The app does not collect your data
The Installory app does not send personal data, package inventory, package names, install locations, provenance evidence, generated scripts, settings, or scan results to the developer or any server.
Installory's Mac App Store privacy label is Data Not Collected. The app is local-first, read-only, and built without tracking, analytics, ads, or accounts. The optional website support form is described separately below.
Last updated: 15 July 2026.
The Installory app does not send personal data, package inventory, package names, install locations, provenance evidence, generated scripts, settings, or scan results to the developer or any server.
Installory is designed to run without network calls. Package descriptions are bundled with the app, and package inventory is read from local metadata on your Mac. Your package inventory is not uploaded, synced, sold, or shared.
Installory stores package metadata, scan history, snapshots, settings, and—only if you enable install tracing—provenance evidence inside its sandbox container on your Mac. This data is used only to provide the app's local features.
Installory is sandboxed and uses the macOS folder picker for access to package-manager directories outside its container. Directory access is read-only and user-granted. Installory persists access using macOS security-scoped bookmarks so it can scan the same selected folders later.
Installory does not execute cleanup scripts, run uninstall commands, remove packages, or modify package-manager directories. When you request cleanup, the app generates a script or command for you to review and run manually in Terminal.
When you choose an export or save action, Installory writes only to the location you select in the macOS save dialog. Exported inventory, reports, and generated scripts remain on your device unless you choose to share them yourself.
Install tracing is off by default. If you enable it in Settings → Privacy and grant read access to your home folder, Installory can inspect local zsh, bash, and fish history plus selected Claude Code project-log fields, including Bash tool events and nearby session context. It compares those records with package timestamps to produce best-effort install evidence. Evidence is processed and stored locally and is never uploaded. You can turn tracing off, revoke folder access, and erase saved install history from Settings.
The website itself has no analytics, advertising, or tracking. If you submit the support form, your name, email address, and message are sent to Netlify, the form processor, and delivered to the developer so the request can be answered. The data is not sold or used for advertising. Form submissions and related support correspondence may be retained for up to 12 months, then deleted unless an active issue or legal obligation requires longer. You can request earlier deletion by emailing will.ricchiuti@gmail.com.
For privacy or support questions, email will.ricchiuti@gmail.com or open an issue at github.com/willytop8/Installory.