vercat

Privacy / August 9, 2026

Privacy, plainly.

vercat is an independent iOS companion for Vercel. This page explains the data the app uses to work and the limited data it uses to measure onboarding.

Vercel access

You provide a Vercel Personal Access Token (PAT). Vercel API requests made with that token go directly from the app to Vercel. The token and saved-account metadata are stored using the iOS Keychain and can be removed by deleting the saved account in the app.

Data kept on your device

App preferences, selected teams and projects, pinned projects, display settings, and cached API data remain on the device. Environment-variable responses and runtime logs are not written to the app's persistent query cache. Local data persists until it is reset or cleared in the app, removed with the app, or otherwise managed by iOS.

Your vercat account and subscriptions

When enabled, Apple or Google sign-in is handled by Clerk. Clerk processes your provider identity and the profile information you choose to share, such as your name and email address, to create your vercat account and manage secure sessions. Session credentials are stored in iOS Keychain. RevenueCat receives your vercat account identifier and App Store purchase information to determine your Pro access across connected Vercel accounts. Your Vercel tokens remain on this device and are not sent to Clerk or RevenueCat. You can sign out or delete your vercat account in Account settings. Deleting the account does not cancel an Apple subscription; manage cancellation in your App Store subscription settings.

Basic app and onboarding counts

The app sends PostHog a small event when it opens, when an onboarding page is shown, and when a Vercel account connection is attempted, fails, or completes. These counts are on for everyone so we can see where onboarding stops. Each installation has a separate random identifier used only for these counts. Events include the page name, whether the build is for development or release, and whether it runs on a simulator. They do not include a Vercel account identifier, token, email, device model, or precise location. PostHog does not enrich these events with location from the network address. The identifier is not linked to your Vercel identity or to the optional analytics identifier. This basic counting cannot be turned off in Account settings.

Optional PostHog telemetry

Additional analytics is off by default. If PostHog is configured for the distributed build and you enable Additional analytics in Account settings, the app may also send:

  • Account-connection, screen-view, app-lifecycle, screen-timing, and navigation data.
  • Uncaught exceptions, unhandled rejections, native crashes, and related error context.
  • Approximate location derived by PostHog from the network address of a screen-view request, such as country, region, or city. The app does not request device location access.

This data is used to understand feature usage, improve reliability, and diagnose failures. Vercel account IDs, email addresses, names, usernames, PATs, environment values, and console logs are not sent as analytics properties. GeoIP enrichment is enabled only for screen views when analytics is on. Analytics uses a random PostHog installation identifier and is not linked to your Vercel identity. Existing users are asked to opt in again after this change. Turning the setting off stops future analytics and crash-event collection from the app.

Feature availability

The app may request anonymous PostHog feature-flag decisions so experimental Vercel API features fail closed if an endpoint changes. These requests use a random installation identifier plus basic app and device context. They are used for app functionality, not advertising, and are not linked to your Vercel identity.

Services and your controls

Vercel, Clerk, RevenueCat, and PostHog process data under their own privacy policies and service terms. You control Vercel access by managing or revoking your PAT in Vercel and by removing saved accounts from vercat. You can stop additional analytics at any time in Account settings and delete local app data by removing saved accounts or deleting the app. For privacy questions concerning this app, use the support contact listed with the app.

Website analytics

This product website uses Vercel Web Analytics to measure aggregate visits and page usage. The website does not receive or process the Personal Access Token stored by the iOS app.

Feature requests and votes

The feature-request board is public. Publishing a request requires a Clerk account, and we associate the request with your account so we can prevent abuse and administer the board. Voting does not require an account. The website stores a random browser identifier as a one-way hash to limit each browser to one vote per request. Do not include credentials or other sensitive information in a feature request.

Support and sensitive information

Never submit Personal Access Tokens, passwords, API keys, webhook secrets, or other credentials in a support message.