01Scope
This policy covers the Devbroom desktop app, the devbroom command line tool and this website.
02What does Devbroom read?
To decide whether something can be cleaned, Devbroom reads:
- Git repositories, worktrees and their git status in the folders you choose.
- The folders Claude Code, Codex, Cursor, OpenCode and Orca keep on your Mac; and, only to show them, those of Gemini CLI, Aider, Cline, Windsurf, Copilot CLI, Amp and Kiro.
- Developer caches (npm, Cargo, Xcode and the like), unless you turn them off in Settings.
- How much space folders really take on disk.
- Running processes and the files they hold open. Command lines are read into memory only to recognize agent processes, and written nowhere.
- Session logs. It takes the fields that tie a session to a folder (session id, folder, branch, time, agent version), and token counts and model names for Analytics. Message text isn't stored.
- When you search sessions, the logs' text is read at that moment for the words you searched; results are shown on screen and written nowhere.
03What does it keep?
Your settings, your cleanup history, a size cache that speeds up scanning, and for Analytics a summary of each scan and your sessions' token counts are kept only on your Mac. None of it is sent anywhere.
04What doesn't it send?
Anything about your Mac, your scan or you. There's no account, crash reporting, usage statistics or advertising id. Reminders are your Mac's own notifications.
Without a license, the only network request Devbroom makes is the update check: once, 8 seconds after launch, and when you press “Check now” in Settings › General, it reads the latest.json file we publish. The request asks only for that file; it carries nothing about your device, your scan or you. The server answering it sees your IP address, as with any web request. If there's a new version the app asks you; if you choose “Install”, the version is downloaded and installed after its signature is checked. We write what changed on the Changelog page.
The MCP server for agents (devbroom mcp) doesn't use the network; it talks only to the agent that started it, on this Mac.
05Command line
devbroom works by the same rules and never connects to the network. The --json report is written to disk only if you redirect it to a file. devbroom clean records what it did in the app's History.
06Pro and buying
The trial (14 days) is counted entirely on your Mac; nothing is sent for it.
When you buy Pro, our merchant Polar takes the payment. Your name, email, billing address and payment details go to Polar and are covered by its privacy policy. Your card details never reach us; we only see your email address, your order and your license key.
When you enter your license key in the app, Devbroom activates it once: the key, a random id that tells this Mac apart, and the Mac's name are sent to our license server. After that, while online, the app quietly checks about once a month that the license is still valid. Without internet, Pro never switches off. These requests carry nothing about your scan, your folders or your sessions.
We keep orders and activations to keep your license working, to handle refunds and to meet our legal record-keeping duties. We don't sell this information or use it for marketing.
07This website
This site is served by Cloudflare. Fonts and everything else on it come from this domain; the only outside service is Google Analytics.
We use Google Analytics 4 to understand how people find and use this site, for example which pages are viewed and where visitors come from. Advertising features are always off. In the EEA, the UK and Switzerland, analytics cookies are set only after you accept the cookie banner; until then Google Analytics receives only cookieless signals (Google Consent Mode). Everywhere else analytics is on by default and you can decline it in the banner. You can change your choice at any time with “Cookie settings” at the bottom of every page; declining removes existing Google Analytics cookies. Your cookie, theme and language choices are kept in your browser's local storage, not on a server. Google's privacy policy applies to Google Analytics.
If you leave your email address to hear when Devbroom is out, we store that address, the site language you used and the date, only to send you that announcement. We don't share it and don't use it for anything else. Every email has a one-click unsubscribe link, and you can ask us to delete your address at any time by writing to support@devbroom.com.
Like any web server, Cloudflare may keep requests' IP addresses and browser details for a short time for security; we don't use those logs for anything.
08If this policy changes
We update the date and announce the change on the Changelog page.
09Contact
For questions, or to have your data deleted: support@devbroom.com