Is this affiliated with Apple?
Is this affiliated with Apple?
Does this work for Android apps?
Does this work for Android apps?
<script id="serialized-server-data"> envelope (Nov 2025+) and the older Ember/FastBoot shoebox-media-api-cache-apps shape (Jan 2021 – Nov 2025) for archive.org captures — which is iOS-specific. Google Play has a different shape and a different label scheme (Google’s “Data safety” section vs. Apple’s “App Privacy”), so it would need a separate parser and data model. The codebase is contribution-friendly and the data layer is structured to make adding a parallel parser feasible if someone wants to take it on.Can I try it before adding my own apps?
Can I try it before adding my own apps?
What data leaves my machine?
What data leaves my machine?
- App Store HTML — fetched from
apps.apple.comto read public privacy labels. Same network call your browser makes when you visit an app’s page. - Privacy-policy text — fetched from the developer’s own domain when you’ve enabled AI summaries. The fetcher follows redirects and respects standard
Cache-Controlheaders. - AI provider calls — only if you’ve configured one. The policy text (chunked if necessary) is sent to OpenAI, Anthropic, or your local OpenAI-compatible endpoint. Nothing else — no app names, no usage, no telemetry.
- Notification webhooks — only if you’ve pasted a webhook URL. App names and change summaries are POSTed to whatever chat service you pointed it at. Off unless you set it up; see Configuration → Notification webhooks.
How much do AI summaries cost?
How much do AI summaries cost?
- OpenAI / Anthropic (hosted) — typically a fraction of a cent per summary. A privacy policy of ~20 KB summarised through
gpt-4o-miniorclaude-haiku-*runs around USD $0.001-0.005 per app. Re-summarisation only happens when the policy text actually changes (we hash and skip otherwise), so the long-tail cost stays low. - Local model (Ollama, LM Studio, llama.cpp) — free at runtime; you pay in disk space and a one-time model download. Quality varies; Llama 3.1 8B and Qwen 2.5 7B both produce usable summaries on the lens prompts.
Can I run this for my whole family on one server?
Can I run this for my whole family on one server?
.txt / .csv files from the iPhone import helper so you can ingest a family member’s app list in one pass. Record whose each device is, and the device menu at the top of every page switches between them — one person’s devices, a few, or everyone’s.That’s a view, not a wall. privacytracker has no built-in user accounts or per-user partitioning — anyone who can open it can pick any device. If family members’ data needs keeping apart, run separate instances (different ports, different data/ directories) or use the audit-bundle handoff workflow to share a curated subset.What happens if Apple breaks the scraper?
What happens if Apple breaks the scraper?
shelfMapping.privacyTypes.items → privacyHeader.seeAllAction.pageData.shelves → generic pageData.shelves → extractFromShoebox for the historical Ember/FastBoot shape, which is what lets the Wayback importer reach back to Q1 2021) so most shape changes absorb without a release. When Apple ships a fully breaking change — twice in the project’s history so far — the fix is usually 5-10 lines in lib/scraper.ts once we have a known-broken example.If you hit a parser failure, the support bundle under Settings → Admin → Deployment Diagnostics captures everything we’d need to fix it; paste it into a GitHub issue.Does this need to be online all the time?
Does this need to be online all the time?
Can I export my data?
Can I export my data?
- Backup bundle —
GET /api/backup/exportproduces a versioned JSON file with every app, label, snapshot, annotation, and notification. Restore it viaPOST /api/backup/restore; the UI adds a preview and a typed confirmation, and a bundle exported by a different install needs an explicit untrusted opt-in. See Backup & restore. - CSV / JSON dump —
GET /api/export?format=csv|jsonfor a flat data dump suitable for piping into a spreadsheet or another tool. - Audit bundle — a curated subset (apps, labels, AI summaries, exportable annotations) suitable for sharing with another household member or a regulator. Available when your focus workflow is
other_handoff, or when the audit-bundle export flag is switched on.
Is this GDPR / CCPA / DPDP-friendly?
Is this GDPR / CCPA / DPDP-friendly?
Why is the database SQLite and not Postgres?
Why is the database SQLite and not Postgres?
- Single-user app — there’s no multi-write contention to manage. WAL mode + a 5-second
busy_timeoutcover the rare cases where a manual scrape and a scheduled sync overlap. - One file:
privacy.dbsurvives container rebuilds in its volume, copies trivially for backup, and can be inspected directly with thesqlite3CLI. No backup server, no replication, no DBA needed. - No schema migration tooling — better-sqlite3’s synchronous API plus an inline
migrationsarray ofALTER TABLEstatements is a complete schema-versioning story for the project’s complexity. Postgres would buy us nothing we’d actually use.
What languages is the interface available in?
What languages is the interface available in?
en) and Simplified Chinese (zh), both at full key parity. Switch between them under Settings → Language. The interface is built on next-intl; the active language is resolved on every server-rendered request from the NEXT_LOCALE cookie, falling back to English when it’s absent or holds an unsupported value. Adding a language is a contributor task — see Translations.Can I contribute a new privacy-label parser, locale, or chart?
Can I contribute a new privacy-label parser, locale, or chart?
lib/scraper.ts plus a regression test.Is the desktop app open source?
Is the desktop app open source?
src-tauri/), the Next.js bundle, the iPhone import helper (scripts/ios-app-import/), and everything else in the repo is Apache-2.0 licensed. The signed binaries we publish on GitHub releases are built deterministically from the same source — you can build your own from develop/build-from-source if you want to verify.