Privacy
Islet runs entirely on your Mac. The app has no analytics, no tracking and no accounts. It sends nothing about you anywhere, and everything it keeps stays in files and preferences on your computer. The only things it fetches from the internet are update checks and Spotify cover art (see Network).
What it reads
Each of these needs a macOS permission that you grant, and works only for the feature you use.
- Accessibility
- Keyboard shortcuts: while the island is open, it watches key presses so Esc, ⌘1–⌘9, ⌘, and ⌘Return work. When the island closes, it stops.
- Text expander (only if you switch it on): it watches what you type in other apps to spot abbreviations, keeping only the last 64 characters in memory, and types the expansion for you. Password fields are never seen. Nothing typed is saved.
- Claude desktop app reply alerts (can be turned off in Settings): when you switch away from the Claude app, the island looks at the app's window for the "Stop response" button, and reads the chat's name and the start of the reply to show in its alert.
- Calendar: your events for today and the next few days, to list them, find call links and give a heads-up. Events are read from macOS; nothing is copied elsewhere.
- Desktop (or your screenshot folder): the latest screenshots, to show them in the Files tab. Copying text from a screenshot uses Apple's on-device text recognition.
- Clipboard: your recent copies (text and pictures), kept in memory only; items you pin are saved to
~/.notch-island/clipboard. Copies made in password managers (an editable list), and anything marked as concealed or temporary, are skipped. - Camera: only when you press the camera button next to Join, for a preview before a call. Nothing is recorded.
- Apple Events (macOS asks once per app):
- Spotify and Music: what's playing, and the play/pause/skip controls.
- Safari, Chrome, Brave, Edge, Arc, Vivaldi and Opera (only during a focus session with blocked sites, and only if the browser is already open): the addresses of open tabs, so tabs on a blocked site can be sent to the block page.
- Focus status: whether Do Not Disturb is on, from macOS's Focus file, so the island only turns off what it turned on.
- System sensors: CPU, memory, disk, network, temperatures and fan speed, only while the System monitor tab is open.
What it writes
~/.notch-island/: your notes (notes.md), the Claude Code hook and status line scripts, the local port number and a random access token that only your user account can read, andstate.json, a snapshot of your to-dos, Claude Code sessions (including what each is doing, such as the command it's running) and focus timer that tools on your Mac such as the Raycast extension can read. Alsobackups/(daily backups, which include pinned clipboard items),clipboard/(pinned items) andreports/(bug reports you create).- App preferences (
com.derekschwung.NotchIsland): settings, to-dos, snippets, recent colors, focus history and references to the files on your shelf. ~/.claude/settings.json(only when you click Connect Claude Code): adds the island's hooks and status line, keeping all your other settings. The previous file is saved assettings.json.notch-island-backup. Disconnect removes them and puts your old status line back./etc/hosts(only if you installed the site-blocking helper): during a focus session a marked section points blocked sites at 0.0.0.0, and it is removed when the session ends. The installer keeps a copy of your original file at/etc/hosts.notch-island-backup. The helper lives at/usr/local/libexec/notch-island-hosts, with a rule in/etc/sudoers.d/notch-islandand a background check (/Library/LaunchDaemons/com.notchisland.hosts-expiry.plist) that clears a block once its session has ended.- Login item (only if you turn on Launch at Login).
Network
- A local server on 127.0.0.1 only. Claude Code's hooks talk to the island on
127.0.0.1:47823using the token above, and the block page is served on127.0.0.1:52526(it reads the session's intention and time left from there). Neither can be reached from other computers. - Updates: a downloaded copy checks
https://tryislet.com/appcast.xmlfor a new version about once a day, and when you click Check for updates. The request carries only what any app's download does (the app's name and version, in its user agent); no system profile is sent. A new version is downloaded from tryislet.com only when you choose to install it, and its signature is checked before it replaces the app. A copy built from the source code instead runsgit fetch(and, when you choose Update now,git pull) against the repository it was built from, using your own git login. - Feedback: Send feedback and Report a bug open Islet's public GitHub page in your browser. Nothing is sent until you submit it there yourself.
- Spotify artwork: the cover of the song playing in Spotify is downloaded from the image address Spotify itself provides (Spotify's servers), the same picture Spotify shows.
- Opening a meeting link, a block page or a file opens it in the app you'd expect; Islet sends nothing else over the network.
This website
The website, tryislet.com, works differently from the app.
- Analytics, only if you allow it: on your first visit a banner asks whether the site may use Google Analytics and PostHog. If you click Allow, they record the pages you visit, what you click, how far you scroll and where you move the mouse, which site sent you, how fast pages load, and your browser, device and approximate location, and they set cookies so a returning visitor is recognised. If you click No thanks, neither is loaded and nothing is recorded. You can change your choice at any time with Cookie settings at the bottom of every page.
- Who receives it: Google (Google Analytics), which may process it in the US, and PostHog, which stores it in the EU (Frankfurt). The legal basis is your consent, which you can withdraw at any time.
- Download counts: without cookies, the site counts downloads and update checks per day, with the country and the kind of device (Mac, phone, bot) Cloudflare reports for each request. It keeps no IP addresses and nothing else that could identify you.
Removing it
scripts/uninstall.sh disconnects Claude Code, removes the helper and the login item, and deletes the app, ~/.notch-island (including backups and pinned clipboard items; it offers to keep your notes and backups) and its preferences.