Privacy
Your code stays yours.
You're going to read the source before you run this. Good, that's the point. Here is exactly what it touches.
What it reads
- Which app is in front
- Name and bundle id. Nothing inside it.
- How long since you touched the keyboard
- A number of seconds. Not which keys.
- Whether a mic is live
- A yes/no from CoreAudio. It never opens a stream.
- Whether a camera is live
- A yes/no from CoreMediaIO. It never opens a stream, and macOS asks you for nothing.
- Session duration
- How long you've been going.
- Window titles
- Only if you grant Accessibility. Off by default.
What it cannot read
- not:
- not:
- not:
- not:
- not:
- not:
Not "we promise not to look." There is no code path that could. Reading any of these needs a permission the app never requests and an entitlement it was never signed with.
Don't trust it. Check it. Every claim above is verifiable from a terminal in under a minute.
zsh, verify sigstop
nm -u /Applications/sigstop.app/Contents/MacOS/sigstop | grep -E 'NSURLSession|_socket|getaddrinfo'Silence. The app's own binary references no networking at all. Every byte of network code is in Sparkle.
ls /Applications/sigstop.app/Contents/FrameworksSparkle.framework, and nothing else. One dependency, named, versioned, diffable.
plutil -p /Applications/sigstop.app/Contents/Info.plist | grep SUThe one URL it can fetch, the key it verifies updates against, and automatic checks set to false.
sigstop --doctorPrints everything it can currently see about you, and why it believes it.
cat ~/Library/Application\ Support/sigstop/events.jsonlYour entire stored history. Plain JSON, one event per line. Read it yourself.