We’ve made a sincere effort to characterise each alternative accurately. If you maintain one of these projects and we’ve described it unfairly, please open an issue so we can fix it.
What privacytracker is good at
- Tracking change over time. Snapshots every label after each scrape, diffs against the previous, surfaces the diff in a bell. This is the headline feature; nothing else listed below does this for App Store labels.
- Self-hosted, local-first. Your data stays on your machine. No account, no cloud, no telemetry. The signed desktop app, Homebrew cask, and Docker image all run from one open-source codebase.
- iOS-specific. Reads Apple’s privacy-label payload directly, with a fallback chain that absorbs HTML reshaping. Other tools generalise across platforms or focus on TOS text rather than the App Store labels themselves.
- Optional AI summarisation under your control. You bring the provider — OpenAI, Anthropic, or any local OpenAI-compatible endpoint (Ollama, LM Studio, llama.cpp). Re-summarisation only fires when the policy hash changes, so cost stays bounded.
- Audit-bundle workflow for households / regulators. A versioned JSON export for sharing a curated subset — see the cookbook for the partner-review and audit-prep recipes.
What privacytracker isn’t
- Not an Android tool (Apple App Store only).
- Not a one-click privacy score. We surface labels, changes, and policy summaries; we don’t reduce them to a single number, because the right judgement depends on your situation.
- Not a TOS analyser. We summarise privacy policies (what data is collected and why), not the rest of the terms-of-service surface (arbitration clauses, indemnification, content licences).
- Not a tool you delegate trust to. It helps you look more rigorously; you still have to look.
Alternatives by situation
”I just check the App Privacy section on each App Store page myself.”
That’s a reasonable baseline. Apple displays the same privacy data privacytracker scrapes; you can read it yourself for free, no install needed. (privacytracker auto-detects the embedding format: the modernserialized-server-data JSON blob on the Nov 2025+ web App Store, or the older Ember/FastBoot shoebox-media-api-cache-apps shape on archive.org captures going back to Q1 2021.)
You’d choose privacytracker over reading-it-yourself when:
- You track more than a handful of apps and want change notifications instead of remembering to re-check.
- You want history — Apple shows you the current labels, not what they used to be.
- You want to compare apps side-by-side, not tab-flip between App Store pages.
- You want a single audit-bundle export covering everything you’ve reviewed.
- You’re tracking five apps and re-checking is fine.
- You don’t trust running a local app to read public web pages on your behalf (which would also rule out a feed reader).
Apple’s built-in App Privacy Report (Settings → Privacy & Security → App Privacy Report on iOS 15.2+)
A different angle: Apple’s report shows what apps actually do on your device — domains contacted, sensors accessed, data accessed in the past seven days. It’s behavioural, not declarative.
These are complementary, not competing. The App Privacy Report tells you what’s happening; privacytracker tells you what’s been promised. A gap between the two is itself a finding.
ToS;DR — Terms of Service; Didn’t Read — tosdr.org
A long-running community project that grades terms of service and privacy policies. Volunteers annotate clauses (good practice, blocker, anti-pattern) and the site assembles them into a letter grade per service. Browser extensions surface the grade in-page when you visit the service’s website. What ToS;DR does better than privacytracker:- Cross-platform — covers websites, services, and apps across iOS, Android, web.
- Human-curated, with linked annotations explaining each clause and why it matters.
- Shows you the assessment up front when you visit the service’s site (via the extension).
- Free, no install required for the core experience.
- Tracks changes to the App Store privacy labels specifically — ToS;DR reviews TOS prose, which moves at a different cadence and contains different information.
- Covers apps without an existing ToS;DR review (long tail).
- Self-hosted history and audit-bundle workflow.
PrivacySpy — privacyspy.org
A privacy-policy analysis project that scores services against a transparent rubric. Like ToS;DR, it’s community-curated; unlike ToS;DR, the rubric is more structured and the per-service score is broken down into categories. What PrivacySpy does better:- Scoring rubric is explicit — you can see exactly how a score was derived, line by line.
- Coverage extends beyond apps to general online services.
- Bookmarks-aware: you can score a service you care about and watch for rubric updates.
- Per-app App Store label tracking (PrivacySpy reads policy text; Apple’s privacy labels are a separate disclosure surface).
- Diffs and change notifications keyed to the iOS App Store.
- Self-hosted; PrivacySpy is a hosted web service.
Exodus Privacy — exodus-privacy.eu.org
A French non-profit that statically analyses Android APKs to enumerate the trackers each app embeds (AdMob, Firebase Analytics, Facebook SDK, etc.). Reports are public and searchable. This is the closest analogue to privacytracker’s spirit — empirical, public, change-tracking — but for Android, and at the binary-analysis layer rather than the App Store label layer. What Exodus does:- Decompiles Android APKs to identify embedded SDKs/trackers.
- Maintains a public database queryable by app name or package ID.
- Catches what an app actually contains, not just what the developer declares.
- Cross-device — you don’t need an Android phone to query their database.
Just disabling tracking in iOS Settings
Settings → Privacy & Security → Tracking → Allow Apps to Request to Track off. This denies the IDFA to apps and limits cross-app advertising tracking. It does not:- Prevent apps from collecting first-party data they were going to collect anyway.
- Surface apps that suddenly start declaring new categories.
- Tell you anything about retention, sharing with third parties, or children-specific protections.
Decision matrix
Quick guide if you only want to install one tool:Working in concert
The most informed setup uses several of these together:- privacytracker running locally for iOS label tracking + history.
- App Privacy Report on the iPhone for behavioural cross-reference.
- ToS;DR browser extension when browsing services.
- Exodus Privacy for any Android device you also use.
When you wouldn’t use privacytracker
To be clear about it: skip privacytracker when- You’re not on iOS and don’t need iOS coverage.
- You’re tracking five apps and the App Store page is fine.
- You don’t want to run a local app at all (Docker, desktop, source) — there’s no hosted version.
- You’d rather a single grade than a granular label history.
- You’re looking for behavioural / network-level evidence rather than declarative label evidence — see App Privacy Report or PiHole-style traffic logging instead.