Privacy
A clear, honest data boundary.
EasyMacDPI does not use accounts, advertising, analytics SDKs, or tracking. This policy describes exactly how EasyMacDPI works, without hiding the implementation details.
Last updated: August 30, 2026
How EasyMacDPI works
- Outbound TCP and UDP connections are evaluated locally only to distinguish HTTPS and QUIC traffic. HTTPS is relayed directly to the server you requested, not to an EasyMacDPI server.
- The first TLS ClientHello is inspected in memory and reframed as valid TLS records. Traffic content, domains, and endpoints are not stored as per-flow diagnostics.
- Legacy last-endpoint diagnostic keys written by earlier test builds are removed when the app or extension starts.
- QUIC/UDP 443 is rejected locally while protection is enabled so clients can use TCP/TLS.
- Language, theme, and menu-bar preferences stay in the app container. Protection configuration, extension status, time, and limited errors stay locally in the App Group.
- Only lifecycle events such as start, stop, and errors go to macOS Unified Logging; remote endpoints and hostnames do not.
- There is no automatic crash report, telemetry, FormSubmit request, or direct DoH request.
User-initiated support
The Feedback button opens an editable draft in your email app. It shows the app/build and macOS version. Nothing is sent to EasyMacDPI unless you press Send.
A support email you voluntarily send may be retained by email providers and the developer only as long as needed to respond and resolve the request. You can request deletion through the same address.
General terms
- There is no user account or identity request.
- There is no advertising, behavioral analytics, marketing profile, or cross-app/cross-site tracking.
- Local settings can remain until the app or related files are removed. Support and crash reports sent to the developer may be retained only as long as needed for support and defect resolution.