Privacy Policy

Last updated: July 17, 2026

Tudor Turcanu ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how Curlew handles your data. Because Curlew is built as a local-first application, our design ensures your data remains under your absolute control.

1. Local-First Architecture

Curlew operates entirely on your local machine. Unlike traditional cloud-based API clients, we do not require you to create an account, log in, or sync your workspaces to a remote cloud server. Your requests, variables, history, and settings are saved in a local configuration file on your macOS filesystem.

2. Keychains & Credentials

Any values marked as secrets (such as API tokens, passwords, and private environment variables) are stored securely using the macOS native Keychain. They are never written to your workspace JSON configuration files and are automatically stripped from any workspace exports to ensure they do not leave your system accidentally.

3. Data Collection and Telemetry

Curlew does not collect, track, store, or transmit any telemetry, crash reports, or analytics data. We have zero visibility into:

  • The APIs you are calling or testing.
  • The request bodies, headers, or responses.
  • Your usage metrics and patterns.

4. Network Connections

All network requests initiated inside Curlew are sent directly from your local machine to the target servers you specify. Curlew does not route your network traffic through any intermediary servers or proxies owned by us.

5. Updates & Changes

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date. By continuing to use Curlew, you agree to the terms outlined in the updated policy.