Privacy Policy
Last updated 1 August 2026
The short version: Ergo has no servers. It collects no personal data, contains no analytics or tracking, and never transmits your kubeconfig, credentials, or cluster data anywhere except to the clusters and cloud providers you yourself connect it to.
Who this covers
This policy covers the Ergo application for macOS and this website. Ergo is published by Joseph Ridenour. Questions go to support.
What Ergo collects
Nothing. There is no Ergo account, no sign-up, no telemetry, and no backend service to receive data. We do not build a profile of you, and we have no ability to see which features you use, which clusters you connect to, or that you are running Ergo at all.
What stays on your Mac
Ergo is a local application. The following is created and kept entirely on your own computer, inside the macOS App Sandbox:
- Cluster credentials and tokens — stored in the macOS Keychain. They are sent only to the cloud provider or cluster that issued them.
- Kubeconfig files — read only through a file picker you control, and remembered across launches using macOS security-scoped bookmarks, which grant access to the specific files you chose and nothing else.
- Cluster data — resources, events, logs, and manifests are held in memory and in local caches for the app's own use.
- Your settings — saved views, filter presets, column choices, window state, and usage history samples.
- Cluster configuration, if you turn on iCloud sync — off by default. When you switch it on in Settings, the details of the connections you have added (name, provider, API server address, environment tier) are kept in step across your Macs through your own iCloud account. Credentials are never included: each Mac signs in to a cluster on its own. Neither are cluster contents, logs, or manifests. Switching it off removes the copy from iCloud.
- Diagnostics — Ergo subscribes to Apple's MetricKit to keep a small on-device record of crashes and hangs (the twenty most recent). This is never uploaded. It leaves your Mac only if you choose Share Diagnostics… in Settings and save the file yourself.
Where Ergo does connect
Ergo makes network connections only to endpoints you direct it to:
- The Kubernetes API servers of clusters you add.
- Amazon, Google, and Microsoft sign-in and cluster-discovery endpoints, when you choose to sign in to EKS, GKE, or AKS. Those providers' own privacy policies govern what they do with those requests.
- Apple's App Store, for subscription purchases and validation.
- Apple's iCloud, only if you turn on cluster-configuration sync. The data goes to your own iCloud account; Ergo has no server and cannot read it.
Ergo also opens listeners on your Mac's loopback interface — for port forwarding, and for the optional local agent (MCP) endpoint. These accept connections only from your own computer and are not reachable from the network.
Artificial intelligence features
Ergo's optional form-fill suggestions run on Apple's on-device model. The content of your cluster is not sent to us or to any third-party model provider for these suggestions. If a future version offers a bring-your-own-key connection to an external model, it will be off by default, will name the provider, and will be governed by that provider's terms — and this policy will be updated before it ships.
Purchases
Ergo Pro is sold as an auto-renewable subscription through the Mac App Store. Apple processes the payment and manages the subscription. We never receive or store your payment details. Apple provides us with aggregate, anonymised sales reporting; it does not identify individual customers to us. Apple's handling of your purchase is covered by Apple's privacy policy.
This website
This site is a set of static pages hosted on GitHub Pages. We run no analytics, set no cookies, and use no tracking pixels. GitHub serves the pages and, as any web host does, processes request data such as IP addresses for delivery and abuse prevention; see the GitHub privacy statement. The pages load the Inter typeface from Google Fonts, which means your browser makes a request to Google when you view them.
Children
Ergo is a developer tool intended for professional use and is not directed at children. We do not knowingly collect information from anyone, of any age.
Your rights
Rights such as access, correction, deletion, and portability apply to
personal data a company holds about you. We hold none, so there is nothing for
us to disclose, correct, export, or erase. To remove everything Ergo has stored
on your own Mac, delete the app and its container in
~/Library/Containers/com.joesapps.ergo, and remove any Ergo entries
from Keychain Access.
Changes
If this policy changes materially — in particular if any version of Ergo ever begins collecting data — we will update this page and the App Store privacy label before that version ships, and note the new date above.
Contact
Questions about this policy: see the support page.