← Notes

How to audit what an app sends home

You do not have to trust a privacy policy. Three tools on a Mac will show you exactly what an application contacts, and the whole audit takes about ten minutes.

Privacy policies are written by people with an interest in the outcome. The good news is that on a Mac you can check for yourself, and the methods are neither difficult nor expensive.

Here they are, roughly in order of effort.

1. Read the entitlements (thirty seconds)

If an app came from the Mac App Store it is sandboxed, and its capabilities are declared in advance and enforced by the system. In Terminal:

codesign -d --entitlements - /Applications/Something.app

The line that matters most:

com.apple.security.network.client

If it is absent, the app cannot make outgoing network connections. Not "does not" — cannot. The kernel refuses. No update, bug or compromised dependency works around it without a new App Store review.

Other entitlements worth noticing: files.all (broad filesystem access), personal-information.addressbook, device.camera, device.microphone. Each should correspond to something the app visibly does.

This method is fast and definitive when the answer is "no network entitlement". It tells you less when the entitlement is present, since most apps legitimately have it.

2. Watch the connections (ten minutes, definitive)

An outbound firewall shows you every connection an app attempts, with the destination, live.

Little Snitch is the established commercial option. LuLu, from Objective-See, is free and open source and does the core job well.

The method:

  1. Install one. Set it to alert on new outgoing connections.
  2. Quit everything else you can.
  3. Launch the app you are auditing.
  4. Use it normally for ten minutes — open a file, run its main feature, change a setting.
  5. Read the list of connections it attempted.

What you will see:

  • Nothing at all. The strongest possible result.
  • Apple domains only — apple.com, icloud.com, mzstatic.com. Usually receipt validation, software update checks or system services. Normal.
  • The developer's own domain. Could be a licence check or an update check, both reasonable. Could also be telemetry. The domain alone does not tell you which.
  • A third-party analytics or crash-reporting service. Now you know something the privacy policy may not have said clearly.
  • An advertising or attribution network. In a paid utility, this warrants an explanation.

The valuable part is that this catches things no document mentions, including connections the developer inherited from a dependency and may not know about.

3. Check the bundled frameworks (two minutes)

Right-click the app → Show Package Contents → Contents/Frameworks.

Analytics and crash-reporting SDKs appear here under recognisable names. This tells you what is present, which is a useful complement to what is contacted — an SDK can be bundled and dormant, or active and phoning a domain you did not recognise.

4. Read the App Store privacy label correctly

It is on every App Store listing, and it is self-declared by the developer. Weigh it accordingly:

  • "Data Not Collected" is a strong, specific, falsifiable claim.
  • A list of categories marked "Not Linked to You" means collection is happening and the developer asserts it is not tied to your identity. Much weaker.
  • "Used to Track You" means the data is shared with third parties for advertising or measurement.

The label is a starting point and should agree with what your firewall saw. If it does not, believe the firewall.

What normal looks like

So you can calibrate: it is entirely reasonable for a well-behaved app to contact Apple for receipt validation, to check for updates on the developer's domain, and — if it has a genuine online feature — to reach the service that feature needs.

What should make you look harder: analytics services in an app with no reason for them, connections that happen when the app is idle, traffic to domains unrelated to either the developer or Apple, and any of the above in an app you paid for.

Auditing ours

The commands above work on our apps and we would rather you ran them than took our word.

RenameDeck has no network entitlement at all — the first check returns nothing and there is nothing for a firewall to see.

Ziploom has no accounts, analytics, advertising, telemetry or network features. ClackSmith carries no advertising or analytics and requests neither Input Monitoring nor Accessibility. Compact Contacts has no developer-operated backend and no app account. Miyu Paint and Garfi do their work on your device.

What a firewall will show for some of them: Apple domains, for purchases and receipt validation. Garfi may involve Apple's speech recognition service for automatic captions when on-device recognition is unavailable — that is a system service, and it is audio going to Apple.

And the exception that is not an app: this website runs Google Analytics. Your firewall will see that, correctly. The apps do not.

If you audit one of our apps and find something this page does not describe, we would genuinely like to hear about it.

Keep reading