Privacy

Local means local.

RepoSweep is designed to inspect less, collect nothing, and leave every cleanup decision with you.

The app only goes online when you check for updates

RepoSweep has no analytics, no telemetry, no crash reporting, no background network activity, and no account system. File contents, file names, paths, scan results, and cleanup history never leave your Mac. The one and only time RepoSweep contacts the network is when you personally press “Check for Updates”: it fetches a small signed version file from reposweep.mlola.com and, if you choose to update, downloads the new installer. That request sends no identifying information about you. If you never press the button, RepoSweep never connects to anything.

Folders you choose

RepoSweep accesses only a folder you explicitly choose through the macOS folder picker. It does not scan your whole disk by default and does not run background scans.

Local history

Cleanup history is stored as a local file in your macOS Application Support directory. It records the selected root path, cleanup date, reclaimed size, the relative path and size of each moved item, and any failures. It never stores file contents. Delete the file at any time to erase the history.

Cleanup behavior

RepoSweep does not permanently delete files. Selected items are validated again and moved to macOS Trash, where they can be restored until Trash is emptied.

Purchases and licensing

Payments are processed in your browser by Paddle, acting as merchant of record, under Paddle's privacy policy; RepoSweep itself never sees your payment details. To issue your license we receive the email address you used at checkout. Your license key encodes that email address and is verified cryptographically on your Mac — there is no activation server and the app never “phones home.” The key is stored as a local file in Application Support, readable only by your user account.

Website

This website is static, sets no tracking cookies, and runs no third-party analytics scripts. To understand which pages are useful we count page views on our own server: the log records the page, time, referrer, and whether the request looked like a bot — never an IP address, cookie, or full browser fingerprint, so nothing in it can identify you. The pricing page loads Paddle's checkout script to process purchases; during checkout Paddle may set cookies strictly needed for payment, under its own policy. Standard VPS access logs may record network metadata such as IP address, request path, browser user agent, and request time for security and operational purposes; logs rotate automatically.

Contact

Questions can be sent to hello@mlola.com.