account identifier, a timestamp, the model used, the number of tokens in and out, and the resulting cost. This is what a bill is made of.
We do not retain the text of your asks or the plans that came back after the request has been served. We do not build profiles, we do not train models on your data, and we do not sell or rent anything about you to anyone. There is no advertising business here to feed.
Three exceptions, and you turn each of them on
If you send an ask from the web or from your phone for the Mac to pick up later, that sentence has to wait somewhere until the Mac comes for it, and that somewhere is us. It is the sentence you typed, held until it is collected.
If you switch on the mirror that lets your phone see what the Mac is doing, we hold the Mac’s current state and the labels of its recent tasks — what was asked, how it ended — so your phone has something to show you. Not the results, not the files.
If you switch on answering from your phone, the full words of a card waiting on your Mac — what it will do, and to what — are held with us while that card waits, so your phone can show you exactly what you are approving. They go when the card is answered or lapses, and your answer is held only until the Mac collects it. Files never pass through us.
Files between a browser and your Mac go directly too. You link a browser by scanning a code on your Mac’s screen. That code carries a key that stays in the browser and on the Mac and is never sent to us. To start a transfer, the two sides need to find each other, so we pass a short introduction between them: the network addresses each one can be reached at, sealed with that key so the server passing it along can’t alter it. We keep it for at most 90 seconds, then it is gone. To learn its own outside address, each side also asks a public address server run by Google, which sees that address and nothing else. The file itself then goes straight from one to the other, encrypted, and never through us or Google. If the two can’t reach each other directly, nothing is sent, and Lyndran says so. We don’t relay files as a fallback.
An ask that arrives from your phone waits for you to start it, unless you have also switched on letting plain tasks start by themselves. Even then, anything that sends, buys, posts, deletes or touches money stops at a card for your press.
None of these is on unless you turn it on, and each is described where you turn it on rather than only here.
Server logs from our API hold ordinary operational data — IP address, timestamp, path, status code — for a short window, because that is how you find out why something broke. They are not analysed for anything else.
Lyndran on your phone
The phone app is a remote, not a second Lyndran. It plans nothing and reads none of your files, except the ones you pick for your Mac. It sends asks to your Mac, shows what the Mac is doing, lets you answer a card waiting there, stops a task, and moves files between the phone and the Mac.
Signing in. Either with Google, through Firebase Authentication as described below, or by scanning a code shown on your Mac. A code works once and for two minutes. When a phone signs in with a code, we record that device on your account: a random identifier, the name the phone gives itself (usually its make and model, such as “Google Pixel 8”), and when. Removing a device from your account today signs out every session on it, the Mac’s included, and each has to sign in again. We say that plainly because it is blunter than it should be.
Files between your phone and your Mac never pass through us. They go directly over your own Wi-Fi, encrypted, and only when both are on the same network. Your Mac only listens once you add a phone, only answers devices on your own network, and only a phone that scanned the code on its screen. The phone checks it is talking to that Mac by the fingerprint in the code. A file sent from the phone lands in Downloads, in a folder called “From your phone”, marked as downloaded, and Lyndran never opens it. A file sent to the phone waits for your press on the Mac first.
When your Mac asks your phone for something. Lyndran on your Mac can ask the phone for files or photos, for how the phone is doing (battery, free space, model, Android version), or for the text on its clipboard. The phone shows you exactly what would go, and nothing goes unless you press. You choose the files yourself in Android’s own picker; the app cannot look through your phone. What you send goes to your Mac over your Wi-Fi. To answer you, Lyndran on your Mac may then send what it reads to its model, exactly as it does with a file on the Mac.
What the phone keeps. The key that links it to your Mac is kept inside the app and left out of phone backups and device transfers. Uninstalling the app removes it. Forget the phone on your Mac, and the key stops working.
What the phone sends to us is only what the three exceptions above already describe: an ask you typed, the mirror of what your Mac is doing if you turned it on, and your answer to a card if you turned that on. A request to stop a task is also held for two minutes, until the Mac collects it.
This website
The page you are reading right now makes zero requests to any other host. No fonts from Google, no analytics, no tag manager, no embedded video, no A/B tooling, no session recorder. Every asset is served from this domain, and the page’s Content Security Policy forbids anything else.
We set no cookies. The only thing stored in your browser is a single localStorage entry remembering whether you chose light or dark. It never leaves your browser and it is not an identifier. Clearing site data removes it.
The site is hosted on Firebase Hosting, which keeps standard web server logs. The one request this site makes off-page is the waitlist form, described next, and only when you submit it.
The waitlist
If you type your email into the form on this site — the one that says it will tell you when the Windows version lands — we store that address, and the time you sent it, and which page it came from. We use it for exactly one thing: to write to you once, on the day there is something to tell you about.
We will not add you to a newsletter, sell the list, or hand it to an email marketing platform. Every message we send will carry a one-click unsubscribe. If you would rather come off the list now, write to us and we will delete the row — there is nothing else attached to it.
Accounts and sign-in
Signing in uses Firebase Authentication from Google. That means Google, as our processor, handles the credential itself: we receive a stable user identifier and the email address on the account, and we never see or store your password.
Your account record on our side is deliberately thin — an identifier, an email, when it was created, and your membership and carrot balance if you have one. You can use Lyndran without an account by bringing your own model key.
Who else touches it
We use a small number of suppliers, each for one job:
- Anthropic — the language model that plans tasks. It receives the material listed above and nothing else. Requests are sent through the commercial API, which is not used to train models.
- Google Cloud — Firebase Hosting for this website, Firebase Authentication for sign-in, Cloud Run for our API, Firestore for the ledger of accounts and usage, and Secret Manager for our own credentials.
- Google Play services (Android only) — the code scanner runs inside Google Play services on your phone, and Google’s scanner and sign-in libraries send Google their own diagnostics about how they are working. They do not receive your files or your asks.
- Google’s public STUN server (stun.l.google.com) — used only when you move files between a browser and your Mac. It sees the network address of the browser or Mac asking, and nothing else.
An earlier version of this page named Neon, a Postgres host, as the database. That was left over from an earlier plan and was never true of what shipped; the store is Firestore. We are correcting it here rather than quietly.
These are processors acting on our instructions. We do not have any other integrations, and we do not add one quietly — this list is part of the page and changes when the list changes.
Deleting everything
On your Mac
Press forget everything about me in the app. It erases the tools, results, history digest, reminders and preferences from disk. It is not a flag that hides them from the interface; the files go.
Dragging Lyndran to the Trash and deleting its support folder achieves the same thing by hand, and there is nothing left behind on the machine afterwards.
On our side
Write to us from the address on the account and ask for deletion. We remove the account record, the usage rows and any waitlist entry with that address. Because we do not hold your asks or your files, there is genuinely nothing else to remove. We will confirm when it is done, within 30 days and normally much sooner.
Devices you signed in with a code are removed with the account. On the phone, uninstalling Lyndran removes everything it kept.
Your rights
If you are in the UK, EU, or another place with comparable law, you have the right to ask what we hold about you, to have it corrected, to have it deleted, to get a copy in a portable form, and to object to processing. Ask, and we will do it — the honest answer is usually that the list is one row long.
Our lawful basis is straightforward: performing the contract when you use the product, and legitimate interests for keeping the service running and secure. The waitlist runs on your consent, which you can withdraw at any time.
Lyndran is not built for, or directed at, children under 16, and we do not knowingly hold data about them.
Changes, and how to reach us
If this policy changes in a way that matters, we will change the effective date at the top and say what moved. We will not quietly widen what we collect and leave you to notice.
Questions, deletion requests, or a correction to something on this page: ertansoftwaresolutions@gmail.com.
Lyndran is made by Mainspring. See also the terms of use and the security architecture.