Back to Hotspot Guard

Hotspot Guard Privacy Policy

Effective date: August 23, 2026

Hotspot Guard is a macOS menu bar app published by TinyNeed. It creates no account, shows no ads, tracks no location, and sells no personal data. This page describes every case in which the app sends anything off your Mac, and what that data is.

What stays on your Mac

The work the app exists to do is entirely local. Per-app traffic measurement, your monthly budget and its forecast, the rules you set, the built-in knowledge pack of 149 common apps and daemons, the record of what the guard did and why, and any explanation the app has already looked up are read and written on your machine only. None of it is uploaded, and there is no server-side copy of it to request or delete.

The update check (optional, off by default)

The app asks once, inside the menu panel, whether it may check for updates. It sends nothing until you say yes, and saying no means it never connects for this purpose.

If you allow it, then at most once every 24 hours the app requests an update manifest from this website. That request carries the app version, which is part of the address requested, and your macOS version, which is sent in the standard User-Agent header. It carries no account, no identifier we assign, no app names, and no usage data.

This check is not suppressed while you are on a hotspot. The request and its response are a few hundred bytes.

Explaining an unknown process (optional, off by default, click only)

When the built-in knowledge pack does not recognise a process, the app can look it up online. This is a separate permission from the update check, granted separately, and it never runs on its own: it runs only for the one process whose Explain online button you click.

What is sent is the process name alone — for example com.apple.photoanalysisd — over an encrypted connection to the Hotspot Guard lookup service, which asks a large language model through the routing provider OpenRouter and returns a short description. No traffic figures, no other process names, no file paths, and no identifier accompany it.

The service caches answers by process name so a name is looked up once rather than once per user, and the answer is also cached on your Mac so the same name is never sent twice from your machine. Its request logs record the outcome of a request and whether it was served from cache; the process name and the network address are deliberately not written to a single joined log record.

Hotspot Guard Plus licensing

This section applies only if you buy Plus. Activating a license sends your license key and a device label of the form Hotspot Guard on <your computer name> — the name macOS already uses for your Mac — so that you can recognise and release your own activations against the three-Mac limit. The service returns an activation identifier, which the app stores locally and sends back when it revalidates the license roughly every 14 days, and when you deactivate a Mac.

The revalidation call carries the license key and that activation identifier, and nothing about how you use the app.

For an activation attempt, the service stores only the action type, a closed result category such as success or invalid, whether the store is in live or test mode, and the time. This aggregate event does not contain the license key, device label, activation identifier, network address, or a stable user or installation identifier. A failure to write this event never changes the activation result.

Buying Plus

Purchases are processed by Creem (Armitage Labs OÜ) as merchant of record. Creem collects your email address, payment details, and any billing or tax information the sale requires, and handles them under its own privacy policy; your card details are never sent to us and we never see them. What reaches us is the resulting license record. Your license key is delivered to the email address you give at checkout.

The Get Plus links first pass through a source-specific path on this website so we can count, in aggregate, whether the purchase source was the website, the App's Plus page, or the one-plan limit. These paths use no cookie, query parameter, installation ID, or client-side analytics script.

Creem also sends the service a signed notification for a completed checkout, refund, or dispute. Across the website's aggregate source counts and the service's event table, the retained funnel data is limited to purchase source counts plus the event type, amount, currency, time, and result. The service does not store your email, name, customer ID, billing address, payment details, or the original notification payload. We do not assign a stable identifier and do not join these events into a user journey.

This website

These pages are hosted and served by Cloudflare. They carry no analytics script, no advertising, and no cookies of ours. What does exist is what any web server sees: Cloudflare's edge logs the requests it serves, including the network address they came from. The same is true of the app's update check, because it is an ordinary web request to this site — so neither this site nor that check is fully anonymous, and we do not claim otherwise. Cloudflare processes that data under its privacy policy. Other TinyNeed tools, some of which do carry advertising, are covered by the site privacy policy.

Children

Hotspot Guard is a general utility and is not directed to children under 13. We do not knowingly collect children's personal information.

Changes

If the app's data practices change, this page and its effective date are updated before the new practice ships, and any new outbound connection is added to the list above.

Contact

Questions or privacy requests: hello@tinyneed.com. We reply within three business days.