Privacy Policy
Effective date: August 13, 2026
Jarl is a native macOS app for managing Jamf Pro instances. It is designed to run entirely on your Mac, without a backend server operated by us. This page explains what data Jarl handles and how.
What Jarl does not do
- Jarl does not collect analytics, usage statistics, or crash reports.
- Jarl does not use tracking technologies or third-party advertising SDKs.
- Jarl does not send your data to any server operated by us — there is no Jarl backend.
- Jarl does not require or use a Jamf user account or SSO login.
Data Jarl handles
Jarl authenticates directly against the Jamf Pro instance(s) you configure, using OAuth 2.0 client credentials (an API client ID and secret that you generate in your own Jamf Pro environment).
- API credentials — stored locally in the macOS Keychain on your Mac, encrypted by the operating system. They are never transmitted anywhere except directly to the Jamf Pro server you configured.
- Jamf Pro data — device inventory, policies, smart groups and related records are fetched directly from your Jamf Pro instance over HTTPS, and are only cached in memory or on-disk locally for the app to function. This data is your organization's data, and Jarl does not have access to it beyond what you configure the app to request.
Third parties
Jarl's core functionality only talks to the Jamf Pro instance(s) you explicitly add. Two optional features involve other parties:
- Community Playbooks — if you choose to browse or import a shared playbook, Jarl fetches it from a public GitHub repository. This only happens when you open that feature.
- AI Assistant — the in-app assistant runs on Apple's on-device Foundation Models framework. Processing happens locally on your Mac via Apple's system frameworks; it requires Apple Intelligence to be enabled and is not used otherwise.
Jarl can also optionally run a local MCP (Model Context Protocol) server, off by default, bound to 127.0.0.1 only — it accepts connections from AI tools running on the same Mac, not over the network, and only if you explicitly enable it.
Your control
You can remove a configured organization — and its stored credentials — from within the app at any time. Uninstalling Jarl removes its local data.
Changes to this policy
If this policy changes, the updated version will be posted on this page with a new effective date.
Contact
Questions about this policy can be sent to marian@spectrechen.de.