Privacy Policy

Last updated: September 9, 2026

Overview

Mint is a local-first macOS application designed to help you organize files on your Mac. We built Mint with a fundamental commitment to your privacy: your files never leave your computer. This policy explains in detail what data Mint does and does not access, process, or transmit.

Controller and Legal Basis

DZG Studio LLC, 1301 16th St, APT 415, San Francisco, CA 94103, United States, is the controller for Mint’s first-party service records. Optional product analytics in all editions begin only after you separately choose to share usage analytics. The Direct and Setapp editions also send the limited setup signal described below after the Welcome acknowledgement. The Mac App Store edition requires your separate analytics choice for every product event, including setup completion; agreeing to the Terms and acknowledging this Privacy Policy does not enable that collection. You can turn optional analytics off at any time in Mint Settings without losing functionality; doing so stops future optional collection and does not affect processing that was lawful before withdrawal.

Where applicable, we process Mint account, purchase, entitlement, and connected-device records to provide the product you requested, restore paid access, meet accounting or legal obligations, and protect the service from fraud and abuse. We process support messages to answer your request. We do not sell or share personal information for cross-context behavioral advertising.

You may have rights to request access, correction, deletion, restriction, or portability of personal data, to object where processing relies on legitimate interests, and to lodge a complaint with your local data-protection authority. Email [email protected] to exercise a right. We may need enough information to verify that a request concerns you, but we do not collect additional identifying data solely to make anonymous installation records re-identifiable.

Local-First Architecture

Mint operates entirely on your Mac. All core functionality runs locally without requiring an internet connection:

  • File analysis and organization — All scanning, categorization, and file-moving operations happen on your local filesystem. No files, file contents, filenames, or directory structures are ever uploaded to any server.
  • OCR text recognition — Document text extraction is performed entirely on-device using the Apple Vision framework. Extracted text is processed in memory and never transmitted externally.
  • Content-aware processing — Mint uses on-device metadata analysis, filename tokenization, OCR, language detection, and image classification to organize files and power cleanup search. All processing runs locally on your Mac.
  • Activity logs — Mint maintains logs of its operations (file moves, renames, organization actions) stored locally at ~/Library/Application Support/Mint/. These logs never leave your machine and exist solely so you can review and undo actions.

Privacy-Minimized Product Analytics

Mint can send a small set of first-party product milestones, subject to the edition-specific choices below, to help us find onboarding drop-off, confirm that releases reach active installations, and understand whether core work completes successfully. The fixed event list covers the first app launch after the onboarding acknowledgement, one activation per Mint release, weekly activity, later onboarding pages and completion, an onboarding page that could not do its job, the Full Disk Access prompt and grant, first-use milestones, free-limit blocks, upgrade-checkout clicks, and each attempted disk cleanup, memory release, folder organization, app uninstall, and file redaction. For those core operations, the only additional detail is a fixed feature, entry surface, outcome (such as success, partial, failed, cancelled, blocked, or no change), and fixed reason code. When macOS records that Mint itself crashed, Mint can also send a fingerprint made only of the crash signal and the name of the Mint function or library involved.

Daily activity in the Direct edition. Direct versions that support daily activity reporting can also report that you opened or returned to Mint, at most once per calendar day in Pacific Time, while you choose to share usage analytics. This helps us understand whether people return to Mint over time. A background launch alone does not count. This signal uses the same anonymous installation identifier and event fields described below, includes no new personal or file information, and stops when you turn off analytics sharing. This daily activity signal is not sent by the App Store or Setapp edition.

Each event contains only a random installation identifier, a random event identifier used to make network retries idempotent, the UTC occurrence timestamp, the event name, an optional short allowlisted detail label (an onboarding step or fixed failure code, a core-operation feature/surface/outcome/reason, or a crash fingerprint), the Mint version and build, the distribution channel (Direct, Mac App Store, or Setapp), and the consent-schema version. Mint does not include scan results, file activity, filenames, file contents, paths, folder structure, document text, search terms, file counts or sizes, account details, hardware identifiers, advertising identifiers, undo history, or free-text error messages in these events. The analytics record does not store an IP address or user-agent string and is not linked to a Mint account, name, email address, purchase record, or Setapp account.

Setup signal (from Mint 1.0.25). Once you press Get Started on the Welcome page of the Direct or Setapp edition — the sentence under that button states that continuing means agreeing to the Terms of Use and acknowledging this Privacy Policy — and as you move through first-run setup, Mint reports a small setup signal to Mint’s first-party analytics endpoint: that Mint was installed, which app version and build is running, which setup pages were reached, a fixed failure code if a setup page could not do its job, and whether setup was completed. Each of these records carries only the random installation identifier, the event name, the allowlisted step label, the UTC day, and the app version, build and distribution channel — never file names, paths, contents, your name, email, or network address beyond what any HTTPS request carries in transit. This setup signal does not depend on the usage-analytics choice below and is how we know whether Mint could be installed and set up at all. The optional usage analytics described next — which features are used, whether operations finish, crash fingerprints, and weekly activity — begin only after you separately choose to share them.

On the first Welcome page, Mint asks you to agree to the Terms of Use and acknowledge this Privacy Policy before continuing. On the final onboarding page, all editions present a separate optional usage-analytics choice that is off by default. In the Direct and Setapp editions, the legal acknowledgement starts only the setup signal described above; it does not enable feature-use, operation-health, crash, or weekly-activity analytics. After you press Get Started in those two editions, Mint creates the random installation identifier used by the setup signal whether or not you later select the optional choice.

Mac App Store choice. In App Store versions that offer usage sharing, no Mint product event is collected or sent, and no analytics installation identifier is created, until you explicitly enable the optional choice on the final onboarding page or in Settings. If you enable it before entering Mint, setup completion can be reported. Earlier setup activity is not recorded for later upload. Declining sharing does not prevent setup or use of Mint. Earlier App Store versions without this choice do not send Mint product analytics.

You can turn optional usage analytics off at any time under Settings > Share my usage statistics without losing product functionality. Turning it off stops future optional collection and clears optional events still waiting locally for delivery; in the Direct and Setapp editions it does not disable the disclosed setup signal. In the Mac App Store edition, turning sharing off stops all Mint product analytics and clears every event still waiting locally for delivery. Events already sent are stored only for the retention period below, and network retries use the same event identifier so one event is not recorded twice.

Server event records expire after at most 120 days. An undelivered local event also expires after 120 days. The endpoint runs on Cloudflare’s global network and Workers KV storage is not restricted to a single country or region. Where European data-protection law applies to a restricted international transfer, Cloudflare’s Data Processing Addendum provides the applicable transfer safeguards, including the EU Standard Contractual Clauses.

Mint does not include advertising, cross-app tracking, or a general-purpose crash-reporting service. Mint checks locally for macOS crash reports and can show a post-crash prompt in every edition. The automatic privacy-minimized crash fingerprint is sent only while analytics sharing is enabled; a full, redacted diagnostic bundle leaves the Mac only when you choose to send a problem report. Direct-edition update checks remain available whether or not you share analytics; Mint serves the appcast without deriving or storing an installation identifier from the request IP address or user-agent string. Setapp may separately process limited technical information through the Setapp Framework for licensing, distribution, reliability, and developer reporting under Setapp’s own privacy notice.

Network Communication

Mint never uploads your files, filenames, folder structure, document text, or activity and undo history. Network communication is limited to the disclosed product-analytics, update, purchase, entitlement, support, and distribution flows:

  • Direct website edition — Mint sends the setup signal described above after the Welcome acknowledgement; after you separately opt in to usage analytics and while sharing remains enabled, it may also send the other privacy-minimized product milestones described above. It also checks the signed Sparkle update feed for new releases. Mint Free does not require an account. If you sign in to unlock or restore Unlimited, your browser securely authenticates with our Cloudflare-hosted Mint account service. The app stores OAuth tokens, a random device identifier, and your verified account email in the macOS Keychain, then sends the token, random device identifier, device display name, Mint version, and release date over HTTPS to check entitlement and enforce the one-Mac allowance. No file information is included.
  • Mac App Store edition — The one-time Lifetime Unlimited purchase and restores are handled through Apple StoreKit. Apple processes payment information; Mint receives entitlement status needed to remove the weekly limits. Only after you separately opt in, Mint may also send the privacy-minimized product milestones described above while sharing remains enabled.
  • Setapp edition — After the Welcome acknowledgement, Mint sends the setup signal described above to Mint’s first-party endpoint. If you separately opt in to usage analytics, it may also send the other privacy-minimized product milestones while sharing remains enabled. Mint also communicates with Setapp through the Setapp Framework to verify entitlement, support licensing and updates, and provide the technical usage, performance, and device information described in Setapp’s documentation. Mint does not send Setapp your file contents, filenames, folder structure, or Mint activity and undo history.
  • Account or entitlement validation may occur at app launch and periodically thereafter to confirm paid access.

If you use the free tier outside Setapp without activating or restoring Unlimited, Mint does not need to contact our licensing infrastructure. Beyond the setup signal, product analytics begin only after the separate optional analytics choice is enabled and remain independently controllable through Settings. The Setapp edition communicates with Setapp as described above.

Your Files Are Never Uploaded

To be unambiguous: Mint does not upload, copy, sync, or transmit your files or any file contents to any server, cloud service, or third party. All file operations are strictly local. Your documents, images, videos, and all other files remain on your Mac at all times.

Website Analytics

The Mint website measures visits, download requests and checkout activity to understand how people discover Mint and return to it. Where website analytics is allowed, a random first-party browser cookie connects visits from the same browser profile across sessions. This is a pseudonymous browser identifier, not a verified identity. We do not use it to track your browsing on unrelated websites.

Browser journey records include public page paths, event times, normalized referral and campaign labels, approximate country, and the checkout session used to associate a verified Direct purchase. Download requests may also include approximate city and region. Event and session history is kept for up to 90 days; the browser profile and first-observed date expire after 90 days of inactivity. The cookie expires after 90 days without renewal. EEA, UK and Swiss visitors must explicitly allow persistent website analytics. Do Not Track and Global Privacy Control prevent browser journey collection. You can allow analytics or turn it off and delete this browser’s first-party journey history through Website privacy in the footer. A separate preference cookie remembers your choice. Clearing browser cookies or using a different browser can prevent recognition.

Website-to-app visit linking is no longer offered. Mint does not create new installation connections or use app links to connect another browser. Previously collected connection records remain subject to the 90-day retention policy. Website privacy controls can still turn off analytics and delete this browser’s first-party visit history; this does not delete legally required purchase records.

We also use Google Analytics 4 for website and checkout reporting. When analytics storage is allowed, Google’s browser Client ID may be retained with the first-party browser profile so our private dashboard can relate the two website reports. We do not send your name, email address or native anonymous telemetry identifier to Google Analytics. Consent defaults deny analytics storage in the EEA, UK and Switzerland; denied storage may still allow Google’s cookieless measurement pings. Website privacy choices update Google’s analytics consent for the Mint website. Google Analytics and payment-provider records follow their own retention settings; forgetting first-party browser history does not erase those separate records.

The website also takes part in DZG Studio’s public Planet map. Unless your browser sends Do Not Track, an open tab sends a short-lived random tab identifier, the product name, and an approximate city or region to The Planet. The map can show an anonymous Mint visit or download start from that area. It never receives a name, email address, order amount, file information, or stable user identifier. Live visits expire after about 90 seconds without a heartbeat. Older activity is kept only as a coarse product and location summary for up to 30 days.

For each browser-tab session, the site stores a random session identifier and first-touch attribution in sessionStorage. A new analytics session begins after 30 minutes of inactivity, and closing the tab also removes the stored session. The stored attribution is limited to the landing path, referral hostname, traffic channel, browser language, selected website interface language, and the utm_source, utm_medium, and utm_campaign labels when present. When the download page requests the Direct DMG, the event also includes the public Mint version and build that the request targets. A download-start event does not establish that the transfer completed or that Mint was installed.

If you continue from the website to the Direct-edition checkout, the random session identifier and the same normalized source, medium, channel, and campaign labels are sent to LemonSqueezy as custom checkout data. LemonSqueezy returns those labels with signed order and subscription webhooks. This lets us connect an aggregate acquisition source to a real payment or refund. We do not send a referral URL, IP address, file information, name, or email address as checkout attribution data, and our measurement tables do not copy the customer name, email address, street address, or payment credentials from the webhook. For regional reporting, we may separately retain only the country, state or region, and city supplied by our payment provider for orders from the last 90 days. These locations are not linked to anonymous in-app usage records.

The Mint analytics endpoint retains privacy-minimized website event records for up to 90 days. Direct-edition activation event rows are retained for up to 400 days; older checkout session identifiers are removed from order records after 400 days. Non-personal order totals, refund totals, product identifiers, and keyed account or purchase hashes may be retained for accounting, fraud prevention, entitlement administration, and historical aggregate reporting. For website download starts, we may retain the approximate city and state or region inferred from the network connection for up to 90 days. This is not GPS or a street address, and a VPN can affect the location. Mint’s internal analytics records do not store IP addresses, precise location coordinates, user-agent strings, full referral URLs, arbitrary URL query parameters, or information about files used in the Mint app. The separate Planet summary follows the shorter retention described above.

Contact Form

If you use the contact form on our website, we collect the information you voluntarily provide: your name, email address, and message. This data is processed by a Cloudflare Worker and used solely to respond to your inquiry. We do not attach an IP address, IP hash, or user-agent string to the saved message. To prevent automated abuse, a one-way IP hash is used only in a separate short-lived rate-limit record; scheduled cleanup removes those records after the rate-limit window. We do not sell, share, or use contact information for marketing purposes. Contact form submissions are retained only as long as necessary to address your request.

Product Updates

If you subscribe to Mint product updates, we store the email address you provide together with Mint as the selected product, the website language, signup source, and the time of consent. We use this information only to send the product news you requested. It is kept until you ask us to remove it and is not sold or combined with product analytics, purchase attribution, or contact-form messages.

If you request a Windows version, we separately save your email address, website language, the form you used, the time of your request, and your consent to receive Windows updates. We use these requests to help prioritize development and to email you about Windows progress. This does not subscribe you to our general newsletter. Repeat requests from the same email address count once. You can ask us to remove your request at any time by emailing [email protected]. We keep the request until you ask us to remove it. The saved request does not include an IP address or an analytics identifier, and your email is never sent to Google Analytics. To limit automated submissions, we use a separate one-way network hash that expires after one hour.

Data Storage and Retention

Mint keeps file contents, filenames, paths, workflow history, and learned organization preferences locally on your Mac. The limited service records described below are stored only when the corresponding network feature is used:

  • Application preferences — Stored in macOS user defaults.
  • Activity logs and undo history — Stored in ~/Library/Application Support/Mint/.
  • Mint account and entitlement — Our Cloudflare database stores the verified email and account records needed for sign-in, keyed one-way hashes used to match Lemon Squeezy purchase emails, paid status, and connected-device records. The app stores OAuth tokens, the random device identifier, and verified email in the macOS Keychain. Mac App Store entitlement state is managed through Apple StoreKit; Setapp entitlement state is managed through Setapp.
  • Direct purchase and activation measurement — Our Cloudflare database stores the privacy-minimized order, refund, source attribution, and keyed-hash records described above. It never stores your files, file paths, or payment credentials.
  • Direct and Setapp product analytics — Our Cloudflare key-value store retains the random-install milestone records described above for no more than 120 days. These records are not joined to customer, payment, license, Apple, or Setapp account data.
  • Website product updates — Our first-party support store retains the subscribed email address and consent details until you ask us to remove them.

You can delete Mint’s locally stored data at any time by removing the application and its associated support files. Uninstalling Mint removes the local random analytics identifier; previously received privacy-minimized events expire automatically within the retention period. Because product-analytics records are deliberately not linked to a name, email address, Mint account, purchase, or Setapp account, we ordinarily cannot identify a particular person’s records from a personal-data request. You can contact us with a privacy request using the details below, and we will delete any record we can reliably identify without exposing another installation’s data.

Third-Party Services

  • LemonSqueezy — Handles Direct-edition payments, receipts, subscriptions, cancellations, and refunds. When you purchase Mint, LemonSqueezy processes your payment information according to their privacy policy. Mint itself never sees or stores your payment details. Signed webhooks include the purchase email; our entitlement record stores a keyed one-way hash of that address so a later verified Mint sign-in can claim the purchase.
  • Apple — Handles the Lifetime Unlimited App Store purchase, restores, refunds, and StoreKit entitlement status for the Mac App Store edition. Mint itself never sees or stores your App Store payment details.
  • Setapp — Handles distribution, licensing, payments, applicable taxes, entitlement validation, updates, and first-line billing and licensing support for the Setapp edition. The Setapp Framework may collect limited usage, performance, and device information from users who activate Mint through Setapp. Setapp processes this information according to its privacy notice.
  • Cloudflare — Hosts the Mint account and entitlement service, D1 account database, sign-in email delivery, product-analytics endpoint, key-value storage, and website on its global network. Subject to Cloudflare’s privacy policy.
  • Optional sign-in providers — If you choose a displayed Google, Apple, or X sign-in option, that provider authenticates you and shares the account information required to create or access your Mint account, including a verified email when available. You can always use Mint’s emailed one-time code instead.

Children’s Privacy

Mint does not knowingly collect personal information from children under 13. The desktop product analytics described above are not linked to a name, email address, account, purchase, or age, and Mint never includes file information in those events. Distribution platforms may separately process limited account, entitlement, usage, performance, and device information under their own privacy policies. If you believe a child has submitted personal information through our contact form or another support channel, please reach out so we can delete it.

Changes to This Policy

We may update this privacy policy from time to time. If we make significant changes, we will update the “Last updated” date at the top of this page. If an analytics change requires a new acknowledgement or consent, Mint will ask before collecting under the changed purpose; continued use alone is not treated as agreement to that changed purpose.

Contact Us

If you have any questions about this privacy policy or Mint’s data practices, email us at [email protected] or use the contact form on our website.