What stays on your Mac
lohost reads process and port information on this Mac and never sends it anywhere. The only request it makes is the update check.
Last changed 28 September 2026. This page changes together with the code it describes.
- What lohost reads
- Secrets
- The update check
- Server logs
- What there is none of
- What lohost keeps
- Questions
What lohost reads, and where it goes
Everything below is read on your Mac, as you, and stays there. None of it is sent to lohost.dev or to anyone else.
| What | Read from | Why |
|---|---|---|
| Listening sockets | macOS, through lohost’s own helper: which processes listen on which ports and addresses, and who is connected to them from this Mac | The list itself, and “open to your network” |
| Processes | The same helper: each listening process’s command, working folder, parent, start time, memory and CPU time | What a server is, how long it has run, who started it |
| Environment keys | The environment of those processes, cut down in the helper to a fixed list of keys lohost uses, such as the markers agents set (CLAUDE_CODE_SESSION_ID, CODEX_THREAD_ID), TERM_PROGRAM, PORT and npm_lifecycle_event | Who started it, and which script |
| Git | The server folder’s .git/HEAD and worktree links; git status only while you look at one server’s details | The project and the branch |
| Agent sessions | Claude Code’s, Codex’s and Cursor’s own files about their sessions, read-only | The session’s name, and whether it has ended |
| Docker, launchd, ssh | Docker’s API over its local socket; launchctl print; ssh’s arguments | Containers, jobs and their restarts, tunnels |
| Agent configurations | MCP settings such as ~/.claude.json and ~/.codex/config.toml: the commands and local addresses in them, never credentials | Which MCP server a tunnel or a port is for |
| Your servers | A server that cannot be named from its command may get one check at your Mac’s own address, 127.0.0.1: a connection, and for a web server one request for its home page’s title. Known frameworks are never asked. | What the server is |
lohost never checks your servers at your network address or anyone else’s, so it never talks to another device on your network.
Secrets
- Dropped before the app sees them. The helper leaves out every environment variable whose name contains
TOKEN,SECRET,KEY,PASSWORDorAUTH, whatever the list of keys says. - Values are never saved. The keys lohost reads are held in memory for the list and dropped when the server goes away. In the servers window, values stay masked until you click one.
- One full read, only on Stop. When you stop a server, lohost reads that one process’s whole environment once, and keeps it in memory only, so the server can be started again the same way. It is never written to disk.
- Configurations for commands, not credentials. Agent and MCP settings files can hold tokens in plain text; lohost reads only the commands and the local addresses in them.
The update check
Copies downloaded from this site or installed with Homebrew check for updates 30 seconds after they start and then about every 6 hours, when your Mac wakes if the last check was 6 hours ago or more, and whenever you choose “Check for updates”. Each check is one HTTPS request to dl.lohost.dev for a small file, latest-mac.yml (or beta-mac.yml on the Beta channel), with a number from the clock added to the address so no cache answers instead. When there is an update, that file carries its release notes too.
The request carries no account, and neither your version of lohost nor your version of macOS: its user agent is the generic electron-builder. Like every connection, it comes from your IP address. The update library can add an installation number to each check; lohost sends the same all-zero value from every copy, and the server deletes that header before anything is written.
When there is an update, the download names what it fetches: the new version for your Mac’s chip (lohost-0.2.0-arm64.zip, for example), and, after the first one, small index files (.blockmap) so only the changed parts are fetched.
Server logs
Caddy, the web server behind lohost.dev and dl.lohost.dev, writes every request to an access log: the time, the IP address, the address requested and the request headers, such as the user agent. Caddy leaves cookies and authorization headers out, and deletes the installation number described above. The public pages set no cookies. The only cookie on lohost.dev belongs to the owner’s admin page: it is set when the owner signs in, and for no one else.
The log is closed and a new one started every day at 00:00 UTC, and whenever it reaches 10 MiB. Closed logs are deleted 7 days (168 hours) after they were closed. So a line is on disk for at most about 8 days.
A program on the same server reads the log as it is written and turns it into counts: visits, downloads and update checks per hour and per day, by page, referring site or link tag (the ?ref= in a link), country, language, version and chip. A disk image fetched from a phone is counted as a tap, not a download. It looks each address up in a country database stored on the server; it keeps the country, not the address. Hourly counts are kept for 90 days and daily counts for 13 months, and download and install totals for as long as lohost exists. Beside the counts it keeps two things, on that server only: the last 48 hours of requests, in memory, with each address cut to its first two numbers (203.0.x.x); and, for requests that probe for weaknesses, the block of 256 addresses they came from, for 30 days. Nothing is shared, sold or sent anywhere else.
Country data: IPinfo Lite (CC BY-SA 4.0).
What there is none of
- No lohost account, and no sign-in to lohost itself.
- No analytics script or service, telemetry, crash reporter or advertising identifier, in the app or on this site. The counts under Server logs are made on this site’s own server, from its own log.
- No remote content in the app: its windows may not load anything from the network.
- No scripts, cookies or third-party requests on this site’s public pages. Their fonts are served from
lohost.devitself.
What lohost keeps
What lohost writes is in its own folders:
~/Library/Application Support/lohost— your settings;lohost.sock, the socket thelohostcommand, the MCP server and the plugin’s hooks talk to;servers.json, the last list, so the command can answer while the app starts; and a small database of the servers you kept, stopped and gave a port to, with their command and folder — never an environment value;~/Library/Logs/lohost— a log of what lohost did, with your home folder written as~, and the output of servers lohost itself started again for you;~/Library/Caches/lohost-updater— the last update, so the next one can fetch only what changed;~/Library/Preferences/dev.lohost.app.plist— what macOS keeps for every app.
Outside them, lohost writes only what you ask it to: the Claude Code plugin’s files and its entry in Claude Code’s settings, after showing you the change. Nothing in ~/.claude, ~/.codex, Cursor’s folders or your projects is ever deleted or changed by reading it. Uninstalling lists what to remove.
Questions
lohost is made by Deokwon Song. Ask about this page, or report something it gets wrong, at github.com/lohost-dev/lohost/issues.