Privacy Policy

App Trust Preview is privacy-first by design. The Mac app inspects supported Mac software locally on your Mac, sends no network requests of its own, and does not upload, launch, or modify the files you inspect.

Software inspection

When you inspect a supported target, App Trust Preview reads local file metadata, bundle metadata when available, and macOS security properties so it can show a report before you open, install, or run the inspected software.

  • The main app sends no network requests of its own.
  • The inspected file is not uploaded.
  • The inspected software is not launched.
  • The inspected file is not modified.
  • Reports are generated on your Mac.

Optional helper

The optional inspection helper is installed only if you choose to set it up. It is read-only and enables two additional checks: a live notarization result using Apple's local macOS tooling, and saved privacy decisions when you grant Full Disk Access.

  • The helper does not launch inspected software.
  • The helper does not modify inspected files.
  • The helper does not grant or revoke privacy permissions.
  • The helper does not upload inspected files or reports.

Report data

Inspection reports are generated by reading the inspected target and macOS's own signing and trust metadata for it. Supported targets include .app bundles, .pkg installer packages, .dmg disk images, binary executables, and executable scripts. A report may include:

  • App metadata from a bundle's Info.plist when present — name, bundle identifier, version, minimum system version, document types, URL schemes, application category, copyright string, App Transport Security configuration.
  • Installer package metadata, component data, install location, authorization needs, payload paths, and readable install scripts when a package provides them.
  • Disk image contents used for previewing bundled apps without opening them first.
  • Readable source previews for executable scripts when the script text can be decoded safely.
  • The report verdict, verdict tier, and the most important before-you-open findings derived from the report signals.
  • The signing certificate chain — subject and issuer names, serial number, validity dates, SHA-1 and SHA-256 fingerprints, public-key algorithm, signature algorithm — and its revocation status as reported by macOS's trust evaluator.
  • Code-signing properties — signing identifier, Team ID, designated requirement, implicit designated requirement, signature flags, CDHashes, digest algorithms used, and the RFC-3161 signing timestamp if present.
  • The full entitlements dictionary, and the structured capability classification derived from it, including Internet, Files & folders, Privacy, Apple Events, iCloud, Keychain, App Groups, Associated Domains, Hardened Runtime exceptions, and so on.
  • Sandbox status, Hardened Runtime status, and the distribution channel inferred from the signing identity, such as Mac App Store, Developer ID, Development, Ad-hoc, or Unsigned.
  • Privacy request indicators found in a bundle, including purpose strings in Info.plist, entitlements, and related metadata for services such as Camera, Microphone, Location, Contacts, Calendar, Photos, Accessibility, Screen Recording, Bluetooth, Apple Events, and similar.
  • Saved macOS privacy decisions for supported permissions when the optional helper is installed and granted Full Disk Access. Location authorization is always reported as Unknown because macOS stores it separately.
  • Potential network connections found through static analysis, including domains and URLs that the developer may use for network requests or user-facing links. Routine Apple infrastructure domains and unrelated URLs found in standard file format headers or certificate chains are excluded.
  • The embedded provisioning profile, if one is present — its name, UUID, team, expiration, devices, and entitlements.
  • Every internal executable component — nested apps, app extensions, XPC services, login items, helper executables, frameworks, dynamic libraries, plug-in bundles, dock tile plug-ins — each with its own signing status, sandbox state, and entitlements.
  • Executable file hashes for runnable components, plus VirusTotal report links that open public hash reports when you choose to review them.
  • Private Apple framework links, private symbol or selector name matches, and symlinks that point outside the inspected bundle when detected.
  • Mach-O metadata for the main executable and its components — supported architectures, UUID, deployment target and SDK version, linked libraries, runtime search paths, and whether the binary is position-independent or has an encrypted segment.
  • Detected technology signals such as native toolkits, web wrappers, browser engines, cross-platform frameworks, runtimes, and game engines when they can be confirmed.
  • The com.apple.quarantine extended attribute, if present, which is the marker macOS attaches to files downloaded from the Internet.
  • Target size and file dates as reported by the file system.

Any text or JSON export is created locally by the app. You decide where to save it and whether to share it.

VirusTotal links are hash report links. App Trust Preview does not upload the inspected file.

Certificate revocation check

The signing certificate revocation status shown in the report is provided by trustd, the macOS trust evaluator service, through a local inter-process call. App Trust Preview does not connect to any revocation server itself and does not contact apptrustpreview.com to perform the check. If trustd needs to refresh its cache, the network request comes from the operating system, not from this app.

Website analytics

The App Trust Preview website uses privacy-friendly analytics powered by Plausible. The analytics script helps understand aggregate website usage, such as page views and referrers. It is not used to inspect supported software and it is separate from the Mac app. The Mac app itself sends no network requests of its own.

Plausible is used because it is designed for website analytics without tracking cookies, persistent identifiers, cross-site tracking, or advertising profiles.

Support

If you email support, the information you choose to include in that email will be used to respond to your request. Avoid sending inspected files unless support specifically asks for a file and you are comfortable sharing it.

Questions about this policy can be sent to support@apptrust.app.

Changes

This policy may be updated as App Trust Preview changes. The current version is published on this page.