Your unreleased roadmapstays on your Mac

Product owners and analysts handle the most sensitive text in the company: unshipped features, customer data in tickets, roadmap decisions. Khint runs AI text actions from one shortcut without turning that into a chat archive: only the text you select leaves, Memory stays on-device, and you can bring your own key.

For product owners and business analysts. macOS and Windows, menu-bar app. No background recording.

The convenient tool
is often the leaky one

The fastest way to clean up a spec is to paste it into a browser chatbot, and now your unreleased feature is a line in someone else's account history. The private way is usually the slow way: strip the identifiers, keep a local copy, don't leave a trail. Khint collapses that trade-off. It sits behind one palette shortcut and its three pillars (Agents, Capture, and Memory) are built so the private path is also the default path, with nothing about your work leaving the device silently.

Exactly what leaves, and what never does

Five checkpoints between your keyboard and the model.

  1. Select the text, and only that text leaves

    Khint's privacy default is strict: an Actiononly ever sees the text you highlighted, nothing else on screen. Select the rough spec paragraph, hit Cmd+Shift+K, run “Tighten this”, and the cleaned version is pasted back in place. No window scraping, no clipboard trawling: the selection is the whole payload.

  2. Memory context is local and opt-in

    Start a Memorysession for the task and Khint keeps a short, compacted summary that rides along on each Action so you stop re-explaining yourself. That summary lives in a local SQLite file on your Mac. It is never synced to Khint's servers, and any Action can turn it off when the session would be noise. Stop the session and the context is closed.

  3. Bring your own key to skip the proxy entirely

    Add a personal Anthropic API key in Settings and it is stored in the macOS Keychain. With a key present, AI Actions call Anthropic directly instead of routing through Khint's backend. Your Mac talks to the model and back, with no Khint server in between. Prefer the default? The managed proxy works out of the box with the same tiny selected-text payload.

  4. Redact PII before it is sent

    Handling a ticket full of a customer's email and phone number? Flip the per-Action Redact PII toggle (off by default) and Khint replaces emails, phone numbers, SSNs, and IBANs with placeholders before the text is forwarded for processing. You keep the useful shape of the request without shipping the identifiers.

  5. Capture and history stay on the device

    Capture never records your screen in the background. It fires only when you ask, using the system screenshot UI. Your action history lives in local SQLite; even when you sign in for cloud sync, the input and output bodies of each run stay on-device and only metadata leaves. Read the full security posture →

Private, but still wired into your tools

Local-first does not mean cut off. When you connect Atlassian or Linear, writes go one issue at a time and each push is explicit: you see what is filed, nothing batches silently. Integrations and the bundled MCP server let Claude Desktop or Codex read your active session, but writes need an explicit OS notification, so no context is injected behind your back. The privacy posture holds whether you work alone in a doc or push a refined ticket to Jira from anywhere.

Common questions

What actually leaves my Mac when I run an AI Action?

Only the text you selected (plus, if you opted in, the compacted summary of your active Memory session). That is the entire payload. Khint does not read your other windows, your files, or your clipboard history, and there is no always-on capture. A product owner drafting an unreleased feature can select one paragraph, run an Action, and know that paragraph is the only thing that was ever sent for processing.

How is this safer than pasting into a browser chatbot?

When you paste an unreleased roadmap or a customer's requirement into a consumer chatbot, the whole thread lives in that product's account history and, depending on the plan, may be eligible for training. Khint keeps the surface tiny: one selection per run, no persistent chat log of your specs, and your reusable prompt (the Action) stays on your machine. You are not building a searchable archive of your confidential product work inside someone else's app.

Can I use my own Anthropic key so nothing goes through Khint's servers?

Yes. Khint supports bring-your-own-key: add a personal Anthropic API key and it is stored in the macOS Keychain. When a key is present, AI Actions call Anthropic directly instead of routing through Khint's proxy. The request goes from your Mac to Anthropic and back, with Khint's backend out of the path. BYOK is Anthropic-only today.

Does Khint record my screen or sync my session notes to the cloud?

No background recording. Capture only runs when you trigger it from the palette, and on macOS the screenshot is taken by the system's own screenshot UI, not by a Khint screen-capture API. Memory sessions live in a local SQLite database on your Mac and are never synced to Khint's servers. Sign out and your sessions still work offline. If you sign in, packs and a history index sync so a fresh install can hydrate, but the input and output text of every action stays on-device; only metadata like timestamps and action names leaves.

Fast AI, without the paper trail

Free with 10 AI actions and 5 captures per day. No credit card. Only the text you select ever leaves your Mac.