Walnut
Docs About Install Language Licenses Community Get started

Legal

Privacy Policy

Last updated: July 30, 2026

This Privacy Policy explains how Walnut (“we,” “us”) handles information when you use walnutlang.com, docs.walnutlang.com, packages.walnutlang.com, community.walnutlang.com, related websites, the package registry, the licensed community forum, and commercial license flows (the “Services”). It also describes what the local toolchain typically keeps on your machine.

Contact: [email protected] or [email protected].

1. Scope

This Policy covers information we process as operator of the hosted Services. It does not cover:

  • Data inside applications you build with Walnut (those apps are yours; you are the controller for your users)
  • Apple, Homebrew, Git hosts, analytics you add to your own apps, or other third parties with their own policies
  • Self-hosted registries you operate (you are responsible for that processing)

2. Information we collect

2.1 Information you provide

  • Account data for the package registry: email address, password (stored hashed), optional display name, organization membership
  • Billing and commercial seat details when you purchase or are granted Commercial entitlements (processed as needed to issue and renew seats; payment processors may receive card or invoice data if/when payments are enabled)
  • Package publishes: package name, version, metadata, and tarball contents you upload
  • Communications: messages you send to support or legal addresses
  • License requests: organization slug and account identity used to issue signed license files

2.2 Information collected automatically

When you access hosted Services we may log:

  • IP address, approximate location derived from IP, user agent, timestamps
  • Request paths (for example API calls to list or download packages)
  • Basic diagnostic and security logs (failed logins, rate limits, errors)

Static documentation and marketing pages may be served with standard web server logs. We do not require an account to read public docs.

2.3 Local toolchain and registry telemetry

The Walnut CLI and related tools may store data locally under paths such as ~/.walnut/ (for example credentials, license files, preferences). Signing keys, App Store Connect API keys, and development certificates you configure for device or TestFlight flows are intended to remain under your control. Do not send secrets to us unless a specific support process asks for redacted material.

When you are logged in to the package registry (walnut login), the CLI may also contact our servers for purposes beyond one-off publish/install commands, including:

  • Usage heartbeats (about once per hour while you use the CLI): CLI version and a machine fingerprint derived from hostname, OS username, and architecture, associated with your account so we can operate licensing, admin support, and abuse prevention
  • License issue / refresh and other registry API calls you trigger (login, publish, install, license download)

You can stop heartbeats by signing out (walnut logout). Local ~/.walnut files remain until you delete them.

2.4 Community and product signals

  • Community forum (community.walnutlang.com): topic and post content, votes, nicknames (display_name), and in-app notifications; optional email when someone replies to your topic (controllable on Account; default on)
  • Pricing / CTA clicks on marketing paths that land on the registry (source, tier, path, user agent — used to understand funnel interest)
  • Invite deliveries: when an admin sends you an invite email, we store the recipient address and send timestamp for delivery accounting
  • Optional willingness-to-pay on Account (after you have used the logged-in CLI): a price bucket and an optional one-sentence note. Used to decide if/when self-serve Commercial seats open. You can skip or change it.

3. How we use information

We use information to:

  • Provide, operate, and secure the Services (accounts, tokens, package hosting, license issuance)
  • Authenticate you and enforce seat and branding rules
  • Communicate about the Services, security incidents, and material Terms or Policy changes
  • Improve reliability and prevent abuse, fraud, and misuse
  • Operate licensing and seat enforcement (including CLI heartbeats when you are logged in)
  • Comply with law and enforce our Terms of Service

We do not sell your personal information.

4. Legal bases (where applicable)

If you are in a region that requires a legal basis (for example the EEA/UK), we process data as needed to perform a contract with you, to pursue legitimate interests in running a secure developer platform (balanced against your rights), and to meet legal obligations. Where consent is required, we will ask for it.

5. Sharing

We may share information with:

  • Infrastructure providers that host our sites, databases, object storage, email, or error monitoring, under obligations to protect data
  • Payment processors if you purchase Commercial seats through them
  • Professional advisors (legal, accounting) under confidentiality
  • Authorities when required by law or to protect rights, safety, and security

Package contents you mark or leave public are available to registry users by design.

We do not share personal information with third parties for their independent marketing.

6. Cookies and similar technologies

Hosted sites may use cookies or local storage strictly necessary for security, sessions, or load balancing. We do not use personal data from the Services to run third-party advertising networks on walnutlang.com.

First-party analytics. Marketing (walnutlang.com), docs (docs.walnutlang.com), and the package registry (packages.walnutlang.com) may record cookieless pageviews on our own servers: page path, host, referrer hostname, optional UTM parameters, client IP address, approximate location (country / region / city derived locally from IP), and a daily hashed visitor key. Location is resolved with a local MaxMind GeoLite2 database — we do not send your IP to a third-party geo API on each request. We respect browser Do Not Track (DNT: 1) by skipping the client beacon. This is not advertising measurement and is not shared with ad networks.

7. Retention

We retain account, package, and log data for as long as needed to provide the Services, resolve disputes, enforce agreements, and meet legal requirements. You may request deletion of your account subject to residual backups, legal holds, and data that must remain for integrity of published package history (for example yank records).

Local ~/.walnut files remain until you delete them.

8. Security

We use industry-reasonable measures (access controls, TLS in transit for hosted Services, hashed passwords, signed license files). No method of transmission or storage is perfectly secure. Protect your tokens and machines.

9. International transfers

We may process data in the United States and other countries where we or our providers operate. Where required, we use appropriate transfer safeguards.

10. Your rights

Depending on your location, you may have rights to access, correct, delete, or export personal information, or to object to or restrict certain processing. Contact [email protected]. You may also lodge a complaint with a supervisory authority where you live.

We will not discriminate against you for exercising privacy rights.

11. Children

The Services are not directed to children under 16. We do not knowingly collect personal information from children. If you believe we have, contact us and we will delete it.

12. Apps you ship

Walnut compiles your apps. End-user data collected by those apps is governed by your privacy policy and store disclosures. We do not receive that data through the toolchain unless you intentionally send it to our Services.

13. Changes

We may update this Policy by posting a new version with a revised “Last updated” date. Material changes will be highlighted by reasonable means when appropriate. Continued use of the Services after an update constitutes acceptance where permitted by law.

14. Contact

Privacy questions or requests: [email protected].
Legal: [email protected].

Related: Terms of Service, Licensing.

Walnut

Typed TEA for native iOS.

Product

Docs About Install Licenses Licensing Community

Build

Language Architecture Effects

Legal

Terms Privacy

© 2026 Walnut. Proprietary software. Terms · Privacy