Installing PrivacyFence

This installs PrivacyFence to /Applications and, since it needs an administrator password anyway, also sets it up to run independently of any AI client on this Mac:

This is the same change described in this project's ADR 0002 and issue #428 — it can be reversed at any time from Terminal with sudo /Applications/PrivacyFenceApp.app/Contents/Resources/scripts/macos_privilege_separation.sh disable.