Privacy
Local by default.
Cloud only by choice.
TinyRocket checks links on your Mac, against threat data on your disk. Cloud Check sends only a public registrable domain when you ask. The full link stays on your Mac, and the domain travels with a short-lived day token instead of your license, email or app account.
Stays on your Mac
Standard link checks
The analysis runs on your own machine, against a threat database on your own disk. The standard check makes no server request, because the data it needs is already on your Mac.
Leaves your Mac
Only a public registrable domain you choose to check
Cloud Check runs only when you ask. The app removes every subdomain, path, query, fragment and userinfo field locally. The request carries only the resulting public registrable domain and a short-lived day token, with no license, email or app account.
Never received
The full clicked link
The service cannot log or fetch the clicked URL because the app never sends it. The service creates no direct record pairing a day token or identity with a checked domain. The 30-day domain-age cache and short-lived network-abuse data are disclosed below; they can still permit timing inference.
The boundary is in the architecture.
The privacy claim comes from how each path is built, not from a request to trust our intentions:
- Standard checks read the threat database on your disk and make no network request.
- The Cloud Check route accepts one canonical public registrable domain and a short-lived day token. It rejects URLs, full hosts and extra fields.
- No analytics or advertising scripts: the site’s browser policy refuses outside scripts entirely.
- Stripe handles full payment credentials. TinyRocket keeps receipt facts; an owner-only support lookup can request the payment brand and last four from Stripe without saving them.
- Each Mac on a license is represented by a salted one-way fingerprint the app computes before sending it.
- Sign-in is a six-digit code that expires in minutes: no password to store means no password to leak.
Where the service does need data — a license needs an email and a trial needs a start date — the complete notice names the field, its purpose and its retention clock.
The one online feature
What Cloud Check sends, exactly
Goes up
One public registrable domain and a short-lived day token, without the full link, license, email or app account.
Comes back
Passive public registration age for that domain, when the registry makes it available, and whether it appears on Google’s malicious-site list.
Not sent with the link
The clicked URL, full host, subdomain, path, query, fragment, userinfo, license, email and app account. The day token is pseudonymous.
Neither TinyRocket’s server nor the lookups it makes on your behalf contact the destination website. Cloud Check cannot report redirects or page content, and does not claim that the link is safe. The dangerous-domain check runs against a copy of Google Web Risk’s list held on our server; only a matching four-byte fingerprint is ever sent to Google to confirm, and it is sent by our server, never by your Mac. Advisory provided by Google.
Then there is the boring version.
The complete notice names the browser settings, server requests, retention rules and processors used by TinyRocket.