Privacy
How the current app processes files locally, retains settings and history, and how website requests differ.
Draft: this information is under review and is not an effective policy or set of terms.
Processing on your Mac
DiskJoy processes your files on your Mac. The current app does not upload your files, file lists, scan results or cleanup history. It does not include app analytics or telemetry, and you do not need an account to run a scan.
Scanning uses file paths and filesystem information to show disk usage and help you review items. Some operations read file contents, such as checking for duplicates. This processing stays on your Mac. Scan results are held in memory rather than saved as a scan-result cache.
Data stored locally
DiskJoy saves settings locally, including appearance, onboarding choices, scan areas, remembered scan locations and exclusions, and the time of your last completed scan. Remembered locations include absolute paths and filesystem identifiers so the app can check that a saved location still refers to the same item.
These settings are stored under your account’s Library/Application Support/DiskJoy directory. A small appearance launch hint and a boolean recording whether Full Disk Access was previously granted are also stored using macOS preferences. These two preferences contain no file paths or file lists.
To identify leftovers from apps previously seen on your Mac, DiskJoy saves app bundle identifiers and names locally. This record holds the previous complete installed-app inventory and apps no longer present in a later complete, nonempty inventory. It contains no app paths.
Cleanup history stores operation dates, results, affected file paths and filesystem identifiers locally. The engine creates its storage with permissions limited to your macOS account. This storage is not encrypted by DiskJoy; device protection and other software’s access depend on your Mac’s security settings and permissions.
Retention and local controls
Settings remain until you change or remove them. When the engine opens the cleanup journal, it prunes completed history to the last 100 operations, with no default age limit. New operations can take history above 100 while that journal remains open; pruning runs again when it is reopened. Interrupted operations are preserved as recovery evidence and do not count toward that limit.
Clear History removes completed operation records while preserving interrupted records. It does not restore files, delete files or empty the Trash. Files moved to the Trash follow macOS’s own retention and removal rules.
App-inventory records have no age limit and are updated after complete, nonempty inventories. Each installed and removed list is limited to 2,000 records; the oldest removed records are dropped first when that list exceeds its limit. Reinstalling an app removes its removed-app record. Incomplete or empty inventories do not advance or clear this history.
Permissions
You choose scan locations and can exclude locations from future scans. macOS permissions can prevent access to some locations. Full Disk Access lets DiskJoy inspect more protected locations; it does not send that information to us. You can change Full Disk Access in System Settings. Some locations remain protected from cleaning by DiskJoy’s safety rules.
Website and cookies
The current website serves static pages. It does not set tracking cookies or include browser analytics scripts. Visiting the website is separate from processing files in the app. Your browser still sends request information to the website’s hosting provider.
Website hosting
The website uses Amazon Web Services S3 and CloudFront. Website files and access logs are stored in the AWS Europe (Frankfurt) region. CloudFront delivers website content through its global network.
CloudFront access logging is enabled for website-request information, including IP addresses, request times, requested paths and query strings, browser information, referrers and response information. Query strings can include campaign parameters or advertising click identifiers if they appear in a link you follow. These logs do not contain the app’s scan results or cleanup history. Cookie logging is disabled.
The configured purpose of access logging is investigating abuse and unexpected website traffic. Logs are stored in a private S3 bucket with encryption at rest and an enabled lifecycle rule that expires them after 30 days. Expiration does not mean deletion happens at an exact instant. The operator’s details and applicable provider terms still require review before this draft becomes an approved policy.
Future processing
Server-side advertising attribution and purchase measurement are planned separately. They are not implemented by the current static website. Their design includes additional processing that would require an updated privacy notice and review before activation.
For help with the app, see Support.