Privacy Policy
Last updated: September 17, 2026
Lasso is designed to process selected screen content privately on your Mac.
Information Lasso processes
When you deliberately select part of your screen, Lasso temporarily processes the selected pixels and any recognized text to suggest actions. Depending on the content, this may include event details, tables, errors, addresses, tracking numbers, sensitive text, receipt information, QR codes, contact details, reminders, links, measurements, time zones, developer data, summaries, translations, or colors.
Data collection
Lasso does not collect, upload, sell, or share your screenshots, recognized text, or extracted fields. Graviro never receives them unless you choose to send them with feedback, as described under "Feedback and support messages". Otherwise they leave your Mac only if you turn on iCloud sync for your capture history, and then only encrypted, as described below. Lasso does not include advertising, attribution, or third-party tracking SDKs, and it has no accounts or logins.
Lasso does report anonymous usage analytics, which you can turn off. See "Usage analytics" below.
Usage analytics
So that we can tell which features are worth improving, Lasso reports anonymous events describing how the app is used, never what you capture.
A report can say that a capture began and whether the keyboard shortcut or the menu bar started it; whether any text was recognized, with its length as a coarse range such as "100-499" rather than an exact count; the approximate size of your selection as a label such as "small"; which detectors matched, by name, such as "event" or "link"; which action was recommended and which one you chose; whether a permission request succeeded; which recognition modules you have enabled; and whether an on-device explanation, summary, or translation succeeded or failed.
A report never contains recognized text, an extracted value, a name, an address, a tracking number, a receipt figure, a URL, a file path, a color, or the name or rules of a Custom Parser Pack.
Each report carries a random identifier that Lasso generates on first launch and stores in its own local container. It is not derived from your Mac, your hardware, your name, or any account, it is never combined with information from other companies, and deleting Lasso deletes it. Its only purpose is to tell repeat use apart from first use. Reports also include your macOS version, your Mac's general model (for example "Mac"), your app version, and your language code. They do not include your time zone, your display size, or your network type.
Reports are processed by PostHog, Inc., an analytics provider based in the United States, on Graviro's behalf and stored in its United States data region. Lasso never identifies you to PostHog, so no user profile is created. Like any server, PostHog sees the IP address of the connection that delivers a report; Lasso instructs it not to derive a location from that address and replaces the address stored with each report by a placeholder, so neither your IP address nor your location is kept. PostHog's own privacy policy is available at https://posthog.com/privacy.
Analytics are on by default. To turn them off, open Settings → Privacy and switch off "Share anonymous usage analytics". With the switch off, Lasso opens no network connection for analytics at all.
Storage
Lasso stores your preferences, such as your chosen shortcut and default output formats, the random analytics identifier described above, and, unless you turn it off, your capture history.
Capture history
So you can reuse a selection without drawing it again, Lasso keeps a history of your captures on your Mac. Each entry holds the captured image, a thumbnail, the recognized text, the kinds of content detected, the time, and the name and title of the window you captured. Captures that contain a valid payment card number are not saved unless you change that in Settings.
The history is encrypted with AES-GCM. Its key is stored in your iCloud Keychain so encrypted backups of your Mac can be opened on your other devices; Apple protects iCloud Keychain with end-to-end encryption, and Graviro never receives the key or the history. The history files themselves stay on your Mac and are included in your local backups, still encrypted. Unless you turn on iCloud sync, nothing from the history is uploaded, and nothing from it is ever included in analytics.
iCloud sync
iCloud sync is off by default. If you turn it on in Settings → History, Lasso stores your history in your own private iCloud database so your Macs signed in to the same Apple Account share it. Before anything is uploaded, Lasso encrypts each image and its details with the key in your iCloud Keychain. Apple stores the encrypted data but cannot read it, and Graviro has no access to your iCloud database at all. The only information stored unencrypted is a random identifier for each capture, the time it was captured, and a short fingerprint that tells your Macs which key to use. Each synced capture also records the name of the Mac that made it, encrypted like the rest.
Your capture limit, age limit, and payment-card setting are kept equal on your Macs through iCloud key-value storage. Full-size images are downloaded only when you use a capture from another Mac, and are kept encrypted on that Mac.
Deleting a capture deletes it on every Mac. Turning sync off removes captures from your other Macs from that Mac, and leaves your iCloud data in place. "Delete iCloud Data" in Settings → History removes the history from iCloud and turns sync off on all your Macs; each Mac keeps the captures it made. Signing out of iCloud pauses sync, and signing in with a different account turns it off.
By default Lasso keeps up to 50 captures and deletes captures older than 30 days. You can change both limits, delete single captures or the whole history, or turn history off in Settings → History. Turning it off deletes every saved capture. With history off, selections and recognized content are held in memory only and discarded when the action bar closes.
Lasso writes an image or text to the clipboard, saves a file, or creates a Calendar event, contact, or reminder only after you explicitly choose and confirm the relevant action.
Custom Parser Packs are stored locally in the app container. They contain user-created matching rules and templates, not executable code. Custom parsers cannot directly access files, accounts, system permissions, or the network. A custom HTTPS action opens only after you choose it.
Permissions
Lasso requests Screen Recording access so it can capture only the region you deliberately select. Calendar, Contacts, or Reminders access is requested only when you confirm the corresponding create action. You can change these permissions in macOS System Settings.
Feedback and support messages
You can send us feedback from Settings → General, or report a wrong result with Report This Selection… in the action bar's More menu. Nothing is sent until you click Send, and only what you include:
- the message you write;
- your email address, if you give one, so we can reply;
- technical details, if you turn them on: the Lasso and macOS versions, your language settings and, for a report, which detectors matched and which action was suggested and used. You can preview them before sending;
- for a report, the captured image and the recognized text, each only if you turn it on;
- up to three images or PDF files you choose to add.
The message goes over an encrypted connection to the lassoanything.com server, which passes it to Resend, Inc. (United States), our email delivery provider, and on to Graviro's support inbox. The server uses your IP address for up to one hour to limit how many messages can be sent, and does not store it. We use feedback only to answer you and to improve Lasso, keep it only as long as that takes, and never use it for advertising. Anonymous analytics record that feedback was sent and which kinds of attachment it had, never its content.
External services
When you explicitly choose to open an address, track a shipment, open a smart link, or search recognized text, Lasso asks macOS to open the relevant destination in Maps, Waze, another installed app, or your browser. Those services operate under their own privacy policies. For a Brazilian Correios tracking code, Lasso first sends an empty request to 17TRACK (t.17track.net) to check that the site is up; the code is not included. If it answers, the code opens on 17TRACK in your browser; if not, the official Correios page opens and the code is copied so you can paste it. Capture and analysis themselves make no external request.
When you open currency conversion, Lasso asks the Frankfurter exchange-rate service (api.frankfurter.dev) for that day's reference rates. The request contains only the currency codes involved, for example USD and BRL; the amount, the rest of your capture, and any identifier never leave your Mac. Like any web request it reveals your IP address to that service. Rates are kept in memory for up to an hour and are not written to disk, and Lasso limits itself to 20 rate requests per minute. Apart from this, the 17TRACK check described above, feedback you choose to send, and the anonymous analytics described above, which carry nothing about what you captured, Lasso originates no network traffic on its own.
This website
This section covers lassoanything.com. The website has no accounts and no forms. Its server receives something you captured with the app only when you send it as feedback, as described above.
Cookies
The website sets these cookies:
- NEXT_LOCALE remembers the language you chose, for one year. It is needed for the site to work the way you set it and is never used for analytics.
- lasso_consent remembers whether you accepted or declined analytics cookies, for one year.
- ph_…_posthog is set by PostHog only while analytics are on. It holds a random identifier so repeat visits can be told apart from first visits.
Analytics on the website
To learn which pages are useful, the website reports these events to PostHog: pages viewed and left, clicks on a download button, the content type chosen in the demo, language changes, questions opened in the FAQ, clicks on the support email address, and your answer to the cookie banner. Each event includes the page address, the referring page, and your browser's general type, screen size and language. The website does not record your screen, does not capture what you type, and does not build a profile of you.
If you visit from the European Economic Area, the United Kingdom, Switzerland, or Brazil, or if your country can't be determined, analytics stay off until you accept them in the cookie banner. Elsewhere they are on by default. Anyone can change the choice at any time with Cookie preferences at the bottom of every page; declining turns analytics off and deletes the PostHog cookie.
Analytics requests go through the website's own server before reaching PostHog, which stores them in its United States data region. The server does not pass your IP address along, and PostHog is told not to derive a location, so neither your IP address nor your location is stored with the events. PostHog's privacy policy is available at https://posthog.com/privacy.
Hosting
The website is hosted by Railway and delivered through Cloudflare. Like any web server, they process your IP address to deliver pages and protect the site from abuse, under their own privacy policies. Cloudflare also tells the website your country, which is used only to decide whether to ask for consent and is not stored.
Your rights
You can ask what information Graviro holds about you, and ask for it to be corrected or deleted, by emailing [email protected]. Because the app does not identify you and the website does not collect your name or email address, in most cases Graviro holds no information that can be linked to you. If you write to us, we use your message only to reply, and we delete it when it is no longer needed. Depending on where you live, laws such as the GDPR or Brazil's LGPD may give you further rights, including the right to complain to a data protection authority.
Changes
If Lasso’s or the website’s data practices change, this policy is updated first, and the App Store privacy disclosure is updated before a changed version of the app is released.
Contact
Lasso is published by Graviro. For privacy questions or requests, email [email protected].