Version 10, 2 October 2026: added "Send me the link", one requested email with the download link, address not stored; see the section of that name. Version 9 (29 September 2026): this site now uses Google Analytics on every page, with an opt-out; see Website analytics and optional advertising measurement. Version 8 (29 September 2026): on visits from a Google ad, Google's tag now sends cookieless signals before you choose; see Optional website advertising measurement. Version 7 (28 September 2026) listed the company address; version 6 (26 September 2026) added optional website advertising measurement. Describes optional diagnostics in Shlex 1.3.0 and shlexball.com. Version 1.2.0 used a separate free-tier sharing notice; upgrading asks for a new choice and discards its unsent queue.
Shlex is made by Forge Analytics & Systems Inc., 915 Queen St East, Toronto, Ontario, Canada ("we"). People type names, clients and private matters into a file search box, so this page says exactly what leaves your Mac, when, and what we keep. Questions and requests go to ishti@shlexball.com.
Shlex is an independent product of Forge Analytics & Systems Inc.
The model and file search run on your Mac. Shlex only reads files; it never changes, moves or
deletes the files you search. Local search history is on by default in both Free and Private.
Shlex records submitted search requests, model responses, generated searches and their outcomes,
including refusals, errors and searches that find no matches. Local records can include the
selected folder and returned file paths. They are stored in
~/Library/Application Support/shlex, with local backup copies in its
backups folder, to help investigate searches that did not work.
Keeping searches local prevents automatic search uploads; it does not turn off local history. The app does not automatically upload these history files in either tier. Optional sharing uses a separate queue containing only the data described below. Removing the application does not automatically remove its Application Support history or local backups.
Automatic sharing is off until you choose it. Free and paid users can choose Keep searches on this Mac or Share future searches. Declining sharing does not reduce the free search allowance or paid features. The Private subscription provides unlimited searches; it is not required to keep searches local. Existing users are asked for a new choice; earlier consent and a purchase do not turn on sharing.
| Your choice | Sent to Shlex |
|---|---|
| Keep searches on this Mac | No automatic search uploads. Local history continues. Model setup, app updates and subscription traffic described below still occur. |
| Share future searches | Full submitted prompts and model outputs, including generated commands, refusals and retries; request identifiers, result counts, timing, app and model versions, a device id, the consent version and whether an event was shared automatically or in a report. This includes failed searches and searches that return no matches. |
| Report this search | Only the report you review and explicitly choose to send. It contains the same categories of diagnostics listed above. Reporting one search does not enable automatic sharing of later searches. |
Prompts and model outputs are shared verbatim. They may include names, paths, credentials or other personal or sensitive information you type or the model repeats. We do not upload returned file lists, document contents, previews, the selected search folder or raw local history files. Those exclusions do not remove sensitive information already present in a prompt or model output.
Open the gear button, then Privacy and diagnostics in Advanced settings to change your choice. Turning sharing off stops future automatic collection and deletes unsent automatic events and one-off reports. An upload already in progress may finish. Changing your subscription does not change your sharing choice. Local-only users can still review and send an individual report.
We use shared diagnostics to investigate failed or inaccurate searches, improve Shlex, and train and evaluate models. Records are stored privately with access controls, are not published or sold, and are not automatically anonymized. We do not assume that names or sensitive details have been removed.
Unsent reports and diagnostics expire on your Mac after 7 days. Raw uploaded records are retained in our active collection database for 30 days, then removed by automated cleanup that runs hourly while the service is operating. Operational backup copies may remain until those backups rotate; they are not a separate training dataset. Deleting records does not undo training already performed. Local history and local backups remain until you delete them.
To delete local logs, backup copies and unsent reports, choose Delete local history in Settings. This does not delete uploaded records or your files, reset your search allowance, or turn off future local logging. To request access to or earlier deletion of uploaded records, choose Request deletion of uploaded searches in Settings. It opens an email addressed to ishti@shlexball.com with your collection device id and no search text. Review and send that email yourself. The same id can be copied from Settings. We may ask for information needed to verify a request.
Uninstalling the app, stopping sharing or purchasing a subscription does not automatically delete records already received. You can withdraw from future automatic sharing at any time without paying. Earlier free-tier records also receive the active-database retention limit above.
Payment. Stripe collects your card and email address on its own pages. We never see the card number. Stripe's privacy policy applies to what Stripe holds.
What we store. From Stripe: your email address, the subscription, its plan, status and paid period, and Stripe's customer and subscription ids. From the app: a device id for each Mac you bind (up to two), when it was bound and last seen. The device id is a salted hash of a random install id and the Mac's hardware id; we never receive the hardware id itself. We also store a hash of your licence key, and the key itself for one hour after purchase so the confirmation page and the welcome mail can show it; after that hour only the hash remains.
What the app sends. When you press Go private or Restore purchase, and while Private at start and about once a day (about once an hour while it cannot tell), the app sends its device id to shlexball.com and receives a signed token that says whether the subscription is live. Nothing about your searches travels with it.
Restore by email. You type the address Stripe has; we mail a one-time link valid for 30 minutes. The address is hashed for rate limiting and not kept; an unknown address gets the same answer as a known one.
Mail. The welcome and restore mails come from noreply@shlexball.com through our own mail server. Mail to ishti@shlexball.com is forwarded to our support mailbox at our email provider.
First setup and model updates send the installation device id, an installation public key, signed activation challenges and model version to shlexball.com. The service stores that public key and trial or paid access state to authorize model downloads. Paid activation also uses your existing licence credential. This setup traffic contains no search prompts or file contents and does not grant prompt-sharing consent. Model access secrets stay in the Mac's login Keychain.
The encrypted model is downloaded separately and cached on your Mac. Existing cached access can work offline within your trial or subscription entitlement. Model routes do not write web access logs. Application update checks contact shlexball.com for signed feeds and app archives; Sparkle system profiling is disabled.
Before its model is first downloaded or used, Shlex asks each Mac account to read and sign the end-user licence. The signed record holds the licence version and its SHA-256, the name you type, the time, the app version and build, the installation device id and installation public key, and a signature made with that installation key. It is saved in your Mac account's Application Support folder with a copy of the text you accepted. When the model is next authorized online, the app sends the record to shlexball.com, which stores it with the time it was received and returns a signed receipt. We keep it as evidence of the agreement for as long as that installation's model enrollment is kept; only the service operator can read it. It contains no search prompts, file names or file contents, and it is separate from sharing, telemetry and payment choices. The typed name records who chose to sign; it does not verify anyone's identity.
The service and this site run on a server rented from DigitalOcean in the United States; the subscription records and shared diagnostic records live in a database hosted by Supabase in the United States. Web server logs hold the requesting IP address and the path for 14 days. IP addresses are also used, in memory only, to limit repeated requests. Website analytics and optional advertising measurement are described below. Tutorial pages load YouTube thumbnails; playing an embedded tutorial contacts YouTube's privacy-enhanced player.
On a phone or tablet, the homepage and shlexball.com/get offer to email you the Mac download link. The address you type is used once, to send that one message, and is not stored by the service: it keeps a keyed hash of the address in memory for up to 24 hours to limit repeats (three messages per address a day, with limits per connection and per day for everyone), then forgets it. Our mail server keeps the delivery record of that message, including the address, in its ordinary mail log; we use it for nothing else and delete it on request (section 6). The message names the sender and its address. There is no list and no follow-up; a newsletter, if we ever start one, would ask for its own consent. Website analytics, if you have not opted out, records that a link was sent and the channel you came from, never the address. The web server log holds the request as section 5 describes, without the address.
This site uses Google Analytics to count visits, pages viewed, download-button clicks and the sites or searches that brought you here. Google's tag sets first-party analytics cookies in your browser and receives your IP address, browser and device information and the page address. We turn off Google signals and advertising personalization, so this data is not used to personalize ads, and we do not send app searches, file contents, file paths or customer email addresses through it. Analytics does not load if your browser sends a Global Privacy Control or Do Not Track signal, or if you choose No thanks with the button below; that choice also removes the analytics cookies this site can reach. A download-button click does not prove that a download or installation finished.
Visitors arriving from Google ads can additionally choose whether to allow Google Ads conversion measurement. On a visit from a Google ad, before you choose, Google's tag runs in consent mode with advertising storage denied: it sets no advertising cookies and sends Google only cookieless signals (the page address, the ad click identifier, the time, your IP address and browser information, and a download-button click), which Google uses to count and model ad conversions. If you decline, the tag stops and nothing more is sent. We store your choice in this browser's local storage. Declining does not affect downloads or the app.
If you allow advertising measurement, Google's tag may also use advertising cookies and receive your IP address, browser and device information, page address, ad click identifiers and a download-button click event. We use this to attribute visits and download-button clicks to our ads and measure advertising costs. We disable advertising personalization signals and enable Google's restricted data processing setting.
Google processes measurement data under its privacy policy and explains its use on sites that use Google services. We do not control Google's retention periods. Global Privacy Control and Do Not Track signals disable all of this measurement. You can decline or withdraw permission using the button below; withdrawal stops future analytics and conversion events and removes accessible first-party Google analytics and click cookies, but does not delete data already received by Google. Clearing site data also clears your saved choice.
Mail ishti@shlexball.com to see, correct or delete what we hold about you. We delete subscription and device records on request once the subscription has ended, and collected searches on request at any time (section 3). Stripe keeps invoices and payment records for as long as tax and payment law requires. We answer within 30 days.
Shlex is not directed at children under 13. When this policy changes, the version and date at the top change and the new text is posted here before it takes effect.
Related: terms of service and end-user licence.