Markover docs
Guide

Reference

Privacy, storage, and recovery

Markover keeps ordinary review work on your Mac. This page explains the account boundary, stored data, deliberate network actions, backups, reinstall, deletion, and reset.

Local means your macOS account

Markover stores reviews and runs its loopback API inside the current macOS account. Each account—including accounts active through Fast User Switching—runs an independent Markover instance with separate data, endpoint records, and credentials.

The application-data directory is restricted to its owner on supported macOS systems. A process running as another ordinary account can connect to loopback but cannot read Markover's protected capability, so the API denies it.

The trust boundary is the OS account. Other processes running as you, system administrators, and root can ordinarily read your files or credentials and remain inside this boundary. Markover does not claim to isolate data from them.

How the local API is protected

Markover's command-line tool and desktop app communicate through a loopback service available only on your Mac. Each running service uses a fresh secret stored inside the protected data area for your account. Review operations require that secret.

This prevents another ordinary macOS account from using your service credential. It does not create isolation from another process running as you, an administrator, or root. Rejected-request logging is off by default and, when enabled, omits credentials, request contents, queries, and review content.

Contributors and interested readers can inspect the optional technical security and protocol reference. You do not need those mechanics to use Markover.

Optional remote client

Allow the authorized remote Markover client is off by default. When you enable it on canonical Markover, Tailscale Serve can carry review commands from the one tailnet host you authorize into the same Markover app, settings, and review store on this Mac. The gateway binds only to loopback and requires the exact Tailscale application capability plus cryptographic proof of a separate secret protected to your account on each Mac. The secret itself is not sent with requests. Markover does not configure your tailnet policy, drive Tailscale login, expose a Tailscale-IP listener, or enable Funnel.

The remote path can receive the complete requested Markdown source, its source path, checksum, review purpose, and agent-supplied Git, pull-request, and thread provenance. Lifecycle commands can return review source, feedback, source-edit proposals, attachment metadata, and provenance to that authorized host. A remote handoff replaces each checked screenshot's canonical file path with a short-lived private HTTPS URL scoped to that attachment and running gateway. Downloading it requires the Tailscale authorization; Markover verifies the managed file's location, length, type, and checksum before returning authenticated bytes. Restarting the gateway invalidates outstanding attachment URLs.

A remotely supplied source path is only a locator for the returning agent. Canonical Markover marks its source and project state unavailable and does not read that path or run Git beside it, even if the same absolute path exists on this Mac.

Your Tailscale hostname is public certificate metadata. Tailscale HTTPS certificate issuance records the canonical machine name in public Certificate Transparency logs. Choose a machine name that contains no sensitive information.

Disabling the setting closes Markover's private loopback gateway after its current bounded request finishes. The same Tailscale Serve configuration cannot reach Markover again until you re-enable it. Another ordinary macOS account can connect to loopback but cannot authenticate without the protected gateway credential; processes already running as you, administrators, and root remain inside the account trust boundary.

What Markover stores

A review can contain the complete Markdown source, parsed document structure, annotations, source-edit proposals, attachment files and metadata, review state, and timestamps. Proposed source edits stay in the review; Markover does not apply them to the original Markdown source.

When available, provenance can include the source path, a sanitized Git remote, branch, commit, pull-request number, and the requesting-session ID with the agent-supplied thread-host snapshot. Working directories, parent or fork details, selected session-log paths, matched log content, and private title or T3 correlation data stay out of the portable review.

Local does not mean safe to publish. Review JSON, attachments, and otherwise legitimate command output can contain private content and identifying paths or IDs. Inspect or sanitize them before sharing.

Where data lives

Persistent reviews, attachments, settings, and temporary local-service records live under:

~/Library/Application Support/Markover/

Managed reviews use one directory per review under reviews/<review-id>/. The downloaded application cache is separate:

~/Library/Caches/Markover/

Removing the cache forces a later launcher command to download Markover again. It does not remove persistent reviews or settings. Removing Application Support is destructive user-data deletion, not a reinstall step.

Local provenance discovery

Markover may run read-only Git commands beside the reviewed source. The portable review retains the sanitized remote URL, branch, and commit reported at opening time; URL credentials, query strings, fragments, and local repository roots stay out of the handoff. App-private workspace state may retain a local project-grouping key.

If an agent supplies a unique handoff key but no explicit thread ID for an open or reviewer claim, Markover can search a bounded set of recent local Codex or Claude session records for an exact match. It retains the matched requesting-session ID with the thread-host metadata the agent supplied, not a copy or path of the scanned logs.

This search is enabled by default. Turn off Discover agent thread from local session logs in Markover's Privacy settings to skip it on subsequent open or get-for-review commands. Explicit thread IDs and Git provenance remain available.

The separate Read current titles from T3 integration is disabled by default. When enabled, Markover reads the current title for known requesting-thread IDs from ~/.t3/userdata/state.sqlite, or from the metadata database override in Settings. Titles are kept in memory only, are not copied into portable reviews or local-agent responses, and fall back to the review purpose or thread ID whenever the source is unavailable. Markover refreshes on launch, review arrival, foregrounding, Inbox or Projects activation, and the explicit Refresh titles now action; it does not poll or watch the database.

The separate Read current titles from Codex integration is also disabled by default. When enabled, Markover starts the configured Codex executable only during an existing refresh event, initializes app-server, and reads each known Codex provider thread by its exact ID. It does not list conversations, infer a title from prompts or previews, poll, or watch Codex state. Codex titles and the executable location stay private and in memory; a current T3 thread-host title takes precedence over a Codex provider title.

The Read current titles from Claude Code integration is disabled by default too. When enabled, Markover uses each known Claude provider session ID to find one exact top-level session artifact under ~/.claude/projects, then reads only dedicated custom-title records for that same ID during existing refresh events. It does not infer titles from prompts or messages, search other Claude products, poll, or watch Claude state. Claude Code titles and artifact locations stay private and in memory; a current T3 thread-host title takes precedence over a Claude provider title.

When an agent retrieves a review

An authenticated get returns the review source, annotations, attachments metadata, provenance, and agent guidance to the requesting local agent. Markover itself does not upload that handoff.

After another agent or tool receives the data, its storage, logging, sharing, and network behavior are outside Markover's control. Apply that recipient's privacy policy and trust model as well as Markover's.

Durability and recovery

While Markover is responsive and local storage is healthy, managed review changes are durably saved within a two-second window by default. After an app-process crash or restart, Markover restores reviews still being edited and reviews already inflight with an agent. Attachment bytes are saved before a review can durably refer to them.

A persistent autosave warning means a save failed or took too long, so the two-second bound is suspended while Markover retries or waits for storage to recover. If a normal quit cannot finish saving within five seconds, Markover lets you retry the quit, cancel it, or quit anyway. Choosing Quit Anyway can discard changes that have not become durable.

The crash window has limits. It does not cover power loss, operating-system or hardware failure, or unhealthy or unusually slow storage. Keep backups of important review data even when no warning is visible.

Advanced: change the autosave window

The setting is intentionally not in Markover's Settings window. Quit Markover, open ~/Library/Application Support/Markover/settings.json, set autosaveMaximumDelayMs to a whole number from 100 through 60000 milliseconds, then restart Markover. Changing it changes the stated maximum-loss window as well as the save timing.

When the internet may be used

Ordinary review handling has no telemetry, analytics, cloud synchronization, or automatic upload of review content. The only review-ingress exception is the remote client you explicitly enable and authorize through Tailscale; it sends the review you requested to this Mac's canonical store.

Launcher installation and update installation are user-triggered connections. The bounded canonical changelist check is automatic, so Markover does not claim that it never connects to the internet.

Retention and deletion

Managed reviews and attachments remain until you remove them. To remove the active managed review, choose Review → Move Review to Trash…; the same action is available from review tabs and the Documents list. Markover moves its complete managed-review directory, including attachments, to the macOS Trash without changing or deleting the original Markdown document.

Removing an attachment from a managed review also moves its owned image file to the Trash after the updated review is safely saved. Review → Clean Up Unused Attachments… reports the number and size of generated attachment files no longer referenced by any valid managed review, then asks before moving them to the Trash.

Back up a managed review first when it matters. Managed-review data remains recoverable from the Trash until you empty it. Open Markdown… creates a managed review, so locally opened documents and their screenshot attachments use the same storage, recovery, and cleanup lifecycle.

Redownload or reinstall without deleting reviews

  1. Quit Markover.
  2. In Finder, choose Go → Go to Folder… and open ~/Library/Caches/Markover/.
  3. Move that Markover cache directory to the Trash.
  4. Run the normal launcher command again. It downloads and verifies the matching app.

Your Application Support data, including reviews, attachments, and settings, remains in place.

Delete one review

  1. Select the managed review in Markover.
  2. Choose Review → Move Review to Trash…, or use the same command from its tab or Documents-list context menu.
  3. Read the confirmation carefully. A review currently with an agent receives a stronger warning.
  4. Confirm to move Markover's complete stored managed review to the macOS Trash.
Your original Markdown document is separate. Moving a review to the Trash does not change or delete the source file. The review and its attachments stop being recoverable after you empty the Trash.

Completely reset or uninstall Markover

  1. Quit Markover.
  2. Back up the complete Application Support directory if any review, attachment, or setting may be needed later.
  3. Move ~/Library/Application Support/Markover/ to the Trash.
  4. Move ~/Library/Caches/Markover/ to the Trash.
  5. If you manually downloaded or copied Markover.app, locate every copy you installed—commonly in Applications or Downloads—and move it to the Trash.

This removes all local reviews, attachments, settings, service state, launcher-cached app versions, and manually installed app copies for your account. Shared npm cache data is outside Markover's owned roots and is intentionally not part of this reset.

Backups and early-preview compatibility

Unreleased prototype review shapes may change without compatibility support. Once a review schema ships in a release, a later breaking release converts supported older schemas automatically on load. Before conversion, Markover preserves a byte-for-byte backup of the original review directory and replaces the active copy only after the converted review validates.

An app that encounters an unknown future version leaves its JSON and attachments untouched and points to the official compatibility catalog for a release that can open it.

Before changing versions, rolling back, or manually deleting data, quit Markover and copy the complete ~/Library/Application Support/Markover/ directory to a safe location. Keep Markover's migration backup if you may need to downgrade.

Get help without oversharing

Use GitHub Discussions for usage questions and general support. Use the bug report form for a reproducible defect and private vulnerability reporting for a suspected security issue.

Share only the smallest sanitized diagnostic needed. Remove credentials, private review content, repository details, usernames, local paths, and identifying IDs.