Do not include screenshots, OCR output, clipboard contents, credentials, or other sensitive information in a security report.
Report security issues privately to the project maintainer.
TextGrab is a local macOS menu-bar application. Its core workflow is:
User-selected screen region -> ScreenCaptureKit -> Apple Vision OCR -> NSPasteboard
Screen Recording permission is required to capture pixels. Accessibility permission is optional and is used only for enhanced system keyboard integration. These permissions are controlled by macOS TCC and are associated with the installed application identity and location. Users should install TextGrab in /Applications, grant permissions to that copy, and relaunch after granting Screen Recording.
Local builds use an ad-hoc Hardened Runtime signature with the screen-capture entitlement embedded. This supports local permission testing but is not a distributable security identity and will not pass Gatekeeper. Production releases must use a Developer ID Application certificate and Apple notarization.
TextGrab should:
- keep OCR local
- avoid logging screen contents
- avoid logging clipboard contents
- minimize retained data
- avoid unnecessary network access
- Screenshots exist in memory only for the capture and OCR operation.
- OCR output is copied to the local pasteboard and is not uploaded.
- Clipboard history is optional, bounded, and disabled by default. When enabled, history is persisted to UserDefaults locally and survives app relaunches; disabling it clears the current history.
- Apple Intelligence correction, summarization, and compaction are optional and use the on-device macOS model when available.
- TextGrab has no telemetry, analytics, account service, or cloud OCR dependency.
Logs may contain state names, counts, timings, and generic platform errors. They must never contain screenshots, OCR text, clipboard payloads, passwords, API keys, document contents, or Apple Intelligence prompts/responses.
Before distribution, verify:
- Release signing uses
Developer ID Applicationand Hardened Runtime. - The signed app contains only the required entitlements.
codesign --verify --deep --strictsucceeds.- The DMG is notarized, stapled, and passes
spctlon a clean Mac. - Screen Recording and Accessibility grants work after a clean install, revoke/regrant, and relaunch.