Privacy
The short version: your files never leave your Mac. Here is the complete list of what does.
The apps
All processing — reading file contents, analysing photos, generating names — happens on your Mac using Apple's on-device frameworks. There are no accounts, and no file contents, file names, photos or personal data are ever sent anywhere.
The apps make exactly three kinds of network requests:
- Anonymous usage statistics via TelemetryDeck (EU-based, anonymised): app launches and a few numeric counters, such as how many folders are watched or how many photos were flagged. Never names, paths or content. You can switch this off in every app's settings at any time.
- Update checks via the Sparkle framework: the app asks this website whether a newer version exists, sending the app version and macOS version. The apps are sold outside the App Store, so they check automatically — otherwise a fix would not reach you. A new install is asked about this on its first launch; if you already had the app before automatic checks existed, they were switched on by the update and nothing asked you first. Either way you can switch automatic checks off in settings at any time, and checking by hand stays available.
- License validation: on activation the app sends your license key to Polar (the merchant of record) to confirm it — nothing about your files.
Perron and public transport data
Perron is the exception worth reading. It is a departure board, so it has to ask somebody when your train leaves — and that question contains the stations you saved.
When Perron looks up a departure it sends the two stations of the connection you are viewing, and the time of the query, to opentransportdata.swiss, the Swiss federal open transport data service. That is what a timetable lookup is. It is not sent to me, I never see it, and it is not stored anywhere by Perron beyond a short cache on your own Mac. Your saved connections live in Perron's own settings on your Mac and are never uploaded.
Perron asks only about the connection currently shown, only when you open the menu or when a departure is close, and never about the other connections you have saved.
Perron and your location
Perron can show the connection leaving from whichever of your saved stops you are nearest. This is off unless you switch it on in Settings, and macOS asks you separately before Perron may read your position at all.
When it is on, your position is worked out on your Mac and is never transmitted — not to me, not to the transport service, and not to anyone else. Perron compares it against the coordinates of the stops you have already saved, which are stored on your Mac, and the answer is simply which connection to show. Your position is never part of any usage statistic: the signals listed above carry counts and fixed labels, never a coordinate.
Perron watches for significant location changes — roughly, moving between places — rather than following you continuously. Switching the setting off stops it.
Every signal Perron can send
This is the complete list — not a summary. Anonymous usage statistics are on by default, Perron says so on first launch, and you can switch them off in Settings at any time. No signal ever contains a station name, a station id or a coordinate; a test in the app's build enforces that rather than leaving it to good intentions.
com.tidymill.app.launched— Perron started.-
com.tidymill.daily.heartbeat— once a day: how many connections you have saved as a range (0, 1, 2, 3-5, 6-10), how many timetable lookups were made as a range (0, 1-10, 11-30, 31-100, 100+), your interface language (en, de, fr or other), your manual-override setting, your "avoid changes" setting as one of the values the picker offers, and whether "launch at login", "show the track" and automatic update checks are on. com.tidymill.menu.opened— the menu was opened.com.tidymill.settings.opened— the Settings window was opened.-
com.tidymill.settings.changed— a setting was changed, carrying only which one, from a fixed list (language, updates, telemetry, launch at login, show the track, manual override, location, avoid changes). It never carries what you changed it to — so this says a setting was worth finding, and nothing about your choice. -
com.tidymill.license.activated— a supporter key was activated. It carries no amount: what you chose to pay is between you and Polar. -
com.tidymill.ojp.rate_limited— the transport service asked Perron to slow down. It tells me the shared data quota is running out, and nothing about you.
NameGnome and your files
NameGnome reads what is inside your files in order to name them, which is the most intrusive thing any app here does — so this section says exactly what that means.
It is read only inside the folders you add to NameGnome, and nowhere else on your Mac. A PDF's text, the words in a screenshot, a photograph's capture date, a video's metadata: all of it is read on your Mac, by on-device models — the one that comes with macOS, and, if you switch it on, the optional photo model described below — and your files never leave your Mac — there is nowhere for them to go. NameGnome has no account, no API key, no server and no upload of any kind.
NameGnome renames files and does nothing else to them. It does not delete or move one, it does not change what is inside one, and every rename can be undone from the app's own history. That history — the old name and the new one — is kept on your Mac and is never transmitted. The usage statistics below carry counts and fixed labels only: no filename, no path, and no word taken from a file.
Since 0.2 NameGnome offers Better photo names: an optional, small
image-description model (about 500 MB) that describes photographs on your Mac.
Nothing about it changes the sentence above — the model is a download, not an
upload. When you switch it on, NameGnome fetches the model's files once from
huggingface.co (the public repository
mlx-community/LFM2-VL-450M-8bit), pinned to an exact version and checked
byte for byte against checksums built into the app — a changed file is rejected, not
used. Your pictures are never sent there or anywhere: the model runs entirely on your
Mac, and Hugging Face learns only what any download tells a server — that some computer
fetched these public files. The switch is off until you flip it, an update never flips
it for you, and switching it off later stops the feature; "Remove download" deletes the
files.
When you activate a licence key, the key and a label identifying this Mac (its computer name) go to Polar so the licence can be checked and so you can free the device again later. Together with the update check described above and the optional model download, that is everything NameGnome sends or fetches, and none of it says anything about your files.
Every signal NameGnome can send
This is the complete list — not a summary. Anonymous usage statistics are on by default, NameGnome says so on first launch, and you can switch them off in Settings at any time. No signal ever contains a file name, a path, or anything read out of a file; a test in the app's build enumerates every signal and every value it may carry, so this stays true rather than being remembered.
com.tidymill.app.launched— NameGnome started.-
com.tidymill.daily.heartbeat— once a day: how many folders you watch as a range (0, 1, 2, 3-5, 6-10, 10+), how large a history you keep (0, 100, 200, 500), how many files were renamed as a range (0, 1-5, 6-20, 21-100, 100+), how many were undone as a range (0, 1, 2-5, 6+), whether Apple Intelligence is usable on this Mac, your interface language (en, de, fr or other), and whether the menu bar gnome, launch at login, automatic update checks and Better photo names are on, and whether the monthly support notice is currently showing. com.tidymill.window.opened— the main window was opened.com.tidymill.settings.opened— the Settings window was opened.-
com.tidymill.settings.changed— a setting was changed, carrying only which one, from a fixed list. It never carries what you changed it to — two of those settings are the naming template and the extra instruction, and those are words you typed. -
com.tidymill.folder.added,com.tidymill.folder.removed— a folder was added to or removed from the watch list. Never which folder. -
com.tidymill.renamed— a file was renamed, carrying the kind of file (pdf, text, image, screenshot, video, other), where the name came from (Apple's model, the optional photo model, what the classifier saw, the file's own metadata, or its previous filename) and a confidence band (low, medium, high). Not the name. -
com.tidymill.undone— a rename was undone, carrying the kind of file, how long the name stood (minute, hour, day or older), and where the undone name had come from, from the same fixed list as above. Undos divided by renames is how I find out whether the names are any good — and per source, which naming path is letting people down. -
com.tidymill.skipped— NameGnome decided not to rename something, carrying only the reason from a fixed list: too little confidence, a proposal that failed validation, a name collision it could not resolve, reading the file failed, the model was unavailable or refused or timed out, the file vanished, access to the folder was lost, or the file kind is unsupported. -
com.tidymill.model.unavailable— Apple Intelligence could not be used, and which of the reasons applied: switched off, this Mac is not eligible, or the model is still downloading. -
com.tidymill.folder.access_lost— a folder you had added stopped being reachable, so NameGnome needs you to pick it again. -
com.tidymill.describer.download— how an attempt to download the optional photo model ended, from a fixed list: completed, cancelled, or failed because you were offline, a file arrived damaged, the disk was full, or something else. Never a speed, a duration or an address. -
com.tidymill.describer.failed— the downloaded photo model produced no description, and which of three reasons applied: it would not load, it took too long, or its answer was unusable. Never the picture, never the answer. -
com.tidymill.nudge.dismissed— the monthly support notice was dismissed with “Not now”. com.tidymill.checkout.opened— the Buy button was pressed.-
com.tidymill.activation.failed— a licence key was refused, carrying only the reason: the key was malformed, not found, revoked, past its device limit, or the check could not be made because you were offline or asked to slow down. -
com.tidymill.license.activated— a licence key was activated. It carries no amount: what you paid is between you and Polar.
Photosteward and your photo library
Photosteward looks at the people in your photographs — who is smiling, whose eyes are shut — which is the most personal thing any app here reads. So, precisely: it reads your Apple Photos library after macOS asks you and only to the extent you grant (full library or a chosen subset), and every judgement about a face is made on your Mac by Apple's on-device frameworks — your files never leave your Mac. What was judged stays in the app's index on your Mac and is never transmitted; the usage statistics below carry coarse buckets only — never a photo, a face, a name, a place, an album or an asset identifier.
With iCloud Photos and “Optimise Mac Storage”, some originals are not on your Mac. Photosteward groups photos from the previews that are, and asks macOS to fetch full-quality originals from your own iCloud only for the groups that need a closer look — the same download Photos performs when you open a picture. That request goes to Apple as part of your iCloud account; nothing goes to me.
Photosteward changes your library in exactly two ways, both visible: it keeps its flagged photos in a Rejects album, and it deletes a batch only when you press the button — after which macOS itself asks you once more, and Photos keeps the deleted photos in Recently Deleted for 30 days. One limit, stated plainly: macOS draws no distinction, for apps, between your own library and a shared iCloud one. Photosteward sees both together.
Every signal Photosteward can send
This is the complete list — not a summary. Anonymous usage statistics are on by default, Photosteward says so on first launch, and you can switch them off in Settings at any time. No signal ever contains a photo, a face, a name, an album, an asset identifier or an exact count; a test in the app's build derives the allowed values from the app's own closed enums, so this stays true rather than being remembered.
com.tidymill.app.launched— Photosteward started.-
com.tidymill.daily.heartbeat— once a day: how large the library is as a range (0, 1-999, 1k-5k, 5k-20k, 20k-50k, 50k+), how many groups were found and how many photos are flagged, each as a range (0, 1-9, 10-99, 100-999, 1000+), which menu-bar reminder threshold you chose (never, 25, 50, 100, 200, 600 or 1000), whether scanning, “only on mains power”, the menu bar icon, launch at login and automatic update checks are on, your interface language (en, de or other), and how much of the free allowance is used — as a share (untouched, started, half, nearly, spent, or licensed), never the exact number, because an exact count beside a library size starts to identify a person. -
com.tidymill.permission.answered— the system's answer to the photo-library request, from a fixed list: authorized, limited to a subset, denied, restricted by a profile, or not decided yet. -
com.tidymill.scan.completed— the first full pass over a library finished, carrying the same three ranges as the heartbeat: library size, groups found, photos flagged. -
com.tidymill.review.session— the review window was closed, carrying how many groups were looked at as a range, how many of the app's choices you overrode (0, 1, 2-5, 6-20, 20+), and how many overrides you took back with “Restore the app's choice”. Overrides divided by reviews is how I find out whether the app picks the photo you would have picked — the claim the product rests on. -
com.tidymill.delete.batch— a confirmed batch went to Recently Deleted, carrying the number of photos as a range (1, 2-9, 10-49, 50-199, 200+) and the reclaimed size as a range (unknown, 0-100MB, 100MB-1GB, 1-10GB, 10GB+). -
com.tidymill.settings.changed— a setting was changed, carrying only which one, from a fixed list (scanning, mains only, review reminder, scan scope, menu bar icon, launch at login, updates, telemetry, language). Never what you changed it to. -
com.tidymill.allowance.gate— the free allowance refused a deletion and the purchase gate appeared. com.tidymill.checkout.opened— the Buy button was pressed.-
com.tidymill.activation.failed— a licence key was refused, carrying only the reason: the key was malformed, not found, revoked, past its device limit, or the check could not be made because you were offline or asked to slow down. -
com.tidymill.license.activated— a licence key was activated. It carries no amount.
This website
Hosted on Cloudflare Pages. It runs no analytics at all: no beacon, no cookies, no page-view counter. The server logs Cloudflare keeps to serve the site are all that exists. Purchases run through Polar, whose own privacy policy applies at checkout; I receive your email address to deliver the license, and nothing more.
Who is responsible, and how to reach them
The controller for the personal data described on this page is the person named in the impressum, reachable at the email address given there. Swiss data protection law (revFADP) applies; where you are in the EU or EEA, the GDPR applies to the processing described here.
Who else sees data, and where
- Polar (merchant of record) — your email and payment details at purchase, to sell you the licence and issue the invoice. I receive your email address and nothing more.
- TelemetryDeck (EU-hosted) — the anonymous signals listed above, with no account and no identifier I could tie back to you.
- opentransportdata.swiss (Switzerland) — for Perron only, the stations of the connection you are viewing, to answer the timetable query. Not sent to me.
- Cloudflare — serves this website and its downloads.
How long it is kept
Anonymous usage statistics are retained by TelemetryDeck under their retention policy and cannot be traced to a person. Purchase records are kept by Polar for as long as tax law requires them to be. Support emails stay in the mailbox until they are no longer useful to answer you. Your saved connections and settings never leave your Mac, so there is nothing of yours here to delete.
Your rights
You can ask what personal data is held about you, have it corrected or deleted, object to processing, and receive it in a portable form. Write to the address in the impressum and you will get an answer. If you are unhappy with that answer you may complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC), or to your local supervisory authority in the EU or EEA.
In practice there is usually very little to hand over: the apps hold your data on your own Mac, and the statistics are anonymous by construction.
If you write to support, your email stays in my mailbox and is used only to answer you. No lists, no sharing.