Privacy Policy

What stays on your device, what anonymous usage analytics send and how to turn them off, and how GitHub sign-in works.

Privacy Policy

Last updated: October 4, 2026

This policy covers the Bifurc desktop app, its engine and command-line tool (version 0.4.0 and later), the Bifurc Companion browser extension, and this website. Bifurc is developed by Harshal Kudale ("we", "us").

The short version

  • Your workspaces, requests, mocks, captured traffic, certificates and secrets stay on your computer.
  • Bifurc sends anonymous usage analytics: what kind of thing you did, never its content. They are on by default once you accept the Terms of Use and this policy, and you can turn them off at any time in Settings → About → Privacy.
  • Signing in to GitHub is optional. It is only needed to sync a workspace with a repository you own, and your GitHub token never leaves your device except to talk to GitHub.
  • We do not sell your data, show ads, or build a profile of you.

Data that stays on your device

Bifurc is a local-first application. Everything you create or capture with it is stored in files on your device, including:

  • Application settings and preferences
  • Workspaces: requests, mocks, mappings, proxy rules, environments and health checks
  • Vaults, encrypted with a passphrase only you know
  • Captured network traffic, including request and response headers and bodies
  • Certificates and private keys generated for HTTPS interception
  • Git history of your workspaces

We do not operate servers that receive, store or back up any of this. Network traffic you route through Bifurc's proxies is processed on your device and is not sent to us.

Anonymous usage analytics

To understand which parts of Bifurc are used and where it fails, the engine sends anonymous usage events to PostHog, an analytics provider that processes them on our behalf on servers in the United States.

When analytics are on

Nothing is sent before you accept the Terms of Use and this Privacy Policy on first run. After you accept, analytics are on by default and stay on until you turn them off.

What is sent

  • What kind of thing you did, as an event name from a fixed list, such as request sent, mock created, workspace synced or engine started.
  • Properties that describe its shape, each one a yes/no, a count, or a word from a fixed list. For example: the request type (rest, graphql, grpc, soap, websocket), the HTTP method, whether a script or test is present, how many headers there are, or the class of the response status (2xx, 4xx).
  • How often each command ran, with the interface it came from (desktop app, command-line tool or browser extension) and whether it succeeded or which error code it returned.
  • About the install: the Bifurc version, your operating system family (for example windows) and processor architecture (for example x86_64).
  • A random install ID, generated on your device the first time analytics run. It is not derived from your hardware, your account or anything else about you, and it only tells us that two events came from the same installation.

What is never sent

  • Names of your workspaces, requests, mocks, environments, folders or files
  • URLs, hostnames, ports, paths or patterns
  • Headers, bodies, scripts, variables, secrets or anything else you typed
  • Captured or proxied traffic
  • Your GitHub username, token, repositories or their contents
  • Your name, email address or precise location

Bifurc asks PostHog not to create a person profile for the install ID and not to look up a location from the request. As with any request over the internet, PostHog's servers necessarily see the IP address the request arrives from; we do not use it to identify you.

Turning analytics off

Open Settings → About → Privacy and switch off Anonymous usage analytics. From then on nothing you do is reported.

Two things to know:

  • With the switch off, a single app installed event (version, operating system, architecture and the random install ID) is still sent once per installation, if it has not been sent already, so that we can count installs.
  • To send nothing at all, including that one event, set the environment variable BIFURC_TELEMETRY=0 or DO_NOT_TRACK=1 before starting Bifurc.

Turning analytics back on takes effect the next time the engine starts.

Legal basis and your choices

We rely on your acceptance of the Terms of Use and this policy, and on our legitimate interest in understanding how the product is used, to collect these anonymous events. You can withdraw at any time with the switch above; withdrawing does not affect anything in the app.

Your install ID is stored in analytics.json in Bifurc's data directory. If you want the events tied to it deleted, send that ID to the contact address below and we will remove them.

GitHub sign-in and workspace sync

Signing in is optional. Workspaces work fully offline as plain files with local git history.

If you choose to sign in to GitHub to sync a workspace:

  • Sign-in uses GitHub's device flow: Bifurc shows a code, you enter it on github.com, and GitHub issues an access token to the app on your device. We never see your GitHub password.
  • Bifurc requests the repo permission, which it uses to list repositories you own, create a repository for a workspace, and push and pull workspace files.
  • Bifurc stores the token together with your GitHub user ID, username, display name and avatar URL in a file on your device. On Windows the token is encrypted to your Windows user account; on other platforms the file is readable only by your user.
  • The token is sent only to GitHub. It is never sent to us or to PostHog, and it is never written into a workspace repository.
  • When you publish or sync, your workspace files are sent to the GitHub repository you chose. What happens to them there is governed by GitHub's privacy statement and by who you give access to the repository. Vaults are synced only in their encrypted form.
  • Signing out in Settings → Accounts removes the token and the account from your device. You can also revoke Bifurc's access from your GitHub settings at any time.

Git operations run on your device using the git you have installed.

HTTPS certificates

When you enable HTTPS interception, Bifurc generates a root certificate and private key on your device, or uses ones you import. They are used only by the local proxy. They are never sent to us.

Browser extension

The Bifurc Companion extension talks to the Bifurc app running on your own device. Traffic it captures is handed to the local app and is not sent to us.

Updates

The desktop app does not check for updates on its own. If you installed Bifurc from the Microsoft Store, updates are delivered by the Store under Microsoft's terms.

This website

  • If you use the contact form, the name, email address and message you enter are delivered to us by email through FormSubmit. We use them only to reply.
  • Our hosting provider may keep standard request logs (such as IP address and user agent) to operate and protect the service.
  • The website does not set advertising or analytics cookies.

Third parties

ServiceWhat it receivesWhen
PostHogAnonymous usage events described aboveWhile analytics are on
GitHubYour sign-in, and the workspace files you syncOnly if you sign in or load this website
Microsoft StoreInstall and update activityOnly if you install from the Store
FormSubmitContact form submissionsOnly if you send the form

Each operates under its own privacy policy.

Data sharing

We do not sell, rent or trade your data. The anonymous analytics events are shared only with PostHog as our processor, and are otherwise disclosed only if required by law.

Security

Because your data lives on your device, its security depends on the security of that device. You are responsible for protecting your computer, your vault passphrases, and the repositories you sync to.

Children

Bifurc is a developer tool and is not directed at children.

Changes to this policy

We may update this policy. The date at the top shows the latest revision. If a change affects what leaves your device, we will say so prominently on this page and in the release notes.

Contact

Harshal Kudale

Email: contact@bifurc.app

Website: bifurc.app