Skip to content

Privacy Policy

Your privacy matters. Here's how DevPulse protects it.

Last updated: September 9, 2026

The Simple Truth

DevPulse — the app — has no accounts, no analytics, and no tracking. We — the developers — never receive your data. The repositories you track live on your Mac, iPhone, or iPad and, if you enable iCloud, in your own Apple account. DevPulse does talk to the internet, but only to the release sources you ask it to follow.

What This Means

No data collection: The app collects no personal information, usage statistics, or analytics. This website keeps cookieless visitor statistics, described below.
No tracking: We don't track how you use the app or which projects you follow.
No third-party services: No third-party analytics, crash reporting, or advertising SDKs in the app.
No accounts required: There is no DevPulse account and no sign-up. Pro is a one-time App Store purchase.
No server of ours: DevPulse has no backend. It talks directly to the release sources you choose, and nothing routes through us.

How DevPulse Works

DevPulse tracks releases of the projects you choose. To do that it makes network requests directly from your Mac to the sources you add — the GitHub REST API, the GitLab REST API, and Helm chart repositories. These requests fetch publicly available release data: versions, dates, and release notes. They necessarily reveal your IP address and which projects you are asking about to those providers, whose own privacy policies then apply. DevPulse sends them nothing else about you.

Data Storage & iCloud

DevPulse stores:

  • The repositories you track, along with their fetched release history and notes
  • Your app preferences and tags
  • A record of which releases you have already been alerted about, kept only on that Mac and deliberately never synced

This lives on your device. If iCloud is enabled, your tracked repositories sync across your Mac, iPhone, and iPad through your own iCloud account using Apple's CloudKit, covered by Apple's privacy policy. We have no access to that data and no way to read it. Turn iCloud off for DevPulse in Settings and it stays local to that device.

Notifications & Background Refresh

The Ambient Release Radar re-checks your tracked repositories on a schedule while DevPulse is running — it is not a background daemon and does nothing while the app is closed. It is off by default. Notifications are opt-in: macOS permission is requested only when you turn them on, and they are generated entirely on your Mac from release data already fetched. No push server is involved, so nothing about you leaves your device to produce them.

Credentials

You may optionally supply a GitHub personal access token to raise your API rate limit. It is stored in the macOS Keychain and sent only to GitHub, as the authorization header on your own requests. It is never synced by DevPulse and never sent to us.

Local MCP Server (Pro)

DevPulse can expose your tracked releases to AI agents through a Model Context Protocol server. It is off by default. When enabled it binds only to 127.0.0.1 — your own machine, never a public network — and requires a bearer token held in your Keychain. Any agent you connect to it runs under your control, and whatever that agent does with the data it reads is governed by its own provider's policy, not ours.

System Permissions

DevPulse may request the following system permissions:

Network access

To fetch release data from GitHub, GitLab, and Helm repositories

Notifications (optional, Mac)

Only if you turn on Release Radar alerts — requested at the moment you opt in

DevPulse runs sandboxed on every platform: the macOS App Sandbox on the Mac, and the standard app sandbox on iPhone and iPad. It does not request Full Disk Access and does not scan your disk. The only files it ever touches are ones you pick yourself in a save or open panel, when you export or import your own repository list.

Feedback Form

The app collects nothing; this website has one page that does — the feedback form, and only when you choose to fill it in and press send. DevPulse itself never sends feedback: it opens a web address in your browser and stops.

We receive what you typed — the subject and the details — and your email address if you chose to give one. The address is optional; leave it blank and the report is anonymous, and we will still read it.

Opening the form from inside the app (Help → Send Feedback) also fills in four technical facts: your DevPulse version, your macOS version, your Mac's model identifier, and your language. They arrive in the web address itself, so you can read them in your browser's address bar before anything is sent, and the form shows them as ordinary editable fields you can change or clear. That is the entire list — never your username, your computer's name, and never a repository, release or credential.

Submissions are stored in a Cloudflare D1 database hosted in Western Europe and emailed to support@mgcrea.io so we can reply. We keep them for twelve months, then delete them. Never used for marketing, never sold, never shared. The form sets no cookie, and nothing in the code that handles your submission ever reads or stores your IP address. Like every page here it loads the site-wide visitor statistics described below.

Website Analytics

This website is a separate thing from the app, and it does count visits. It uses Cloudflare Web Analytics, which sets no cookie and stores nothing on your device — no identifier between page loads, no localStorage, and no fingerprinting of your browser or IP address. A visit is counted by looking at whether the page you came from was on this site, not by recognising you. Because nothing is written to or read from your device, this needs no consent banner under the ePrivacy Directive (in France, Article 82 of the loi Informatique et Libertés), and there is none.

Sent on each page view: the page address, the address you came from, your browser and operating system, your screen size, and page load timings. Cloudflare derives an approximate country from your IP address and does not pass the address itself to us. We see aggregate totals only — never a profile, never an individual, and never anything across other websites. Our lawful basis is legitimate interest in understanding how our own site is used; Cloudflare acts as our processor under its Data Processing Addendum. Any content blocker, or a browser Do Not Track setting, stops the script loading.

Children's Privacy

DevPulse is a developer tool and is not directed at children. It collects no personal information from anyone, regardless of age.

App Store Compliance

This privacy policy is designed to comply with Apple App Store requirements. Because DevPulse collects no personal data, there is nothing for us to disclose, sell, or delete under privacy regulations such as GDPR or CCPA. Data held in your own iCloud account is managed by you through Apple.

Changes to This Policy

If we ever need to change this privacy policy, we will update this page and the "Last updated" date above. Since we don't collect any contact information, we cannot notify users directly of changes. We recommend checking this page periodically if you have concerns about privacy.

Contact Us

If you have any questions about this privacy policy or DevPulse's privacy practices, you can reach us through our support repository or the contact information provided on the App Store.

Privacy Summary

DevPulse is local-first by design. It fetches release data straight from the sources you pick, keeps everything on your device or in your own iCloud account, and sends us nothing — because there is no "us" for it to send anything to. No accounts, no analytics in the app, no backend.