Privacy
This page describes how the app works technically. The publisher's name and contact details still need to be added and reviewed before release.
The short version
Dustpan runs on your computer. It makes no network requests unless you turn on one of two optional features in Settings, both off by default: encrypted backup of your settings, and anonymous usage stats. Your files, folder paths and scan results never leave your machine either way.
What the app reads
- Names, sizes and modification dates of files and folders in the folders you choose, and in the known cache, Xcode and emulator locations listed in the docs.
- Whether marker files exist (for example
package.jsonorCargo.toml). It doesn't read their contents. - A few tool metadata files: Xcode DerivedData
info.plist(which project it belongs to), Android emulator.inifiles and lock files, and the output ofxcrun simctl list. - For generic folder names like
build, whether git ignores them (git check-ignore).
It doesn't open or read your source code, documents or other file contents.
What the app stores
Two files in ~/Library/Application Support/Dustpan/ (macOS) or ~/.config/Dustpan/ (Linux):
settings.json: your chosen folders, suggestion cut-off, removal method and hidden items.last_scan.json: the most recent scan results (paths, sizes, dates), so the list shows up instantly next time.cloud.json, only if you use backup or stats: sync bookkeeping and your stats choice. No passwords or keys.
Delete that folder to remove all of Dustpan's data.
Optional encrypted backup
Backup is optional. Without an account, everything stays on this device, exactly as before. If you sign in:
- What's uploaded: one record with your suggestion cut-off, removal method, whether you've finished setup, and your hidden-items list. Hidden items are identified by their path, so that list does contain folder paths you chose to hide. Your chosen scan folders and your scan results are never uploaded.
- Encryption: the record is encrypted on your Mac with a key protected by your passphrase (AES-256-GCM, PBKDF2 with 600,000 rounds) before it's uploaded. The server stores only scrambled data and can't read it; neither can we.
- If you forget your passphrase and lose your recovery key, your backup can't be recovered, by you or by us. There is no reset. Your settings on this Mac are unaffected.
- Your email is used only to send a sign-in code. It isn't linked to anything inside your encrypted data.
- What the server can still see: that you have an account (your email), how many records you have and how big they are, when they change, and which devices are signed in.
- The sign-in token and encryption key are kept in the macOS Keychain. Sign out of this device and Delete cloud backup are in Settings; deleting removes the account and everything stored with it.
Optional anonymous stats
Off by default and separate from backup. When on, Dustpan sends at most once a day a random install id made only for this purpose, the app version and the number of crashes since the last report. It never includes your account, files, paths or scan results, and the server keeps no IP addresses.
What the app changes
Only the items you select and confirm, moved to the Trash or deleted permanently, as you choose. Simulators are
removed through Xcode's simctl.
This website
This site is static HTML and CSS. It sets no cookies and loads no analytics or third-party scripts.