--- title: "Privacy and permissions" description: "What macOS asks you, why, and what tty7 itself holds." --- ## Why macOS asks tty7 for permission Panes are forked from tty7's own bundled executable, so when a program you run asks macOS for a protected resource, macOS attributes the request to **tty7.app** — not to the program. If tty7 declared no usage strings, that request would be **denied outright with no prompt at all**, and the program would look broken for no visible reason. So tty7 declares the matching usage strings, and you get the normal one-time prompt: Camera · microphone · Bluetooth · location · motion Contacts · calendars · reminders · photo library Local network · Apple Events · speech recognition · system administration **Declaring a usage string is not the same as holding the permission.** tty7.app itself is granted none of these. Every prompt you see belongs to whatever you ran in the pane, and you can revoke it under **System Settings → Privacy & Security**. ### Full Disk Access Apple defines no usage-string key for it. Reaching `~/Library/Mail`, `~/Library/Messages`, `~/Library/Safari`, or `~/Library/Containers` needs a manual grant in **System Settings → Privacy & Security → Full Disk Access**. ## What leaves your machine | | | |---|---| | **Update checks** | A request to the GitHub releases API every six hours, plus the download when you accept one. Turn it off with `check_for_updates: false`. | | **Remote server installs** | Downloading a `tty7-server` binary for a machine you connected to — or, for WSL, copying the one already bundled with your install. | | **Everything else** | Nothing. There is no telemetry, no analytics, and no account. | Both of the above honour `http_proxy`. [Updates →](/reference/updates#proxies) ## What is stored, and where | | | |---|---| | Settings, themes, window state | `~/.config/tty7/` (`%APPDATA%\tty7\` on Windows) | | SSH passwords and key passphrases | The **OS keychain** — never `config.json`, never plain text on disk | | Pane scrollback tails | `/scrollback/*.bin`, mode `0600` on Unix and behind the config directory's ACL on Windows. 256 KiB per pane, kept only until something can no longer ask for it: closing a pane deletes its file at once, a restore consumes it, and a periodic pass collects the rest. | | Shell history | Your shell's own file, exactly as before. With **per-pane history** on, tty7 points each pane's `HISTFILE` at `/pane-history/pane-` instead — the directory is created `0700`, and the files in it are written by your shell, under your umask, holding the command lines you ran in that pane. A pane's additions merge back into your usual history file when it closes. | | Crash reports | `/crash.log`, appended whenever tty7 panics: the time, the version, the panic message and a backtrace. Capped at 256 KiB. Nothing uploads it — it is there for you to read, and to attach to an issue if you choose. | | Update log | `/update.log`, appended by the updater while it installs a release: what it verified, what it replaced, and why it stopped if it did. Written whenever an update runs, not only under `TTY7_LOG` — the swap happens after the window is gone, so this is the only account of it. Nothing uploads it. | | Diagnostic log | `/tty7.log`, written **only** while `TTY7_LOG` (or `RUST_LOG`) is set; unset, there is no log at all. At `info` it records the daemon and connection lifecycle. At `debug` it also carries the directories and workspace names each request names, and output from the libraries tty7 is built on — worth reading before you attach it to an issue. Capped at 4 MiB. |