PRIVACY · EFFECTIVE AUGUST 24, 2026

What Terrarium reads and sends.

Terrarium is made by Grainwork LLC. The free local watch is designed to work without an account and without sending repository data off your machine.

The local product

Terrarium reads the repository you open, plus agent transcripts under ~/.claude/projects and ~/.codex. The transcript scan covers those directories and is filtered to the selected repository. Transcripts may contain prompts, tool data, and agent text.

Recordings are stored under ~/.terrarium/sessions as JSONL. They may contain absolute paths, source-like labels, structural derivatives, and verbatim agent quotes. Treat recordings as sensitive files.

Saving a snapshot creates a PNG in your browser. Terrarium does not upload the image, but labels visible on the map can appear in it.

Mac 0.0.24 also saves a local HTML file with a static map image, commit ID, checkout observation time, and clean, dirty, or unknown working-tree state. Supported repository origins add a commit link that reveals the repository address; other origins keep the full commit ID without a link. HTML export requires a connected live map with a readable commit. Review both formats before sharing. Private or unpushed commits may not open for recipients, and uncommitted work is not included in the linked commit. Saving either format does not upload it.

What leaves your computer

The free local watch has no required external endpoint. It binds to loopback and does not transmit your repository, transcripts, prompts, recordings, or usage data to Grainwork LLC.

When you activate Founding Pro, Terrarium sends your license key and the Terrarium Polar organization ID from your machine to Polar. Polar returns the license record, including its benefit, status, and expiry, so Terrarium can decide whether to save a local grant. No recording is part of that request.

Only when you choose Encrypt and publish does Terrarium compress and encrypt the selected recording on your machine. It sends the ciphertext and saved license key to Terrarium's replay service, along with a random share ID, byte length, ciphertext checksum, signed time, selected expiry, signing-key fingerprint, upload signature, and a one-way hash of the revoke secret. The request also carries ordinary network information, including your IP address. The replay service sends the license key, organization ID, Founding Pro benefit ID, and its own Polar credential to Polar for license validation before it reads or stores the encrypted recording. The recipient's browser downloads and decrypts the complete selected recording, then renders a compact timeline and summary rather than the full animated terrain.

Terrarium does not put the repository name, file paths, symbol names, agent names, narration, prompts, machine identifier, account identifier, or your private-library session label into the hosted replay record.

The decryption key stays after the # in the replay link, so it is not sent to the replay service. The complete URL is a bearer link: anyone who has it can open the replay in a current browser without an account or Terrarium installation. Email, chat, browser history, and link-preview services may retain it. There are no per-recipient access controls, so share it only with people you trust.

One Pro license may retain up to 100 active hosted replay links or 2 GiB of active encrypted replay data, whichever comes first. Revocation or expiry returns capacity; the limit is not a lifetime count.

The individual link record, complete bearer URL, and replay-specific revoke proof stay only in an owner-only file on the publishing machine. Terrarium has no cloud account library of your links and cannot recreate a lost revoke proof. If the active-storage limit refuses an upload, the service returns only aggregate link count, encrypted byte count, public ceilings, and the earliest expected capacity-return time; it returns no license, individual share ID, revoke proof, repository data, or recording data.

If the subscription lapses, no new hosted replay can be published. Existing links keep their selected expiry, and you can still revoke them or delete the hosted copies. The lapse does not remove any local feature or local recording.

Polar processes payment and receives the account and transaction details needed to complete the purchase. Polar's checkout presents its current purchase and privacy terms before payment.

Optional connections and update checks

Connected state exchanges encrypted state only with installations you explicitly pair after comparing their complete fingerprints. You choose the outgoing projects before encryption. Exchange files manually or use a folder you already synchronize; Terrarium does not operate the folder service or provide a network relay. That service may receive filenames, file sizes, timing, and its ordinary request metadata. The paired recipient can decrypt the state you share.

The explicit update-check action contacts the public npm registry for version information. Normal watch startup does not make this request. Installing or upgrading through npm contacts npm and its download infrastructure separately from the local watch.

Website and email list

If you join the email list, we store your email address, where on the site you signed up, the privacy and consent version you accepted, and the times you requested and confirmed signup. We also store confirmation delivery and suppression status. You must confirm by email before product updates begin. Resend receives the address and delivery metadata needed to send confirmation and update messages. We do not sell the address.

The website is hosted on infrastructure operated for Terrarium and may receive ordinary request metadata such as IP address, browser information, and timestamps for security and delivery. Signup abuse controls turn the network address into a keyed, one-way value and retain it only for a short fixed window. A separate keyed value limits how often one address can be sent confirmation email, even when requests come from different networks. Raw network addresses are not stored in the signup database.

Terrarium does not add advertising or analytics trackers. Hosting and security providers may set cookies that are strictly necessary to deliver the site, protect the form, or maintain service integrity. Those cookies are not used for advertising.

If you email support or report a security issue, Grainwork receives the address and anything you choose to include. Do not attach a repository, recording, credential, or agent transcript unless it is needed and you are authorized to share it.

Deletion and ownership changes

To remove local recordings, delete only the selected JSONL files under ~/.terrarium/sessions. Revoke hosted replay links separately before a full reset. Deleting all of ~/.terrarium also removes the device key, share ledger, and proofs needed to revoke links from this computer. Local deletion does not delete hosted copies, and lost revoke proofs cannot be recreated before link expiry.

For the email list, use the one-click unsubscribe link in any message or contact hello@terrarium.watch to request an export or deletion. A new signup request does not erase an unsubscribe or suppression record. Only confirmation by the address owner can opt the address back in.

If Terrarium is acquired, transferred, or shut down, we will explain what happens to hosted data and provide a reasonable export or deletion window before access changes. Local recordings remain readable without us.

Contact

Privacy questions: hello@terrarium.watch. Support information is at terrarium.watch/support, and security reporting information is at terrarium.watch/security.