Privacy · local-first

Your work stays on your machine. Here is exactly how.

No account, no server, no telemetry. This page lists every place heap. keeps your data and every request it can make — there are only four.

Where it lives

All state is one human-readable file, state.json, in your platform’s application-data folder. Timestamped backups rotate into backups/ beside it; you choose how many to keep.

--data-dir or HEAP_DATA_DIR puts everything somewhere else for a run.

Linux
~/.local/share/heap/state.json
macOS
~/Library/Application Support/heap/state.json
Windows
%APPDATA%\heap\state.json
TokensIn the OS keychain, never in state.json. Without a keychain, a separate secrets.json with restricted permissions.
BackupsRestore from Settings → Data; the current state is backed up first.
LogsWritten to logs/ on your disk. Nothing is uploaded — not even crashes.

Everything that ever leaves your machine

The complete list. If it isn’t here, heap. doesn’t send it.

01

Update check

on start · can be off
GET api.github.com/repos/sectapunterx/heap/releases/latest

Asks GitHub whether a newer release exists. It sends nothing about you or your data. Turn it off in Settings → About.

02

Tracker sync

only if connected
the hosts you configure — github.com, your Jira site…

Pulls your issues. For GitHub, GitLab, Gitea and Forgejo it also closes or reopens an issue when you move its card. Manual, or on a timer you set.

03

Browser sign-in

when you click Connect
your browser → the tracker → 127.0.0.1

Your browser opens the tracker’s own sign-in page, and heap. waits on a loopback port for the reply. heap. never sees your password.

04

Mattermost people

only if connected
your Mattermost server

Reads the people you talk to, to offer them as contacts and @handles. Nothing is posted.

Moving between machines

Export a profile to a .todocpp.json file and import it on the other side — importing only ever adds. Continuous sync through your own private git remote is on the roadmap.

Data & backups in the docs
todayExport / import a profileContent only — never your settings or other profiles.
todayNotes as MarkdownA folder of .md files, readable by Obsidian or any editor.
roadmapSync via your git remoteOne diff-friendly file per profile, history for free.

This website follows the same rule: no analytics, no cookies, no third-party requests. Fonts are served from here. The browser demo keeps its state in your browser’s local storage and nowhere else.