Browser data stays on your Mac
Cookies, cache, and other browsing data stay in Refract's profile on your Mac, and the cookie store is encrypted with a macOS Keychain key. The network log and held requests live in memory and are cleared when Refract restarts. Provider API keys are encrypted with macOS safe storage, and the interface cannot read them back. The app does not start a crash reporter, includes no analytics SDK, and switches off Chromium background services such as sync, translation, and the component updater.
Agent requests go to the provider you choose
When you start an agent turn, Refract sends your API key and the relevant browser context directly to that provider. By default, Refract redacts cookie and authorization header values before the agent sees them. Redaction is a precaution, not a promise that every secret on a page is removed. Turning on real secret values sends more. Your provider's data and retention terms apply.
When the app contacts Refract
Activating a license sends the key, a hashed machine identifier, the Mac's hostname, platform, and app version to the licensing service. With a license active, the app revalidates its signed receipt at launch and every few hours. Recovering a key sends the email address you enter. Help → Check for Updates sends the app version. Until you use one of these features, the app does not contact Refract's service.
Purchases and licensing
Stripe handles checkout; Refract never receives your full card number. The licensing service keeps the purchase email address, license status, seat count, activation records, payment identifiers, and the audit events needed to issue and manage a license. License and account email is sent through Resend.
Website and support
This site and the licensing API run on Cloudflare, which processes ordinary request data such as IP address and headers to serve pages and protect the service. The public pages set no cookies and load no third-party scripts or analytics. The account portal uses a secure session cookie while you are signed in. If you email support, your message and contact details are used to answer it.
Questions or requests
For a question about your account or data, contact licenses@refracted.tools. Include the purchase email address if you need help finding a license. Never email an API key or license key.