He can see your screen and click in your apps. So here is what keeps that safe.
Here is how your data is protected, which permissions AirBubble asks your Mac for and why, and how the app is checked before it runs.
It says how to report something you have found, and what happens after you do. Where we have nothing to show yet, we say so.
Encrypted every time it leaves your Mac.
The app talks only to AirBubble and to the providers that do specific jobs for us, and always over an encrypted connection.
In transit
Everything the app sends is encrypted with TLS. There is no unencrypted fallback and no setting that turns the check off. If a connection cannot be verified, the app refuses it.
At rest on your Mac
Your notes and your conversation history are stored in AirBubble's own folder on your Mac, under your user account, and protected by FileVault if you have it switched on. Screenshots are not kept. Delete a question and its answer and they are removed, and never brought into a later conversation.
At rest on the server
What we store on our servers is encrypted at rest, and only our own service can reach it, over an authenticated connection. The outside services involved are listed on the subprocessors page.
Where your question goes
- 1Your MacYou hold the keys and ask. Nothing starts until you do.
- 2EncryptedSent over a connection that is checked every time.
- 3AirBubbleConfirms it is you, then has our AI provider work out the answer.
Your sign-in is kept encrypted on your Mac.
A key saved in a plain file can be read by other apps on the same Mac. AirBubble keeps its sign-in key in an encrypted store instead.
Encrypted on the device
The key that signs the app in to AirBubble is kept in an encrypted store tied to your user account on the Mac. It is never written to a plain file you could open in a text editor.
Kept out of logs
The key is read only when a request needs it. It never appears in a log or a crash report, and our logs are written so they are safe to paste into a support request.
Nothing of yours to hold
AirBubble never asks for the password to another app or service, and the agent will not type one for you. If a lesson reaches a login screen, it stops and hands the keyboard back.
What it asks your Mac for, and why.
Each permission is asked for when it is first needed, with the reason on screen. You can turn any of them off in System Settings whenever you like.
Screen Recording
Lets him see your screen when you hold the keys and ask. Without it he cannot see, and he tells you so.
He never looks between questions. Nothing watches your screen on a timer or in the background.
Microphone
Opens while fn ⌃ is held and closes when you let go. Dictation works the same way.
There is no wake word and nothing listening in the background. The Notetaker is the one exception. It asks before it records, and it stops by itself after eight silent minutes.
Accessibility
Lets him read the app in front of you when you ask, so he can show you the right place. macOS also requires it before AirBubble can notice you holding its keys.
The agent uses it to click and type for you, and only after you say yes to the run.
Two more, only if you use what needs them. When AirBubble types text for you, as dictation does, macOS may ask whether it can control System Events. If you connect your calendar so the Notetaker can spot a meeting, it asks to read your calendar, and the events are read on your Mac. AirBubble does not ask for Full Disk Access, contacts, photos, location or your keychain, and it installs no kernel extension. If a future release needs a permission that is not on this page, we will add it here before that release ships.
Signed by us and checked before it runs.
Apple verifies that AirBubble came from us and has not been changed. The app then checks its own parts every time it uses them.
Signed and notarised
The app is signed with our Apple Developer ID and notarised by Apple before release, so macOS can verify it came from us and has not been altered since. A build that fails that check will not open, and you should not force it.
Hardened runtime
It runs with Apple's hardened runtime switched on, which closes off common ways for another program to tamper with it while it runs.
Checked every time
The parts of AirBubble that work with your screen and your apps are checked against a fingerprint we record when we build them. If one does not match, it does not run.
The agent does nothing until you say yes.
Nothing gives that yes for you. Switch Agent Mode off and a run that is under way stops, even halfway through a step.
Any setting that skips a confirmation ships switched off. Turning one on is your decision.
Every change to these safeguards is reviewed as a security change and tested against the real code.
- 1Agent Mode is switched on
- 2You said yes to this specific run
How the code is looked after, and what we have not done yet.
We keep outside code to a minimum and review changes before they ship. No outside auditor has checked any of it yet.
Little outside code, locked down
The outside libraries we use are locked to exact versions and updated by hand. An update that touches the screen, input or the network gets a closer review.
What runs on your Mac is what we built and signed.
Reviewed before it ships
Any change to how the app sees your screen, clicks for you or talks to our servers is reviewed as a security change. The agent's safeguards are tested against the real code.
Our own keys never go into our source code. If one ever slips in, we treat it as exposed and replace it.
No certification yet
AirBubble holds no SOC 2 report and no ISO certification, and no external penetration test has been commissioned yet. There is no audit under way that we are waiting to announce.
When a report exists, this page will name the firm, the scope and the date.
Found something? Tell us before you tell the internet.
We would rather hear it from you than read it somewhere else. Report it privately, give us a reasonable window to fix it, and we will keep you in the loop while we do.
How to report
Send it to the security address below. Include what you did, what happened, and what you expected. Add the macOS version and the AirBubble build number, which is in the app under About.
A short proof of concept helps more than a scanner export. If you would rather encrypt the report, say so in the first mail and we will send you a key.
Security contact
Provisional: security@airbubble.io. This mailbox is not live yet. Until it is, use support and mark the message as a security report, and we will move it to a private channel.
Response target
Provisional: acknowledgement within a few business days, a first assessment after that, and progress updates until it is closed. The exact hours are not set yet, and we will not publish a number we cannot hold.
What happens next
- 1We confirm we have it, and ask anything we still need.
- 2We reproduce it and tell you what we found.
- 3We fix it, ship it, and tell you which build carries the fix.
- 4We credit you by name if you want it, or keep you anonymous if you do not.
There is no paid bounty programme yet. If that changes, the terms will be on this page.
In scope
- The current released version of the AirBubble app for Mac, including how it reads the screen, listens for the keys and stores data on your Mac.
- The AirBubble servers and the API the app talks to.
- This website and anything served from it.
- The agent. Anything that makes it click or type without your yes to that run, or while Agent Mode is off.
- How sign-in details and session data are kept on your Mac.
Out of scope
- AirBubble appearing in screen recordings and screen shares. That is on purpose.
- Attacks needing physical access to an unlocked Mac, or an account you already control end to end.
- Social engineering of our team, our users or our suppliers, and anything involving physical premises.
- Denial of service, load generation and volumetric testing against our servers.
- Scanner output with no demonstrated impact, and missing headers or best-practice flags with no exploit path.
- Issues in third-party services we depend on. Report those to them, and tell us so we can track it.
- Findings that only reproduce in a modified, repackaged or unsigned build.
Safe harbour (draft)
Research done in good faith should not put you at risk. If you stay inside the scope above, use only your own accounts and test data, avoid touching anyone else's information, avoid degrading the service for other people, and give us a reasonable window before you publish, we will treat your work as authorised and will not pursue legal action over it.
If a report puts you in an unclear position, ask us first and we will answer in writing.
This paragraph is a draft. It has not been reviewed by a lawyer and is not yet a legal commitment. The reviewed version will replace it before launch.
No badge yet. Check it for yourself.
Everything above describes how the app behaves and how we work on it. No outside auditor has checked any of it yet.
You can test the visible parts yourself. Hold the keys and watch the microphone indicator come on and go off. Record your screen and see AirBubble in the recording. Turn off Screen Recording in System Settings, ask him something, and he tells you he cannot see.
Last reviewed: pending first release.
If something here is unclear, ask and we will write it down.
We answer security questions the way we answer reports, plainly and in writing. If your answer is missing from this page, it belongs on it.
