# Quickstart
Source: https://docs.privacytracker.privacykey.org/quickstart

Install privacytracker and import your first apps in about five minutes — no source build required.

privacytracker is designed to be self-hosted on your own machine. The fastest path is a signed prebuilt binary or a Docker container — pick whichever fits how you usually run things.

> **Note**
>
> If you want to build privacytracker from source — for development, a custom build, or a platform we don't ship binaries for yet — see the [Develop section](https://docs.privacytracker.privacykey.org/develop/overview).

![Onboarding audience picker](https://docs.privacytracker.privacykey.org/images/onboarding-audience.png)

*First-run audience picker*

## Pick how to run it

**Desktop app (macOS)**

Signed and notarized for both Apple Silicon and Intel. The simplest path on a Mac.

**Step 1: Download the latest .dmg**

Grab the latest release from [github.com/privacykey/privacytracker/releases/latest](https://github.com/privacykey/privacytracker/releases/latest).

**Step 2: Drag privacytracker into /Applications**

Gatekeeper opens it without warning — the build is Developer ID signed and notarized by Apple.

**Step 3: Launch privacytracker**

Auto-updates are handled by the Tauri updater with an ed25519 signature check on every patch. The SQLite database lives at `~/Library/Application Support/privacytracker/` and survives app updates.

**Homebrew (macOS)**

For people who already manage tools with `brew`:

```bash
brew tap privacykey/tap
brew install --cask privacytracker
```

Installs the same signed `.app` bundle into `/Applications`. Upgrade with `brew upgrade --cask privacytracker`.

**Docker (Linux / macOS / NAS)**

Best for self-hosting on a server, NAS, or LAN-trusted machine.

```bash
git clone https://github.com/privacykey/privacytracker.git
cd privacytracker
echo "AUDITOR_ADMIN_TOKEN=$(openssl rand -hex 32)" >> .env
chmod 600 .env
docker compose up --build -d
```

Docker always requires the admin token: Compose won't start without it, and it's what you sign in with. The SQLite database lives in a Docker-managed volume, `privacytracker-data`, so your data survives container rebuilds.

Open [http://localhost:3000](http://localhost:3000) and sign in with the token from `.env`.

On macOS without Docker Desktop, [Colima](https://github.com/abiosoft/colima) is a lightweight alternative — see [Installation](https://docs.privacytracker.privacykey.org/installation#colima) for the full setup.

## Import your first apps

Whichever way you installed it, the in-app workflow is the same.

**Step 1: Pick an audience and goals**

First-run onboarding asks who you're tracking apps for (`self`, `loved one`, `guardian`) and what you want to focus on (`monitor`, `cleanup`, `minimal`, plus an optional `accessibility` modifier). These choices tune the UI, and a short goal-aware guided tour highlights the surfaces they unlock — dismiss it any time and replay it later from the focus tour at `/help/focus`.

Changed your mind? Re-pick audience and goals from the **Your focus** card at the top of **Settings** via its **Adjust** button. Individual feature flags can be fine-tuned separately under **Settings → Developer Options → Feature flags**.

**Step 2: Add apps by name or URL**

Type app names — privacytracker hits the iTunes Search API and shows ranked candidates to confirm. You can also paste App Store URLs directly, or upload a `.txt` / `.csv` from the [iPhone import helper](https://docs.privacytracker.privacykey.org/installation#iphone-import-helper).

Not ready to add your own yet? Choose **Try with sample data** in onboarding to load 10 demo apps so you can explore the dashboard, Privacy Map, and timelines first. The demo set is session-only — it clears itself when you restart or once you start adding real apps, so it never mixes into your data.

**Step 3: (Optional) Configure an AI provider**

Skip this if you only want label tracking. To get developer-policy summaries, head to **Settings → AI** and pick a provider:

- **OpenAI** — paste an API key.
- **Anthropic** — paste an API key.
- **Own model** — point the base URL at any OpenAI-compatible endpoint. The simplest local setup is:

```bash
ollama pull llama3.2
ollama serve
# In Settings → AI:
#   Provider: Own Model
#   Base URL: http://localhost:11434
#   Model:    llama3.2
```

**Step 4: Watch the timeline**

Each app gets a per-app detail page with a chronological snapshot timeline, a category-trend chart, and a "matches live sync" badge when an archived snapshot agrees with the current scrape. Re-scrape an app from the detail page to produce a change notification you can see in the bell.

![AI provider settings](https://docs.privacytracker.privacykey.org/images/settings-ai.png)

*AI settings for choosing a provider*

![App detail change timeline](https://docs.privacytracker.privacykey.org/images/app-detail-timeline.png)

*App detail timeline after a few syncs*

## Verify it's healthy

![Dashboard overview](https://docs.privacytracker.privacykey.org/images/dashboard-overview.png)

*Dashboard after importing sample apps*

```bash
curl http://localhost:3000/api/ready
# {"status":"ready","checks":{...}}
```

`GET /api/ready` is the readiness probe (DB reachable + data dir writable). It returns 200 with `status: "ready"`, or 503 with `status: "not_ready"` and the failing entries in `checks` — which is what makes it usable as a Docker `HEALTHCHECK`. `GET /api/health` is the cheaper liveness probe used by uptime checks.

## Next steps

**[All install paths](https://docs.privacytracker.privacykey.org/installation)**

Detailed setup for desktop, Homebrew, Docker, and behind a reverse proxy.

**[Configure AI providers](https://docs.privacytracker.privacykey.org/configuration#ai-providers)**

Add OpenAI, Anthropic, or a local model — tune timeouts, chunking, and debug logging.

**[Back-fill historical labels](https://docs.privacytracker.privacykey.org/configuration#wayback-import)**

Pull every quarter of label history Apple has published since February 2021 — the earliest era when Apple shipped privacy nutrition labels in the App Store HTML.

**[Build from source](https://docs.privacytracker.privacykey.org/develop/build-from-source)**

Run privacytracker from a checkout — for development or unsupported platforms.
