DevSweep

Privacy and local data

DevSweep scans and hashes files locally. It requires no account. Licence validation uses a signed offline payload; no activation server is contacted. The app includes no advertising, telemetry or crash-upload SDK.

One exception, stated up front: DevSweep can check for its own updates. That check is off until you enable it, and it is described in full under Network behavior.

What is stored

Network behavior

DevSweep itself does not upload scan results, paths, hashes or source code. Git inspection uses local refs and does not fetch or verify the current remote state. Installed tools invoked by the app retain their own behavior. Homebrew auto-update and analytics are disabled for DevSweep commands. Some tool operations and subsequent regeneration may access their registries; offline regeneration is not guaranteed.

Update checks — the one exception

DevSweep can check whether a newer version exists. This is the only request the app makes, and it is the only part of DevSweep that is not local.

This exists because DevSweep is not notarised and is not distributed through the App Store. Without an update channel, a safety defect in a tool that deletes files could not be corrected on a machine that already had it installed.

Checkout and remote crash reporting are not enabled. Any future network feature requires explicit configuration and an updated disclosure. Optional macOS notifications are local notifications, with no DevSweep push server.

Permissions and exclusions

Full Disk Access is optional. Skipped locations and incomplete measurements are shown. Choosing a folder for duplicate detection authorizes local inspection only; moving copies to Trash requires a separate confirmation. Protected personal locations and source trees are excluded from duplicate cleanup. Do not share receipts or exported screenshots unless you intend to disclose the paths they contain.