Your files are not our business.
Purser is a file manager, not a data service. There is no Purser account, analytics SDK, crash-reporting upload or record of the places you browse.
Never collected
File names, paths, contents, activity, usage analytics, device fingerprints and crash reports.
Private iCloud
Settings and connection definitions sync through the private CloudKit database of your Apple Account when you enable it.
iCloud Keychain
Passwords and authentication secrets for connections you explicitly save.
Device-local
Full Disk Access, folder grants, automation roots and the operating system’s own privacy decisions.
What connects to the network
Purser contacts a remote file service only when you browse or operate on a connection you configured. Remote servers receive the requests required by their protocol; Purser does not proxy that traffic through Spectrumlabs.
When iCloud Sync is enabled, Purser contacts Apple CloudKit for settings and connection definitions. It also checks its HTTPS Sparkle update feed. Every update package is independently verified with Purser’s embedded EdDSA public key before installation can proceed.
iCloud configuration sync
Normal preferences and saved connection definitions can converge through the private CloudKit database of your Apple Account. Spectrumlabs does not run a sync server and does not receive those records. Settings shows the live state, lets you sync immediately and lets each Mac opt out.
Passwords, private keys and other connection secrets are never written to CloudKit. They use iCloud Keychain.
Security grants remain local because permission must reflect the person’s choice on that specific Mac.
Distribution security
- The app and DMG use a Developer ID Application certificate issued to Spectrumlabs B.V.
- Apple’s notarization service scans every public release and issues a ticket that is stapled for offline verification.
- Hardened Runtime and library validation remain enabled in shipping builds.
- Sparkle update metadata and every enclosure use a separate EdDSA signing key.
- SFTP known-host checks distinguish matched, unknown, changed and revoked server keys.
- The optional MCP server is off by default, scope-limited and approval-gated for changes.
Control and deletion
Delete a saved connection in Purser to remove its definition and secret; that deletion converges to other participating Macs. iCloud Keychain follows the Apple Account’s Keychain behavior. Uninstalling the app does not delete files you browsed or remote data.
A supporter serial is stored as a synchronizing Keychain item and verified entirely on the Mac. If you voluntarily contribute cryptocurrency, the transaction is public on its blockchain and you choose what identifying details to include when requesting the serial by email. Purser does not send serial or usage data to Spectrumlabs.
Questions or a vulnerability?
Contact the publisher through the project repository before sharing security details publicly. Include the Purser version, macOS version and the smallest reproducible description; never attach unrelated private files.