1. Scope
MacGuard is provided by Grisha Pipoyan (“MacGuard,” “we,” “us,” or “our”). This policy applies to the Mac app, iPhone app, MacGuard cloud API, push-notification delivery, and private cloud photo-evidence features. It does not apply to third-party websites, products, or services that have their own privacy policies.
MacGuard does not require a user account. The Mac and iPhone are connected through a time-limited pairing process that must be confirmed on both devices.
The Mac app is distributed free of charge from the official MacGuard website. The iPhone app is offered as a one-time paid download through Apple’s App Store. Version 1.0 does not contain a subscription or an in-app purchase.
2. Information handled by MacGuard
Information processed on the Mac
Depending on the protections you enable, the Mac app processes:
- motion and gyroscope readings, lid state, sleep/wake events, and input-event categories such as keyboard activity, pointer movement, clicks, and scrolling;
- alarm state, settings, and local diagnostic status;
- a randomly generated MacGuard device identifier and secret stored in Apple Keychain;
- your Mac’s device name, sent during pairing so the paired iPhone can identify the Mac;
- optional camera frames when Camera Evidence is enabled; and
- optional custom alarm sounds and locally stored incident video.
MacGuard does not record typed keys or their contents, continuously store motion history, scan unrelated files, collect location, or record microphone audio.
Information processed on the iPhone
- a Firebase Installation identifier used for pairing and push notifications;
- an Apple Push Notification service/Firebase Cloud Messaging registration token;
- your iPhone’s device name, shown to identify the paired phone;
- a randomly generated phone-control secret stored in Apple Keychain;
- pairing state, alert history, evidence metadata, and app preferences; and
- an optional custom notification sound copied into app-managed local storage.
The iPhone camera is used only when you choose to scan the one-time pairing QR code. MacGuard does not upload QR camera images.
App Store purchase information
Apple processes the purchase, payment method, Apple Account, billing, and refund information for the paid iPhone download under Apple’s own terms and privacy policy. The current MacGuard app and cloud service do not access or transmit an individual App Store receipt or purchase transaction, and they do not receive or store your payment-card details, Apple Account password, or Apple billing information.
As the seller, we may receive sales, proceeds, territory, tax, and financial reports through App Store Connect. These commercial reports do not give MacGuard your payment-card details or Apple Account password and are used for accounting, tax, fraud prevention, and business administration rather than advertising or cross-app tracking.
Information sent to the MacGuard cloud service
When cloud features are used, MacGuard processes pseudonymous device and installation identifiers; device display names; pairing and verification state; cryptographic hashes of control secrets; alarm event information; push-send status; evidence-photo metadata and deletion state; and, when enabled, up to three compressed JPEG face-presence frames for a real alarm.
The service also processes Firebase App Check material produced with Apple DeviceCheck on Mac and Apple App Attest on iPhone, along with network, rate-limit, security, service-operation, and error metadata needed to operate and protect the service. This can include IP address and request timing.
Camera Evidence
When you enable Camera Evidence and an alarm starts, the Mac can record up to about 20 seconds of camera-only incident video. That movie remains in MacGuard’s Application Support folder on the Mac and is never uploaded by Camera Evidence.
Face-presence detection runs locally on the Mac. It detects whether a face is present; it does not identify a person. While the alarm remains active, MacGuard may upload no more than three compressed JPEG evidence photos for the incident. Those photos are stored privately and can be requested only through the authenticated cloud service by the currently paired iPhone. MacGuard does not create public evidence URLs or provide an evidence-sharing feature.
3. How we use information
We use information to provide local alarm, pairing, remote alert, history, and evidence features; authenticate the paired Mac and iPhone; prevent unauthorized access; send requested push notifications; detect abuse; enforce rate limits; deduplicate requests; diagnose failures; operate the service; administer App Store sales, accounting, tax, and legally required financial records; and honor owner-authorized evidence-deletion requests.
We do not sell personal information. We do not use MacGuard information for targeted advertising, advertising measurement, data-broker activity, or tracking across apps or websites owned by other companies. MacGuard contains no advertising SDK and does not request Apple’s App Tracking Transparency permission.
5. Retention
- Pairing sessions and pairing codes expire after about five minutes and are removed through scheduled cleanup.
- Cloud rate-limit records are retained for the relevant window plus approximately 24 hours and then become eligible for scheduled cleanup.
- Cloud alert history and uploaded JPEG evidence are scheduled for deletion after approximately 30 days. Cleanup runs periodically, so deletion may not occur at an exact moment.
- Deleting cloud photos from the iPhone removes the photo objects and records a deletion state while retaining the alert timeline until its normal expiry.
- Local incident movies follow the retention choice on the Mac: 7, 30, or 90 days, or manual retention.
- Keychain credentials and local preferences remain until they are deleted, reset, unpaired where applicable, or removed with the app or its data.
- Infrastructure providers may retain security and operational logs under their configured retention periods and legal obligations.
- Apple retains App Store purchase and billing information under its own terms and retention practices. We may retain App Store financial, tax, and accounting reports for the periods required by applicable law.
6. Legal bases where required
Where applicable law requires a legal basis, we rely on performance of the service you request and administration of the App Store sale; our legitimate interests in providing a reliable device-security service, preventing abuse, securing the service, and diagnosing failures; your consent or affirmative feature choice for optional permissions and Camera Evidence where consent is appropriate; and compliance with legal obligations or protection of legal rights when necessary.
MacGuard does not use cloud data for solely automated decisions that produce legal or similarly significant effects.
7. Your choices and controls
You can choose whether to enable movement, input, lid/wake, remote alerts, and Camera Evidence. You can deny camera, notification, Input Monitoring, or owner-authentication permissions, although the related feature will not work.
On the Mac, you can choose local-video retention and use the owner-authenticated Delete All Local Videos action. On the paired iPhone, you can use device-owner authentication to delete an incident’s cloud JPEG evidence. You can also unpair the devices. Unpairing revokes the phone’s current control relationship but does not itself erase an alert timeline still within its retention period.
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to certain processing, or to receive information about how your data is handled. Because MacGuard has no account system, we may need the MacGuard device identifier and reasonable verification before acting on a request.
Purchases, charges, payment methods, and refund requests for the iPhone app are managed through Apple and the App Store. MacGuard cannot access or change your Apple payment method or Apple Account credentials.
8. Security
MacGuard uses encrypted network transport, Apple Keychain, app attestation, one-time pairing claims, server-side authentication and authorization, private cloud storage, bounded upload tickets, rate limits, and owner authentication for sensitive deletion actions. Direct client access to the underlying Firestore database and Storage bucket is denied. No security method can guarantee absolute protection, and local physical access to an unlocked device can create risks outside the app’s control.
9. International processing
Apple, Google, and their infrastructure may process information in countries other than the country where you live. Where applicable, those providers use their own legal and contractual mechanisms for international transfers.
10. Children
MacGuard is a device-security utility and is not directed to children under 13. We do not knowingly collect information from a child in a way that requires parental consent. If you believe a child has provided information improperly, contact us so we can review and delete it where appropriate.
11. Changes to this policy
We may update this policy when MacGuard’s features, providers, or legal obligations change. We will change the “Last updated” date and, when required, provide additional notice. Material product or data-flow changes will be reviewed against this policy before release.
12. Contact
Controller and seller: Grisha Pipoyan
Product: MacGuard
For privacy questions or requests, email support@getmacguard.com.