Privacy Policy
Last updated July 21, 2026
DittoBot is built to run entirely on your own Mac and talk directly to the network destinations — and, if you use them, the SSH sources — you configure yourself. This policy explains, in plain language, what that means for your data.
The short version
- DittoBot has no server and no account system. There is nothing for us to store on your behalf, because we never receive your data.
- Every file it copies moves directly between the machines you configure — your Mac, an optional remote Linux source reached over SSH, and the SMB network destination(s) you choose. We are never in that path.
- App settings (folder paths, destination and SSH source hostnames, preferences) are stored locally in a settings file in your user Library folder. They never leave your Mac.
- Network drive credentials and SSH credentials (passwords or private-key passphrases) are stored only in the macOS Keychain, scoped
ThisDeviceOnly— never eligible for iCloud Keychain sync, never written to the settings file. - DittoBot contains no analytics SDKs, no advertising SDKs, and no third-party trackers of any kind.
Information we collect
None, directly. DittoBot does not operate any servers that receive, log, or process your files, folder names, or usage activity. The app does not ask for your name, email address, or any account credentials of its own.
Information stored on your device
The following stays entirely on your Mac, in a local settings file (not in this app's Keychain item):
- The folders you've chosen to mirror (local or on a configured SSH source), and which destination(s) each one is assigned to
- The hostnames and share names of your configured network drives, and the hostnames and usernames of your configured SSH sources
- App preferences — versioning, exclude patterns, bandwidth throttle, launch-at-login
Network drive passwords and SSH credentials (a password, or a private key's passphrase) are kept
separately, only in the macOS Keychain, with AfterFirstUnlockThisDeviceOnly
accessibility — readable while your Mac is unlocked (or has been since boot, so scheduled overnight
backups still work), and never eligible for iCloud Keychain sync or an unencrypted backup/restore onto
another Mac.
Where your files actually go
DittoBot mounts the SMB share(s) you configure and copies your mirrored folders there directly, over
your own network. If a folder comes from a configured SSH source instead of your Mac, DittoBot reads
it directly from that machine over an SSH/SFTP connection using the system's own ssh/sftp
tools — your password or key passphrase is supplied to those tools directly by the app, never typed
into a script or logged. Either way, it doesn't route file contents through any intermediary server of
ours — the destination and any SSH source are whatever hardware you pointed it at, and you are
responsible for that hardware's own security and backups.
Non-sandboxed by necessity
DittoBot is not distributed through the Mac App Store because it needs raw filesystem access, SMB mounting, and background file-system event monitoring that Apple's App Sandbox does not permit. It is signed and notarized directly with Apple using a Developer ID certificate, and distributed as a direct download instead.
Third parties
DittoBot does not integrate with any third-party analytics, advertising, or crash-reporting service. The only "external" systems involved are the SMB network destinations, and any SSH sources, you yourself configure.
Children's privacy
DittoBot is a general-purpose file utility and is not directed at children. It does not knowingly collect information from anyone, of any age, because it does not collect information at all.
Deleting your data
Removing a folder or destination inside the app stops it from syncing immediately; it does not delete anything already copied to your network destination. Uninstalling DittoBot removes its local settings file. Saved Keychain credentials can be removed independently via Keychain Access if you'd like to clear them.
Changes to this policy
If this policy changes, we'll update the date at the top of this page. Since DittoBot doesn't collect contact information, we're not able to notify you directly — check back here if you'd like to stay current.
Contact
Questions about this policy? Visit the Support page.