Privacy Policy
Your data stays between you and your providers.
Dashlytics has no account system and no server of its own. This page explains what the app and this website do with data, who else is involved, and what you can do about it.
The short version
- No Dashlytics server. The app talks directly to the providers you connect. Nothing you see in the app passes through us.
- Your credentials stay in the Keychain. API tokens and Google sign-ins live in your device's Keychain and, if you leave iCloud Sync on, in your end-to-end encrypted iCloud Keychain.
- No tracking, no ads, no analytics. Neither the app nor this website uses analytics, advertising, or tracking of any kind.
- Purchases go through Apple and RevenueCat. They see your purchase history, never your provider data.
- Who we are
- The app
- Services the app contacts
- Google user data
- Purchases
- This website
- Your rights
- Deleting your data
Who is responsible
The controller for the processing described here is:
Jonas Gehring
Am Blumenstrich 32
69151 Neckargemünd, Germany
Email: apps@jonasgehring.com
We are not required to appoint a data protection officer. Questions about privacy go to the address above.
What the app handles, and where it stays
Dashlytics is a client for other services. You connect an account at a provider (for example Vercel, Namecheap, or Google Search Console), and the app shows you that account's data. We do not receive, store, or see any of it.
| API tokens and keys | Stored in the Keychain on your device, one item per connected account. With iCloud Sync on (the default), these items are synchronized through iCloud Keychain, which is end-to-end encrypted: Apple cannot read them. With iCloud Sync off, they never leave the device. Tokens are never written to logs, caches, or files. |
|---|---|
| Google sign-ins | The OAuth access and refresh tokens, and the email address of the Google account you signed in with, are stored in the Keychain in the same way. |
| Provider data | Projects, deployments, domains, analytics, and everything else the app displays is fetched directly from the provider when you open it. It is held in memory while the app runs. Summaries for site services are cached in a protected file inside the app's container on your device, excluded from backups, so they appear instantly next time. |
| Views and hidden items | The views you create and the items you hide are stored in the Keychain and follow the iCloud Sync switch, like your accounts. |
| Settings and recent items | Tab order, appearance, the app lock setting, and the last eight items you opened are stored on the device only. |
| Namecheap client IP | The public IP address you enter or detect for Namecheap is stored on the device only and never synchronized. |
| App lock | Face ID, Touch ID, Optic ID, and your passcode are handled entirely by Apple's operating system. The app only learns whether unlocking succeeded. |
Because none of this reaches us, we cannot view, export, or recover it for you. The legal basis for processing on your device is the performance of our contract with you, Art. 6(1)(b) GDPR.
Services the app contacts
The app only connects to the following. Every connection uses HTTPS without cookies or a shared cache.
The providers you connect
When you connect an account, the app sends requests with your token directly to that provider's API, for example api.vercel.com or api.namecheap.com, or to a self-hosted address you entered yourself. Like any server, the provider sees your IP address and the requests. The provider's own privacy policy applies to that account. Dashlytics is not affiliated with any provider.
Some actions change data at a provider, such as editing a DNS record or purging a cache. The app always asks for confirmation before it sends one.
Your project's own website
To show a project's icon, the app may load the favicon from that project's own HTTPS address. No third-party favicon service is used.
ipify
Namecheap and Name.com only accept requests from allowlisted IP addresses. When you open the connection form for one of these two registrars, the app asks api.ipify.org for your public IPv4 address, so you can copy it into the registrar's allowlist. ipify sees your IP address and nothing else: no token, no account data. This happens only on that form, never in the background.
Apple
The app checks itunes.apple.com for a newer version, sending only the app's bundle identifier. Apple processes App Store purchases, iCloud Keychain, and, if you agreed to share them with developers, crash reports and usage statistics under Apple's privacy policy.
Google user data
Google Search Console, Google Analytics, and Firebase Hosting connect through Google's OAuth sign-in. The app requests only these permissions:
openidandemail, to label the connected account with its email address.webmasters.readonly, to show your Search Console properties and performance.analytics.readonly, to show your Google Analytics properties and reports.firebase.hosting, to show your Firebase Hosting sites, releases, and domains.
Data from these Google APIs is fetched directly by the app on your device and shown only to you inside the app. It is never sent to us or to anyone else, never used for advertising, never sold, and never used to train AI models. No person at Dashlytics reads it.
Dashlytics' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke access at any time in your Google Account permissions, or disconnect the account in the app.
Purchases
Dashlytics Pro subscriptions, the lifetime purchase, and tips are sold through the App Store. Apple processes the payment; we never see your name, Apple Account, or payment details.
To know whether Pro is active on your devices, the app uses RevenueCat (RevenueCat, Inc., USA). RevenueCat receives an anonymous app user ID generated on your device, the App Store receipt with your purchase history, the app version, and basic device information such as the operating system and storefront country. RevenueCat never receives your provider credentials or any provider data. We use this data to unlock Pro and to see aggregate purchase figures. The legal basis is Art. 6(1)(b) GDPR. RevenueCat processes this data on our behalf and is bound by a data processing agreement; transfers to the USA rely on the EU Standard Contractual Clauses. See RevenueCat's privacy policy.
In the App Store's privacy label this appears as "Purchase History", not linked to your identity and not used for tracking.
This website
This website is hosted by Vercel (Vercel Inc., USA). When you visit it, Vercel's servers process your IP address, the page requested, the time, your browser's user agent, and the referring page, in order to deliver the site and protect it against abuse. These logs are kept for a short period and are not used by us for analytics. The legal basis is our legitimate interest in running a secure website, Art. 6(1)(f) GDPR. Vercel is bound by a data processing agreement, and transfers to the USA rely on the EU Standard Contractual Clauses and the EU-U.S. Data Privacy Framework. See Vercel's privacy policy.
The website sets no cookies, loads no fonts, scripts, or images from third parties, and uses no analytics. If you use the light/dark toggle, your choice is saved in your browser's local storage and never leaves your device.
If you write to apps@jonasgehring.com, for support or to be told about the launch, we use your address and message only to answer you, or to send that one launch email. We delete launch requests after the launch and support conversations once they are resolved, unless the law requires us to keep them. The legal basis is Art. 6(1)(b) or, for launch requests, your consent under Art. 6(1)(a) GDPR, which you can withdraw at any time by replying.
Children
Dashlytics is a tool for people who run websites and apps. It is not directed at children, and we do not knowingly collect data from them.
Your rights
Under the GDPR you have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to its processing, to data portability, and to withdraw consent at any time. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU country where you live or work.
Since the app keeps your data on your devices, the data we hold about you is limited to emails you sent us. If you want RevenueCat's purchase record deleted, write to us and we will ask RevenueCat to delete it.
Deleting your data
- One account: open the workspace, choose the account, and disconnect it. Its Keychain item is deleted on every device that syncs it.
- Everything: Settings → Disconnect all accounts removes every connected account together with your hidden and recently opened items. Views you created stay until you delete them.
- Google access: revoke it in your Google Account permissions.
- At a provider: delete the API token you created in that provider's dashboard.
- Deleting the app removes its local files. Synchronized Keychain items stay in iCloud Keychain until you disconnect them from another device or delete them in the Passwords app.
Changes to this policy
If the app or this website starts processing data differently, we update this page and the date at the top before the change ships. Material changes are also mentioned in the app's release notes.