Your files stay yours

Privacy Policy

Effective 11 October 2026 · LiveTree for macOS · Jeff Welling

LiveTree scans and analyzes storage on your Mac. It does not upload file names, paths, contents, scan results, or saved scans to our analytics service.

Filesystem data

For locations you choose to scan, LiveTree reads metadata such as names, paths, sizes, folder structure, file kind, timestamps, permissions, and readability. Verified Duplicates reads file contents only when you start that analysis. Quick Look may read a selected file and, for a cloud placeholder, may ask its provider to download it after LiveTree warns you.

Scan results stay on your Mac. A completed scan is saved only when you choose File → Save Completed Scan and pick a destination. That document can contain private names and paths; treat it as sensitive. Imported scans open read-only. LiveTree does not automatically upload or share these documents.

Mac App Store access

The Mac App Store edition runs in Apple's App Sandbox. You choose folders or volumes through the macOS picker; LiveTree reports access gaps when macOS prevents a complete scan. The separately distributed Direct edition runs outside the sandbox and has additional features, including a command-line tool, Finder-integrated compression, and local Time Machine restore-point deletion.

Product analytics

Product analytics is on by default after the first-run Feature Guide discloses it. Before you advance past that disclosure, a fresh installation creates no analytics identifier, queues no event, and attempts no analytics upload. There is no opt-in prompt. You can turn analytics off at any time in Settings → Advanced → Privacy & Diagnostics; that choice persists across launches, upgrades, and Restore Default Settings.

We send allowed event names, feature-use counters, performance buckets, closed diagnostic categories, app version and build, macOS major, major.minor, and full major.minor.patch version, architecture, and a random install-scoped identifier hash to TelemetryDeck. The hash is not derived from your hardware, Apple account, username, filesystem, or network. These categories correspond to Product Interaction, Performance Data, Other Diagnostic Data, and Device ID in the app's privacy manifest. They are used for analytics, not tracking, and are not linked to a person.

Analytics does not include file or folder names, paths, volume names or IDs, file extensions, file contents, scan results, exact sensitive disk measurements, exclusion rules, CLI arguments, raw errors, license keys, purchaser details, or payment details. The HTTPS connection necessarily exposes network routing information such as your IP address to the receiving service; LiveTree does not place it in its analytics payload.

You can inspect the exact pending and recently accepted payloads in Privacy & Diagnostics. The pending local queue keeps at most 500 events, 1 MiB, or seven days. Recent accepted history keeps at most 100 events, 256 KiB, or 48 hours. Turning analytics off cancels uploads, clears both local stores, and deletes the identifier. LiveTree attempts one final opt-out signal using that identifier; it is not queued or retried. Turning analytics back on creates a new unrelated identifier.

TelemetryDeck receives these analytics payloads. See TelemetryDeck's privacy information for its service practices.

Support messages

When you choose Send Feedback, LiveTree opens your email app with the text you wrote. You review and send it yourself. LiveTree does not submit support text directly. If you contact us, we receive what you choose to include; please omit private paths, filenames, screenshots, and logs unless needed and you are comfortable sharing them.

Contact

Questions about this policy or your data can go to support@livetree.ca. Our support page has help and contact guidance.