Skip to content

Updately

Privacy Policy

Last updated 30 September 2026

Updately is made by Aqib Javed, an individual developer based in Karachi, Pakistan. This policy explains what the Updately app and the https://updately.dev website collect, why, and what you can do about it. I wrote it to be read, not skimmed past.

Summary

  • Updately runs no analytics, tracking, ads or crash reporting. No server of mine ever receives your app scan.
  • A small licensing server runs the free trial and licenses. It stores a hashed ID of each Mac that starts a trial (even without an account, so a trial can’t be restarted) and, for accounts, the plan and the Macs added to it.
  • To find updates, the app talks directly from your Mac to Apple, Homebrew, GitHub, each app’s own update feed (Sparkle or Electron) and the matching download servers. Those services see your IP address and which apps are being checked.
  • Your scan results and preferences stay on your Mac.
  • An account is optional. If you create one, your app list (the “Library”) is backed up to Google Firebase so you can restore it on another Mac. Never your files, documents or any app’s data.
  • Purchases are handled by Polar, the Merchant of Record. I receive the order details needed to grant your license, never your card details.
  • You can delete your Library and account at any time from inside the app.
  • The website sets no cookies and runs no analytics.

Who is responsible

Aqib Javed, Karachi, Pakistan, is the developer of Updately and is responsible for the data described here. You can reach me at support@updately.dev.

What stays on your Mac

Updately scans the apps in /Applications and ~/Applications and checks each one for updates. The results of that scan, and your preferences (ignored apps and versions, check schedule, notch panel settings, quiet hours, appearance), are stored only on your Mac.

If you sign in, the sign-in session (your email, name and the tokens that keep you signed in) is stored in the macOS Keychain on that Mac. The Keychain also holds the latest signed license token from the licensing server (so the app can work offline), the start of this Mac’s free trial and the latest server time the app received.

Services the app contacts to check for updates

To check for and install updates, the app sends requests directly from your Mac to these services. Updately does not route them through any server of mine.

  • Apple’s App Store lookup service (itunes.apple.com), for apps from the Mac App Store.
  • The Homebrew cask index (formulae.brew.sh).
  • GitHub’s API (api.github.com), for apps that publish their releases on GitHub.
  • Each app’s own Sparkle update feed, at whatever address that app’s developer chose.
  • Electron apps’ update feeds: the vendor’s host named in the app’s app-update.yml, or GitHub releases (github.com) for apps that use electron-updater.
  • The download server named by that source, when you install an update.
  • google.com, only if you click “Get it yourself” for an app with no known website: your browser opens a Google search, which sends the app’s name.

These requests reveal your IP address and which apps are being checked to the service that receives them. The app identifies itself with the User-Agent “Updately/1.0 (macOS)”. Each service handles that data under its own privacy policy, which I don’t control.

Your account (optional)

Updately works without an account. If you choose to create one, you can sign up with an email address and password, or sign in with Google. Accounts are provided by Google Firebase Authentication (Google LLC).

When you sign up you give a name, an email address and a password. The password goes to Firebase Authentication, which stores it hashed. I never see it.

Firebase sends account emails (confirming your email address, resetting your password) from noreply@updately.dev. Replies go to support@updately.dev.

Your Library backup

With an account, Updately backs up your Library to Google Cloud Firestore (Google LLC), stored under your account. It syncs every non-Apple app in /Applications and ~/Applications, including apps you’ve told Updately to ignore. It contains:

Your profile

  • Name, email address, when the account was created and when you last signed in.

For each app

  • Name, bundle identifier, and for each of your Macs: the installed version, whether it’s installed there, and when it was last seen.
  • Where its updates come from, with source details such as the Homebrew cask name, Sparkle feed address, GitHub repository, App Store link and the app’s homepage.
  • The developer’s Team ID and the app’s public update-signing key, when the app has them.

For each Mac

  • The name you give it (by default, your Mac’s name) and its model identifier.
  • When it was last seen.
  • A hashed hardware identifier: a salted SHA-256 hash of the Mac’s hardware UUID (the salt is a fixed string built into the app). The raw UUID never leaves your Mac. It is used to tell your Macs apart.

The Library never contains your files, your documents, or any data belonging to the apps themselves. Database security rules restrict each account to its own data.

Why: so you can restore your apps onto a new Mac and see which Mac has what.

Trials and licenses

To run the free trial and licenses, the app talks to a licensing server at https://updately.dev/api. It runs as Netlify Functions, hosted by Netlify, Inc., and stores its records in the same Google Cloud Firestore database as the Library, in collections that the app itself can never read or write. It never receives your app list or scan.

The trial record (with or without an account)

When you finish setting up Updately on a Mac (onboarding), it sends that Mac’s hashed hardware identifier (the salted SHA-256 hash described above; the raw UUID never leaves your Mac). This happens even if you never create an account. The server stores:

  • the hashed hardware identifier;
  • when the trial started;
  • if you were signed in, the ID of the first account seen on that Mac.

Why: each Mac gets one free trial. Keeping this record is what stops a trial being restarted by reinstalling the app or making a new account, so it is kept indefinitely. If you delete your account, the account ID is removed from it and only the hash and start time remain.

Your license (with an account)

If your account has a license, the server stores, under your account ID:

  • your plan, how many Macs it allows, and how it was granted (a purchase, a code, or a manual fix by me);
  • for each Mac you add: its hashed hardware identifier, its name and model identifier as the app reports them, when it was added and when it last checked in.

When the app checks your license, it sends your sign-in token, this Mac’s hashed hardware identifier, name and model. The server answers with your plan, your Macs and a signed license token. The app checks in with updately.dev when it opens (after onboarding finishes; the first trial check happens only then), when it comes to the front, every 15 minutes while it runs, before Update, Update All, Install or Uninstall, when you sign in, when the plan window opens, and when you press Check Again.

Codes

Codes are stored only as a one-way hash with their last four characters. When you redeem one, the server records which account redeemed it and when.

Purchases

Purchases are not open yet. When they are, payments are handled by Polar (polar.sh) as Merchant of Record. Polar is the seller of record and handles the payment, your card details, sales tax or VAT and invoices, under its own terms and privacy policy. I never receive your card details.

After a purchase, Polar sends the licensing server the order: its order ID, the product, the amount and currency, the email address Polar has for you, Polar’s customer reference, and your account ID. The server stores these to grant your license, and to take it back if the order is refunded or charged back.

Server logs

Netlify processes every request to the licensing server and logs standard request data (such as IP address, browser or app user agent, and time) for security and rate limiting. The server’s own logs record errors without request contents or identifiers.

Who can see it

Only I (and my hosting providers acting as processors) can see license, device, code and order records. I see them through an admin page that requires an admin account and a one-time code from an authenticator app. Every admin action is logged with the admin account’s email, the action, when it happened, and, for a change to a license, the account ID it applied to.

The website

https://updately.dev is a static website hosted by Netlify. It sets no cookies, runs no analytics and its public pages have no forms. Like any website, the hosting provider logs standard request data (such as IP address and browser user agent) for security and operations. If I ever add analytics, I will update this policy first.

How long data is kept

  • Account and Library data: for as long as your account exists.
  • Trial records: indefinitely, as explained above.
  • License and device records: for as long as your account exists.
  • Records of codes you redeemed: for as long as your account exists; after that, the code is kept as used with no link to you.
  • Order records: kept for my accounting. When your account is deleted, your account ID and email are removed from them, leaving the order ID, product, amount, currency, dates and Polar’s customer reference.
  • Admin log entries: kept as a record of admin actions.
  • Data on your Mac: until you remove the app or its data.

Deleting your data

In the app, go to Settings › Account › Delete My Library and Account…. This removes all of your Library data and the account itself, immediately, from the database. Copies may remain in Google’s backups for a limited period under Google’s own policies. You can also ask me to delete it by emailing support@updately.dev.

Deleting your account also clears your data on the licensing server, first, while you are still signed in:

  • your license and every Mac on it are deleted (this ends the license, and it can’t be restored);
  • trial records keep only the hardware hash and start time: your account ID is removed. The record stays so the Mac can’t start a second trial;
  • codes you redeemed stay marked as used, with your account ID removed;
  • order records keep only what accounting needs (order ID, product, amount, currency, dates and Polar’s customer reference); your account ID and email are removed. Polar keeps its own records of the sale under its policy.

Your rights

You can ask me for a copy of your data, to correct it, to delete it, or to export it. Email support@updately.dev from the address on your account. You can withdraw from all of this at any time by deleting your account. Depending on where you live, you may have further rights under local law, and you may be able to complain to your local data protection authority.

International transfers

Firebase and other Google services may process your account, Library and license data in the United States and other countries. Netlify processes requests to the website and the licensing server in the United States and other countries. Polar processes payments under its own policy.

Children

Updately is not directed at children under 13 (or the minimum age in your country). I don’t knowingly collect their data. If you believe a child has created an account, email me and I will delete it.

Changes to this policy

If this policy changes, I will update it on this page and change the date at the top.

Contact

Questions about privacy: support@updately.dev. See also the Terms of Use and Refund Policy.