Privacy Policy
Straight Up Browser · Effective date: August 11, 2026
Summary
Straight Up Browser has no Browser account, advertising, tracking, usage analytics, or third-party analytics SDK. Ordinary browsing data is stored on your device. Optional sync uses your private iCloud database, not a database operated by us. Data otherwise leaves the app only as needed to visit a website, use your chosen search service, or use an optional provider or integration that you deliberately configure.
Who we are
Straight Up Browser is made by Nathan Fennel. Privacy questions can be sent to support@100apps.studio.
Data stored on your device
The app stores information needed to provide browser features, including:
- Browser library and state. Open tabs, tab groups, bookmarks, browsing history, recently closed tabs, favicons, container names, saved workspaces, and app settings.
- Website data. Cookies, caches, local and session storage, and website logins are kept in WebKit data stores. Normal browsing and each container have separate stores. Incognito stores are temporary.
- Downloads and captures. Download records, downloaded files, PDFs, and screenshots remain on your device or in a folder or Files location you choose.
- Site permissions. Camera and microphone choices can be remembered per website so the site does not need to ask every time. Incognito tabs do not save these choices.
- Mac agent data. If you use the optional macOS agent, its conversations, runs, approvals, replay evidence, artifacts, scoped memory, schedules, and redacted diagnostics are local by default. Provider and integration secrets are stored in Apple Keychain.
We do not receive this local data. The app does not operate a hosted browsing proxy or send browsing activity to us as telemetry.
Optional private iCloud sync
Sync is off by default and requires an Apple Account with iCloud available. When you turn on browser sync, Apple stores the selected records in Straight Up Browser's private CloudKit database for your Apple Account. An opted-in open-tab record can include its current URL and title, tab settings, and that tab's saved visit URLs. If the tab visited a search-results page, those URLs can contain the search terms. Tab groups, bookmarks, and container names and colors also participate in browser sync. We do not use this data and do not receive a copy of it.
Live page state is a separate opt-in. It can add scroll position, back/forward state, and form state to a synced tab. Cookies, local storage, session storage, and saved logins never sync. Turning live page state off removes those saved snapshots. Incognito data, caches, downloads, saved workspaces, and extension state also never participate in browser sync.
Three Mac agent definition categories are separately opt-in: scheduled-task definitions, nonsecret provider presets, and user-authored memory. Provider keys, bearer and OAuth tokens, MCP credentials, page handles, runs, transcripts, approvals, artifacts, and incognito data never sync.
For definition sync, Browser creates a random identifier for each installation and stores it with private iCloud definition records so changes from different installations can be merged deterministically. It is not an advertising identifier and is used only for that private-record merge—not for tracking, analytics, or profiling.
Websites, search engines, and updates
A browser must connect to the services you ask it to use. When you visit a page, that website and its service providers receive the request and ordinary network information such as your IP address, browser details, and any cookies or information you submit. A search typed into the omnibar is sent to the search engine selected in Settings. Those services handle data under their own terms and privacy policies; Straight Up Browser does not route those requests through our servers.
The macOS app checks nathanfennel.com for signed software updates. The website host may process routine, short-lived request logs for delivery, reliability, and security.
Optional model providers and MCP connections on Mac
The macOS app can connect directly to a model provider or compatible endpoint that you choose. Starting a run sends the prompt and the context needed for that request—which can include selected page or file content—to that provider. The app shows and limits tool access, but the provider processes submitted data under its own terms, retention rules, and privacy policy. We do not receive provider requests or API keys.
You can also add a compatible MCP server. The app requires an explicit trust and connection flow and shows the server identity and tool effects. A trusted server receives only the connection requests and tool data you authorize. Bearer and OAuth credentials stay in Keychain; OAuth sign-in occurs through the system authentication session. The server and its identity provider are independent third parties with their own data practices.
Camera and microphone
A website can request camera or microphone access. Straight Up Browser shows a prompt tied to that website before WebKit grants access. If allowed, media goes to the website you are using—not to us. You can review or revoke remembered choices in Settings under Site Permissions, and Apple's system privacy settings remain in control.
Incognito browsing
Incognito tabs use in-memory tabs and temporary website-data stores. They do not add persistent browsing history, sync data, saved site-permission decisions, Fast Forward learning, or retained agent content under the default policy. Incognito does not make you anonymous to websites, internet providers, employers, schools, or network operators.
Your controls and deletion
- Browsing data. Settings › Privacy can clear history, cookies, caches, and local storage. You can also inspect and delete individual cookies, remove individual history entries, clear history, or clear data for one site, one session, or every browsing session.
- Permissions. Settings › Site Permissions can revoke one website decision or all saved camera and microphone decisions.
- Downloads. Clearing download history removes the app's record. Delete downloaded files, screenshots, and exports separately from their saved location.
- iCloud data. Turn browser sync off to stop new browser-data syncing. Disabling an agent-definition category offers a choice to keep local copies or delete its iCloud copies. You can remove the app's remaining private CloudKit data from your Apple Account using Apple's iCloud storage controls.
- Mac agent and integrations. Agent settings let you delete runs, conversations, memory, and integration data, revoke MCP connections, and remove provider credentials from Keychain.
We cannot look up or delete local or private-iCloud browser data for you because there is no Browser account or copy on our systems. For step-by-step help, see the support page.
Children
Straight Up Browser is a general-purpose browser and is not directed specifically at children. We do not knowingly collect personal information from children. Websites used in the browser may have their own age requirements and data practices.
Changes and contact
If this policy changes, this page will show a new effective date. Questions or requests about this policy can be sent to support@100apps.studio.