There is no guarantee that this software will not occasionally start acting as a keylogger. If somehow this happens (let's assume not intentionally), will it be the direct responsibility of the author?
Legally, there is no entity behind that responsible for privacy (1), and honestly, I don't see even minimal reason to trust this software from a legal perspective.
Apple provides a network client entitlement[1] that sandboxed apps must have, to connect to the network. Since this app isn't sandboxed, that restriction doesn't apply.
Personally, I only use software that was either built on my machine or downloaded off of the Mac App Store (MAS apps have the be mandatory sandboxed).
Well, I understand the security benefits of sandboxing. However, Apple's sandbox restrictions prevent apps from using Accessibility APIs, which are essential for Refine to read and enhance text across different applications.
Many popular apps, like Grammarly and Raycast, are also not sandboxed for the same reason. Without these APIs, Refine wouldn’t be able to provide a seamless text refinement experience. Otherwise, why wouldn’t we just use ChatGPT to correct the grammar?
Not at all. Most commercial software has a publisher (as legal entity) that is responsible for privacy and takes reputational risks if something goes wrong.
Is your objection that he is distributing this by himself, instead of through the app store? Or that it appears that he is doing it as an individual instead of a company?
Sure, it's a little sketchy, it's a guy with a website and a privacy protected domain and that's about it. But if anything were to happen you would be suing the developers of refine.sh.
I guess I do see your point though. For my software I have indeed created a legal entity and can be easily looked up.
Legally, there is no entity behind that responsible for privacy (1), and honestly, I don't see even minimal reason to trust this software from a legal perspective.
1. https://refine.sh/privacy-policy