Polishly is built around explicit invocation. Here's exactly how your data is handled on Mac and Windows.
When you grant Polishly Accessibility permissions, you give it the ability to read your screen and synthesize keystrokes. We do not take this lightly.
Polishly does not read your screen or your typing in the background. It only ever attempts to read the currently selected text at the exact moment you press the ⌃⌥Space hotkey. If you don't press the hotkey, Polishly sits idle.
When you use Polishly to rewrite text, your Mac or Windows device communicates directly with the AI provider you have configured (e.g., Groq, Cerebras, OpenAI, Anthropic). There is no "Polishly server" sitting in between that logs, stores, or intercepts your prompts and text. You bring your own API key, and you are the only one who sees your traffic.
Your API key is stored locally in macOS Keychain or Windows Credential Manager. It is never uploaded to Polishly.
If you prefer not to use an external provider, you can use "Demo Mode." In Demo Mode, Polishly runs entirely on your device, performing simple rule-based cleanups without ever making a network request.
This marketing website (polishly.info) uses Google Analytics and Vercel Web Analytics to understand page views, engagement, and traffic sources. Google Analytics may use cookies or similar identifiers to provide these measurements; no selected text, API keys, or in-app activity is sent to either service. Analytics are not present in the Polishly macOS app.
Email support@polishly.info with anything about how your data is handled, including security reports. Please never include an API key or sensitive text in a message — we will never ask for either. More ways to reach us are on the contact page.
Have more questions? Check the open-source code on GitHub to verify exactly what the app does.
Free, open source, and yours to run however you like.