AppSheriff is made by Limonti. This policy covers the AppSheriff Mac app, this website (appsheriff.cc) and buying a license. It took effect on 23 September 2026.
- Sent to Apple
- Your apps' bundle IDs and the App Store country, to look up versions, dates and icons. You can turn this off.
- Never kept
- Your Apple ID, name and account ID. iOS includes them in each app's purchase record, and AppSheriff discards them.
- Kept on your Mac
- App Store lookups, measured sizes, when AppSheriff first saw each app, your settings and your license key.
- Kept by our store
- Your email address, license key and Stripe's payment reference, to deliver your license and send it again if you lose it.
- This website
- No cookies, no analytics, and no third-party scripts or fonts.
What does the Mac app send over the internet?
Only App Store lookups, and only while the setting "Check the App Store for each app" is on. It's in AppSheriff's Settings, under App Store, and it's on by default.
- Lookups. AppSheriff sends the bundle IDs of the apps on the selected device, such as
com.spotify.client, to Apple's public iTunes Lookup API atitunes.apple.com/lookup, with the two-letter code of the App Store country to search, such asus. Apple answers with each app's latest version, release dates, availability and icon address. iOS's own built-in apps aren't looked up. - Icons. AppSheriff downloads each app's icon from the address in Apple's answer, on Apple's servers, and keeps icons in memory only.
- Nothing else. It sends no device name, serial number or identifier, no Apple ID, and nothing about how you use your apps. There's no account, no analytics and no crash reporting of our own, and the license check happens on your Mac without contacting a server.
Like any request on the internet, these reach Apple with your Mac's IP address and a standard header naming the app and your version of macOS. How Apple handles them is covered by Apple's privacy policy. Links inside AppSheriff, such as an app's App Store page or its developer's website, open in your browser only when you click them.
Can I turn the App Store check off?
Yes. In AppSheriff's Settings, under App Store, turn off "Check the App Store for each app", and AppSheriff sends nothing at all. It still lists every app with its size, version and what it declares, and shows which apps iOS has offloaded, but it can't show App Store icons or say which apps are abandoned, stale, gone from the App Store or waiting for an update.
The same section sets which country's store is checked first. By default that's the one your iPhone buys from, read from its apps' purchase records, and the US and UK stores are checked after it.
What does AppSheriff read from my iPhone?
Over the USB cable, through Apple's own MobileDevice framework, it reads the list of installed apps and what each one reports about itself: its name, bundle ID and version, the permissions and capabilities it declares, whether iOS has offloaded it, and how much space it and its data take. It doesn't read what's inside your apps: no messages, photos or documents.
For each App Store app, iOS also returns its purchase record, which includes the purchaser's Apple ID, name and account ID (DSID). AppSheriff keeps only the non-personal fields: the purchase date, the release date, the App Store IDs of the app and its version, and the store it was bought from. The account fields are dropped as soon as the record is read. They're never stored, shown or exported, including in the diagnostic dump, which lists only the record's key names.
AppSheriff uses each device's name and identifier on your Mac, to tell devices apart and to name its files. They aren't sent anywhere.
What does AppSheriff keep on my Mac?
| Where | What |
|---|---|
~/Library/Caches/AppSheriff | App Store lookup results, reused for up to a day, and the app sizes measured on each device. |
~/Library/Application Support/AppSheriff | When AppSheriff first saw each app on each device and when its version last changed, and your license key once you've unlocked AppSheriff. |
com.limonti.appsheriff in macOS preferences | Your settings. |
| Wherever you save it | A diagnostic dump, if you export one. |
None of it is uploaded anywhere.
How do I delete it?
Quit AppSheriff. In Finder, choose Go > Go to Folder, paste a folder's path from the table and move that folder to the Trash, then do the same for the other one. Or run this in Terminal:
rm -rf ~/Library/Caches/AppSheriff "$HOME/Library/Application Support/AppSheriff"
defaults delete com.limonti.appsheriff Deleting the Application Support folder removes your license key from this Mac as well. The key is in the email you got when you bought AppSheriff, so you can activate again. To remove AppSheriff completely, move it from Applications to the Trash too.
What happens when I buy a license?
You pay on a checkout page run by Stripe, which processes the payment. Your card details go to Stripe, not to us, and Stripe's privacy policy covers what Stripe collects.
Once the payment goes through, our store, a small service we run on Cloudflare, creates your license key. It keeps a record of the purchase in a database on Cloudflare: your email address, your license key, Stripe's reference for the payment and its status, and when the key was issued and emailed. We keep this record to deliver your key and to send it again if you lose it. The store's logs name license IDs, not keys or full email addresses.
We email you from license@appsheriff.cc to deliver your license key, and later only if you ask us to send it again. Nothing else: no newsletters and no marketing. To prevent abuse, the page that re-sends keys limits how often one IP address or one email address can use it.
Your license key includes the email address you bought with, so AppSheriff can show who it's licensed to. The app checks the key on your Mac and never contacts our store to do it.
What does this website collect?
Nothing of its own. It's a static site with no cookies, no analytics, no tracking pixels and no third-party scripts or fonts. Its fonts and scripts come from appsheriff.cc itself, and the site's security policy blocks loading them from anywhere else.
The site is hosted by Cloudflare, which processes standard request data, such as your IP address, your browser and the page you asked for, to deliver pages and protect the site from abuse. Cloudflare's privacy policy explains how.
Will this policy change?
If anything described here changes, this page changes with it, and so does the date at the top.