Where keys and sign-in details are kept
Vixlo keeps two kinds of secret — the API keys you save under Cloud providers, and the details that keep this Mac signed in — and neither is ever written to a file you could find or travels to another Mac. Settings never shows a key back (the key rows show only a key's last four characters), nor what keeps this Mac signed in, this Mac's id or the licence. What the Account section does show is the email, a sentence and a word for where the account stands, and the three answers from sign-up. This page says where the secrets are, and what you will and will not see because of it.
The Keychain
Everything goes into the macOS Keychain, the same place Safari and Mail keep their passwords. One item per value:
- Each provider's API key, under Cloud providers.
- For your account: what keeps this Mac signed in, an id for this Mac, the licence the website sends, the latest time the website has reported, the time of the last successful check, the email on the account, and the three answers from sign-up.
- On a Mac that cannot give Vixlo an identifier of its own, one more: an id Vixlo makes for this installation, which stands in for it.
The password you sign in with is not among them. It is sent once, over an encrypted connection, when you press Sign in, and never stored on this Mac.
There is no other place in Vixlo a key can end up: never in a library folder, never in the app's own settings file, never in a log. The diagnostic log under Diagnostics does not carry secrets.
This Mac only
Every item is marked to stay on this device. It does not ride iCloud Keychain to your other Macs — a key or a sign-in leaves the house only when you type it there yourself — and it becomes readable only after this Mac has been unlocked at least once since it started up.
Never shown back
Once a key is saved, Vixlo shows you that it is there and its last four characters — Stored key ends in •••• 9f2a — and nothing more. There is no reveal button. The field you typed it into empties on Save, and the only way to get a different key on file is to type a new one; the only way to take it off this Mac is Clear. Signing out removes the account's items the same way, all except the id made for this installation, where there is one, which stays so that signing in again on this Mac is recognised as the same Mac.
Never a prompt
Vixlo never puts up the Mac's own Keychain panel asking you to allow it access, at launch or at any other time. A Keychain item it cannot read without asking is treated as if it were never there: you see the sign-in card, and nothing already stored is touched or deleted. A key it cannot write shows up as a line at the foot of the Settings window — Could not save the Anthropic key: and the Keychain's reason — never as a panel in your way.
The sign-in card can come back on a Mac you expected to stay signed in because Vixlo cannot read what it kept: an earlier copy of Vixlo, signed with a different identity, wrote those items, and the Mac counts them as another app's. Signing in again does not help. Vixlo will not write over an item it cannot read without asking, so the card shows the Keychain's own reason in a red-tinted line, you stay signed out, and the old items are left as they are. Write to support with that sentence.
When the website ends the session
The card also comes back, by design, when the website ends this Mac's session. At the next licence check the website refuses the Mac, Vixlo removes what kept it signed in, and the sign-in card covers the library window. Your libraries are not touched.
You sign in again and every library opens as before. What you sign in with depends on why the session ended:
- This Mac was removed on the account page: your email and password.
- The password was reset on the website: your email and the new password.
- The account was deleted: a new account, because the old one is gone. Deleting your account says what a new one starts with.
Signed out again, and the Keychain lists every reason and what each one needs.