Templeton Protect is a security tool that reads sensitive things. Here is exactly what it touches, and what it does not.
There is no account, no sign-in, no analytics, no telemetry and no crash reporting. The scanner has no network client in it at all. Findings, file paths, credentials, your code and the contents of your AI conversations are read on your machine, shown on your machine, and never transmitted anywhere.
The app checks whether a newer version exists. That is an HTTPS request to
templetongroup.dev for the same update file listed on the download
page, and it carries only the version you are currently running — nothing about
your machine, and nothing about what was scanned. System profiling is explicitly
switched off, and the app asks your permission before it starts checking
automatically. You can turn it off at any time and the scanner keeps working.
It does not read your email, your browser history, your documents or anything else outside those places.
Nothing, until you click a fix. Scan history is stored on your own machine under
~/Library/Application Support/Templeton Protect, readable only by your
account. Reports go where you point the save panel.
Every finding, export and notification has the credential blanked out before it is shown. A report that carries the key it found has copied that key somewhere new, which is the exact failure this tool exists to catch.
The scanning engine is MIT-licensed and public. Every claim above is checkable in the source at github.com/templetongroup/templeton-protect.
Write to hello@templetontech.com.