← Notes

What "no third-party analytics" means in practice

Analytics SDKs collect more than page views and the app's own developers often do not know the full list. Here is what a typical SDK gathers, and how to check an app for yourself in about ten minutes.

"No third-party analytics" appears on a lot of app pages, ours included. It is a narrower claim than it sounds and worth unpacking, because the interesting part is what a third-party SDK does when it is there.

What an analytics SDK actually collects

Adding an analytics library to an app is three lines of code, and the default configuration collects considerably more than the events you deliberately log.

A typical SDK gathers, out of the box:

  • A persistent identifier for your installation, which survives app restarts and often app updates.
  • Device model, OS version, screen size, language, region, time zone, carrier and whether you are on Wi-Fi or cellular.
  • Session start and end times, and how long you spent in each screen.
  • Every screen you visited, in order.
  • Crash reports, which depending on configuration can include file paths, document names and fragments of memory.
  • An IP address at the server end, which is a coarse location whether or not anyone calls it that.

Some SDKs add advertising identifiers, some attempt to link installations across apps from the same vendor, and some offer "user properties" that developers fill with whatever they find useful.

The important structural point: this data goes to a company that is not the app's developer. Their privacy policy governs it, their retention schedule applies, their security posture protects it, and their business model determines what else happens to it. The developer has made a decision on your behalf about a third party you never chose.

None of this requires bad intent. Most developers add analytics to find out which features get used and where people get stuck, which are reasonable things to want to know. The default payload is simply much larger than the question being asked.

Why small utilities often skip it

For an app that renames files or unpacks an archive, the honest answer is that analytics would not change much. There is no funnel to optimise, no onboarding to A/B test, no engagement to maximise. The feedback loop that matters is email from people who hit a problem.

There is also a hard constraint that helps: an app distributed through the Mac App Store is sandboxed, and an app with no outgoing network entitlement cannot make a network connection at all. The system blocks it regardless of what the code attempts. That is a structural guarantee rather than a promise — and it is the strongest form this claim can take.

Checking an app yourself

You do not need to trust the marketing page.

Inspect the entitlements. In Terminal:

codesign -d --entitlements - /Applications/Something.app

Look for com.apple.security.network.client. If it is absent, the app cannot make outbound connections.

Watch the traffic. An outbound firewall — Little Snitch, LuLu — shows you every connection an app attempts, live, with the destination. Run the app for ten minutes and look at the list. This is definitive and it is the only method that catches everything.

Read the App Store privacy label, then weigh it correctly. It is self-declared by the developer, and the categories are broad. "Data Not Collected" is a strong, specific statement. A list of items marked "not linked to you" is much weaker — it means collection is happening and the developer believes it is not tied to your identity.

Check for bundled frameworks. Right-click the app, Show Package Contents, and look in Contents/Frameworks. Recognisable analytics vendors are visible there.

Where we stand, precisely

Our apps carry no third-party analytics. Some specifics rather than a blanket sentence:

  • RenameDeck is sandboxed with no network entitlement — it cannot transmit anything, by construction.
  • Ziploom has no accounts, analytics, advertising, telemetry or network features.
  • ClackSmith has no advertising or analytics, and no keyboard activity history.
  • Compact Contacts has no developer-operated backend, no app account, no advertising and no third-party analytics.
  • Miyu Paint has no account, advertising, analytics or tracking.
  • Garfi has no account, advertising, developer cloud backend or generative AI.

And the exceptions, because a privacy claim without them is not worth reading:

  • This website runs Google Analytics. The apps do not; the site you are reading does. If that matters to you, a content blocker will stop it and nothing on the site will break.
  • Apple handles purchases and receipt validation, which necessarily involves Apple.
  • Garfi's automatic captions use Apple's speech recognition, which may involve Apple processing audio when on-device recognition is unavailable.
  • AIonRadar's website is a web service with its own privacy policy; the native app has no account, advertising or in-app purchases.

If a page makes a privacy claim and does not list its exceptions, the exceptions still exist.

Keep reading