Privacy Policy
The short version is that we don't collect your information. Everything MacMon finds stays on your Mac, and we never receive it.
This policy covers the MacMon app for Mac, including its bundled macmon command-line helper ("MacMon", "the app"), and this website. Both are published by Backsketch ("we", "us"). If you have questions, email [email protected].
In brief
- We don't collect, store, sell, or share any personal information. MacMon has no servers, and nothing it finds is sent to us or anyone else.
- MacMon has no accounts, ads, analytics, crash reporting, or tracking, and contains no third-party SDKs.
- MacMon makes no network connections. Its scans run with network requests refused. The only exception is an optional command-line feature you run by hand, described below.
- What MacMon records is stored in a private folder on your Mac, readable only by your user account. You can delete it at any time.
What MacMon reads on your Mac
MacMon is a security monitor, so it reads information about how your Mac is set up and what happens on it. It reads this information only to show it to you. It doesn't send it anywhere. Depending on which features you turn on, it reads:
- Security settings: FileVault, System Integrity Protection, Gatekeeper, firewall, software update, screen lock, sharing services, and similar settings.
- Things that start automatically or are trusted: launch agents and daemons, login items, privileged helpers, kernel and system extensions, configuration profiles, trusted certificates, admin accounts, and system files such as
sudoers,hosts, and SSH configuration. - Network setup: DNS resolvers, proxies, firewall exceptions, and programs listening for network connections.
- Installed software and browser extensions: app and command-line tool names, versions, code signatures, and where they came from, and the extensions installed in your browsers.
- Sign-in and system activity from the macOS system log: screen lock and unlock, failed unlock attempts,
sudocommands, SSH and console sessions, startups and shutdowns, package installs, and downloads (from the macOS download quarantine record). - Credential hygiene: whether credential files and SSH keys are readable by others, and whether your shell history contains text that looks like a secret token. For shell history, MacMon stores only a count of matching lines. It never stores the secrets themselves.
- AI coding agents (Claude Code and Codex): their configuration (hooks, MCP servers, plugins, skills, permissions, and settings) and their session transcripts on your Mac, so it can check the tool calls they made. If you install the MacMon logging hook, the agent also passes each tool call to MacMon as it happens.
- Privacy permissions (optional): the apps you've granted access such as Full Disk Access, Accessibility, or Screen Recording. Reading these needs Full Disk Access, see below.
MacMon reads file contents only where a check needs them, such as configuration files. It doesn't read or store the contents of your documents, and it doesn't monitor network traffic.
What MacMon stores, and where
MacMon keeps its history in a database at ~/Library/Application Support/macmon/ on your Mac. That folder is created so that only your user account can open it. Your settings and allowlists are kept in ~/.config/macmon/config.json, and a few app preferences are kept in the app's standard macOS preferences.
Because MacMon is a security tool, its history can include sensitive details. You should treat it as you would your shell history. For example, it can include:
- The full text of commands your AI agents ran. If an agent ran a command containing a password or token, that text is in the database.
- The prompt you typed before an AI agent's flagged tool call (up to 600 characters), and the paths of files agents read or wrote, but not the files' contents.
sudocommand lines and other system log messages, and the web addresses of files you downloaded.- For AI agent settings, the names of environment variables and MCP server settings. Secret values are replaced with a placeholder or a one-way hash.
This information never leaves your Mac through MacMon. It's not included in iCloud or synced between devices by MacMon. It can be included in your own backups, such as Time Machine, like any other file in your home folder.
How long it's kept
Informational and low-severity events, and recorded AI tool calls, are deleted automatically after 180 days. You can change this period in the configuration. Medium and high-severity alerts are kept until you delete them.
Notifications
When a check finds a new medium or high-severity alert, MacMon shows a macOS notification. You can turn this off with Notify about new alerts in MacMon's Settings › General, and MacMon asks for notification permission only from that screen. A notification can include a short description of the alert, which may contain part of a command. Notifications follow your macOS notification settings, including whether previews appear on the lock screen.
Full Disk Access (optional)
To list the privacy permissions you've granted to other apps, MacMon's background helper needs Full Disk Access, which you grant yourself in System Settings › Privacy & Security › Full Disk Access. MacMon uses this access only to read the two macOS privacy permission databases. Everything else in MacMon works without it.
Administrator actions (optional)
MacMon never asks for your password on its own. One optional feature, Protect the hook, installs a copy of the AI agent logging hook in a system location so that agents can't turn it off. Before it runs, MacMon shows you the exact file and the command, and macOS asks for an administrator password. It doesn't send anything anywhere.
Network use
MacMon doesn't connect to the internet. The app makes no network connections, and its background scans run with all network requests refused. It doesn't check for updates or contact any server run by us.
Optional online vulnerability lookup
The macmon command-line tool has one feature that uses the network, and it runs only when you type macmon vulns --online yourself. It sends the names and versions of software packages found on your Mac to OSV.dev, a public vulnerability database run by Google, and downloads the U.S. Cybersecurity and Infrastructure Security Agency's list of known exploited vulnerabilities. Like any internet request, this reveals your IP address to those services. Their own privacy policies apply. We never receive this information. The MacMon app never runs this lookup.
This website
This website is a set of static pages. It uses no cookies, analytics, or tracking scripts, and it has no forms. It's hosted on Cloudflare Pages, whose servers may record standard request information such as your IP address for security and operations, as described in Cloudflare's Privacy Policy. We don't turn on Cloudflare Web Analytics or any other analytics for this site. If you download MacMon from a link on this site, the download host's privacy policy applies to that request.
If you email us, we use your email address and message only to reply to you. We don't add you to a mailing list or share your message.
Your choices and deleting your data
- You choose which features to turn on. Background checks, the AI agent logging hook, and Full Disk Access are all off until you turn them on, and you can turn each off again in MacMon's Settings or in System Settings. Notifications can be turned off in MacMon's Settings › General.
- To pause MacMon, use Pause in the app. Scheduled checks stop until you resume.
- To delete everything MacMon has recorded, quit MacMon and delete the folder
~/Library/Application Support/macmon/. To delete your settings too, delete~/.config/macmon/. The support page explains how to uninstall MacMon completely.
Because we don't hold any of your data, we have nothing to give you, correct, or delete on our side. Your data is fully under your control on your Mac.
Children
MacMon isn't directed at children, and it doesn't knowingly collect information from anyone, including children.
App Store privacy details
If MacMon is offered on the Mac App Store, its privacy label reads Data Not Collected, which reflects this policy.
Changes to this policy
If MacMon's handling of information changes, for example if a future version adds a feature that uses the network, we'll update this page and the "Last updated" date before that version is released, and describe the change in the release notes.
Contact
Backsketch
[email protected]