Privacy, data, and AI
Where everything lives, what leaves your Mac, and what Claude sees.
Updated Aug 14, 20265 min readApplies to 1.1.5
Your work is yours. Your clients' work is theirs.
Where the files live
Your originals stay on your Mac. Full-resolution files never upload to us, with exactly one exception. You explicitly approve a high-res request from a publication editor, and even then the file lands in a bucket that deletes itself after 72 hours. An hourly sweep does the deleting. High-res requests covers who can ask and what approving does.
Your catalog syncs. Tags, captions, alt text, vendor credits, all the metadata. That's what makes the same archive available on the Mac and the phone.
Published images route through an image host. Web-optimized copies only, so Pinterest and Instagram can fetch them at publish time.
Reference documents you drop on a job, planner timelines, design decks, briefs, live in a bucket scoped to your workspace.
Where your files live has the folder-level detail.
What the AI sees
We use Anthropic's Claude for cataloging, captions, alt text, and every other written field. Each call sends one image plus the context that matters, meaning your brand voice, the job's details and the debrief answers, gets a response, and moves on.
The image it sees is a 1568 pixel copy, made on your Mac at catalog time. Not your original. Read, then discarded, and never used for training.
Separately, a 2560 pixel working copy goes to storage. That's the one carousels, submissions, and publishing run on.
The two paths
| Plan credits | Your own key | |
|---|---|---|
| Route | Your Mac, our proxy, Anthropic | Your Mac, straight to Anthropic |
| Touches our storage | No. It passes through, it's not kept. | Never goes near us at all |
| Billed by | Us, against your monthly cap | Anthropic, and it ignores the cap |
| Batch size | Capped at 3 images per call, to stay inside the proxy's time limit | Whatever you set, up to 15 |
Where your Anthropic key is actually stored
This is worth being plain about, because the previous version of this page was wrong.
Your personal Anthropic key lives in the app's own settings. It's part of the
app settings record, written to ~/.tbt-catalog/settings.json on your Mac as
ordinary readable JSON. Stored in plain text. Anything running as you on
your Mac can read that file. It isn't sent to us and it's not synced to the
cloud, but it's not encrypted at rest either.
It's not in the macOS Keychain. No Anthropic key of yours has ever been in the Keychain. The only thing les Archives ever put there was a sign-in credential from the old email-and-password flow, which no longer exists now that sign-in is a six-digit code. If you're cleaning up old entries, that's the one you'll find.
On Studio and Agency there's a second key, and it's stored on our servers. Chapter 08 of Settings carries a WORKSPACE ANTHROPIC KEY row on those tiers. That key is written to your workspace's row in our database so that everyone on the team can catalog against it. Only the workspace owner can read it back or change it. A team member never sees the row or the value, and their cataloging runs on it all the same. If you would rather no key of yours sat on our infrastructure, leave that row empty and use the personal key row instead.
Your session is in UserDefaults, not the Keychain. The sign-in token that keeps you logged in is stored in the app's own preferences, deliberately, so macOS doesn't prompt you for a keychain password on every launch. Scoped to this app's preferences and not readable by other sandboxed apps, but not protected by the Keychain either.
Your license key is stored locally in the same preferences and checked against our billing account.
We don't read any of these. But "we can't read it" and "it's encrypted on your disk" are different claims, and only the first one is true.
What we never send
- Bug reports carry app state. Never your photographs, never your API keys. The activity tail is run through a redactor on your Mac that strips anything shaped like an Anthropic key, a session token, or an authorization header.
- Catalog logging records folder names only. Never local file paths.
- Digest emails carry counts and status. No image content.
- Health monitoring is internal and is never emailed to a client.
If you cancel
Your originals stay where they always were, on your Mac. Your catalog metadata is deleted according to our retention policy. Your own Anthropic key stays in your own settings file, and you should delete it yourself if you want it gone.
Was this helpful
Still stuck
Tell us what happened and we will usually answer the same day. If it is more of a question than a bug, ask the room. Every tester reads it, and you are already signed in.