Shrink Books

Privacy Policy

Last updated August 25, 2026. Applies to Shrink Books for macOS and the iPhone companion.

Your books stay on your own computer. There is no Big Tree Publications server, no account to create, and no copy of your practice records anywhere we can reach.

Shrink Books holds some of the most sensitive material a practice produces, including clinical notes. So this page is written to be accurate rather than reassuring. It says exactly where your data sits, the three specific occasions when something leaves your machine, and what we never collect at all.

Where your data lives

Your books are kept in a single encrypted file on your own Mac, using AES-GCM encryption. The key to that file is held in your macOS Keychain, under your account, not in the app and not anywhere we can see.

The app keeps backups locally, alongside your books: one for each of the last thirty days, then weekly ones going back a year. You can also nominate a second backup folder, which is entirely your choice of location. Delete the app and its data folder and the records are gone.

The only three times anything leaves your device

The entire app contains three external destinations and no others: api.anthropic.com, api.stripe.com, and links that open stripe.com in your browser. Each of the three features below is optional, and none of them sends anything to Big Tree Publications.

1. iCloud sync, if you turn it on

Sync is off unless you switch it on. When it is on, the encrypted file syncs through your own iCloud account, inside the app's private container there. If you set sync up before that container existed, it may still be using a folder in your iCloud Drive instead; either way it stays inside your own iCloud. The file is encrypted before it leaves your device, so what sits in iCloud is unreadable to us, and we have no access to your iCloud account in any case.

To read those books, the iPhone companion needs the key. It gets it either through your iCloud Keychain, or by scanning a pairing code that the Mac app can display. One caution about that code, which the app also gives you on screen: it contains your key, so anyone who photographs it could read your books. Do not show it on a shared or screen-shared display.

2. Card payments, if you use them

Taking card payments is optional and runs through Stripe using your own Stripe account. You supply your own Stripe secret key, which is stored in your Keychain. Charges go directly from the app to your Stripe account, so the money never passes through us. We never see your Stripe key, your clients' card details, or your revenue. Card numbers are typed by your client on Stripe's own pages and are never entered into the app.

3. The AI features, when you press the button

The AI features never run on their own. They run when you press a button, and not otherwise.

Before any text leaves your machine, it is pseudonymised on your Mac: client names are replaced with stand-ins such as "Client-1" and "Client-2", and email addresses and phone numbers are stripped out. Only that pseudonymised text is sent, over an encrypted connection, to Anthropic's API. When the result comes back, the real names are put back in locally, on your machine.

Two things worth being straightforward about. During the beta these requests use a Big Tree Publications API key, which means the bill for them comes to us, although the content was pseudonymised before it was sent. You can enter your own Anthropic key instead if you would rather the requests be entirely yours. And Anthropic does not train its models on content submitted through its API.

What we never collect

There is no analytics or telemetry of any kind in this app. No Firebase, no Sentry, no Mixpanel, no Amplitude, no Crashlytics, nothing of that sort. The app does not phone home, does not count launches, does not report crashes to us, and does not tell us that you are using it.

There is no account to sign up for, so there is no profile of you to hold. We hold no copy of anyone's books, no client list, no notes, and no financial records.

Permissions the app asks for

Each of these is optional, is requested by macOS with a reason shown, and can be refused or withdrawn without breaking the rest of the app.

Calendar. Reads the calendars you choose, on your device, so it can spot appointments that look like sessions worth adding to your books. Nothing about your calendar is sent anywhere.

Contacts. Fills in a client's email, phone, and address from your own address book, matched by name, so you do not have to type them twice.

Mail. Sends the invoices and reminders that you ask it to send. If you turn the payment scanner on, it also reads payment receipt emails from Venmo, Zelle, and PayPal, on your machine, so those payments can record themselves.

About HIPAA

Shrink Books is built so that clinical information stays on equipment you own and control: encrypted on your own Mac, under your own Keychain key, with no copy held by us and no third party in the middle. That design is what makes it usable in a practice that handles protected health information.

What this page will not tell you is that the app "is HIPAA compliant". Compliance is a property of a practice, not of a piece of software: it depends on your policies, your devices, your training, and your agreements. No app can confer it on you. We also do not offer a Business Associate Agreement. If your situation requires one from every vendor that touches client data, please take that into account before adopting the app, and note in particular that the optional AI features send pseudonymised text to Anthropic.

Changes and questions

If this policy changes, the new version will be posted at this address before it takes effect. Questions are welcome through the contact form, and a real person answers them.

Shrink Books is made by Big Tree Publications.