# Does Your Mac Cleaner Send Data? How to Check

> Cleaners get Full Disk Access to your files. How to check what any Mac app sends home with built-in tools, and what a privacy-first cleaner looks like.

- Published: 2026-10-10
- Updated: 2026-10-10
- Author: @cemali (https://www.linkedin.com/in/cemaligencer/)
- Topic: Privacy & buying
- URL: https://fresh.ist/blog/mac-cleaner-privacy-telemetry/

**TL;DR:** A Mac cleaner with Full Disk Access can read almost everything on your disk, so it's fair to ask what it sends home. Search its privacy policy for words like analytics, diagnostics and usage data, then watch it yourself: Activity Monitor › Network shows bytes sent per app, and the built-in nettop and lsof commands in Terminal show its live connections.

*Written for macOS 27 Golden Gate and macOS 26 Tahoe. The tools below are built into macOS and have been available for many releases.*

A Mac cleaner asks for one of the broadest permissions macOS has: access to nearly every file you own. If everything stays on your Mac, that's fine. If the app also talks to the internet, you'll want to know what it says. Below is how to check what *any* app sends, using only tools that ship with macOS, and how to read a privacy policy without getting lost in it.

## What is the short answer?

A Mac cleaner granted **Full Disk Access** can read almost everything on your disk, so it's reasonable to ask what it sends home. Start with the privacy policy and search for words like *analytics*, *diagnostics* and *usage data*. Then check for yourself: **Activity Monitor › Network** shows bytes sent per app, and `nettop -p <PID>` or `sudo lsof -nP -a -p <PID> -i` in Terminal show the app's live connections.

### Key takeaways

- Full Disk Access lets an app read your files, including other apps' data, so a cleaner's network behaviour matters.
- Some network traffic is legitimate, like update checks and license activation. Undisclosed analytics is the thing to watch for.
- macOS already includes everything you need to observe an app's connections.
- The built-in macOS firewall handles *incoming* connections and doesn't show or block what apps send out.
- Notarization means Apple scanned an app for known malware. It says nothing about privacy.

## Why do cleaners need Full Disk Access, and what does it expose?

macOS protects many locations by default, including Mail and Messages data, Safari data and parts of `~/Library`. A cleaner that wants to measure caches and leftovers in those places has to ask you for **Full Disk Access** in **System Settings › Privacy & Security › Full Disk Access**.

Apple describes this permission plainly: it lets an app access **all files on your computer**, including data from other apps (Mail, Messages, Safari, Home), data from Time Machine backups, and certain administrative settings. Apple also notes that once you give a third-party app access to your files, what it does with that data is governed by *its* terms and privacy policy, not Apple's.

With Full Disk Access, the cleaner *can* see your files. What you need to find out is whether anything it sees leaves your Mac. Privacy is one item on a longer list, and our [honest buyer's guide to Mac cleaners](/blog/do-you-need-a-mac-cleaner/) covers the rest.

## How can you check which apps connect to the internet?

You can start without installing anything. Run these checks with the cleaner open, then again while it scans, because some apps only send data at specific moments.

### 1. Activity Monitor (no Terminal needed)

1. Open **Activity Monitor** (Applications › Utilities).
2. Click the **Network** tab.
3. Click the **Sent Bytes** column header to sort by data sent.
4. Find the cleaner, plus any helper processes with a similar name. Choose **View › Columns** and enable **PID** if it isn't showing. You'll use the PID number below.

This shows *how much* each process sends and receives, but not where it goes. A few kilobytes during an update check is unremarkable. Steady uploads while you're only scanning deserve a closer look.

### 2. nettop: live connections per process

`nettop` is a built-in command-line tool that shows network activity per process, including the remote addresses each process is talking to.

```bash
# Watch one process live (use the PID from Activity Monitor, or the process name)
nettop -p 12345

# Per-process summary of everything currently using the network
nettop -P
```

Press `q` to quit. Options can vary slightly between macOS releases. Run `man nettop` to see what your version supports.

### 3. lsof: open network connections

`lsof` lists open files, and network sockets count as files. This gives you a snapshot of every connection a process has open right now:

```bash
# All network connections for one process (-a means "AND" the filters)
sudo lsof -nP -a -p 12345 -i

# Only established TCP connections, for every process
sudo lsof -nP -iTCP -sTCP:ESTABLISHED
```

`-n` and `-P` keep addresses and ports numeric, which makes the command faster. Drop `-n` if you'd like to see host names instead of IP addresses. `sudo` lets you see sockets that belong to processes running as other users.

### 4. An outbound firewall or network monitor

To get alerts the moment an app tries to connect, or to block it, you need a third-party **outbound firewall** (sometimes called a network monitor). These apps sit between your Mac and the network, ask you to allow or deny each new connection, and log which app contacted which server. Several established options exist. Pick one from a developer you trust, since it sees all your traffic too.

**What about the built-in firewall?** The macOS firewall, in **System Settings › Network › Firewall**, is designed to block unwanted *incoming* connections. Turn it on, but don't expect it to tell you what an app sends out.

## How do you read a privacy policy for telemetry?

Privacy policies are long, but the parts that matter tend to use the same phrases. Search the page (Command-F) for:

| Phrase in the policy | What it usually means |
| --- | --- |
| "usage data", "analytics", "product analytics" | The app reports how you use it: features, clicks, sessions |
| "diagnostics", "crash reports" | Error data is sent, sometimes including system details |
| "improve our services" | A broad purpose that often covers analytics |
| "device identifier", "advertising identifier" | Your Mac is given a persistent ID |
| "third-party service providers", "partners" | Data may go to outside analytics or marketing companies |
| "opt out" | Collection is on by default and you have to turn it off |
| "we do not collect" followed by a specific list | Good. Check that the list matches what you observe |

A trustworthy policy is specific. It names what is sent, when, and to whom, and it separates the **app** from the **website**. Many apps have no analytics while their marketing sites use standard web analytics. That's a fair distinction to make, as long as the policy spells it out.

## What does Apple notarization prove, and what does it not?

Apps distributed outside the Mac App Store are normally **notarized**: the developer submits the app to Apple, which runs an automated scan for **known malware** and code-signing problems, then issues a ticket that Gatekeeper checks when you open the app. Apple can also revoke an app later if it turns out to be malicious.

You can check an app's status in Terminal:

```bash
spctl -a -vv /Applications/AppName.app
```

A notarized app reports `accepted` and `source=Notarized Developer ID`, plus the developer's name.

Notarization is a meaningful **safety** signal, but it is **not** a privacy review. Apple's notary service is automated and separate from App Review, and a notarized app can still include analytics as long as it isn't malware.

## What should a privacy-first cleaner do?

Use this as a checklist for any cleaner you're considering:

- **States plainly what leaves your Mac.** "Nothing" is rarely literally true. Expect update checks and license activation, described in specific terms.
- **No usage analytics or tracking in the app**, rather than "anonymous" analytics that's on by default.
- **No account required** to scan or clean.
- **Keeps scan results on your Mac.** File names and paths are personal data.
- **Keeps a local log** of what it removed, which you can read.
- **Moves files to the Trash** rather than erasing them, so mistakes can be undone.
- **Notarized**, so Gatekeeper can verify it.
- **Behaves on the network the way its policy says**, which you can confirm with the steps above.

## What should you not do?

- **Don't grant Full Disk Access before you trust the developer.** You can scan many locations without it, and you can remove the permission any time in Privacy & Security.
- **Don't treat every connection as spying.** Update checks and license activation are normal. Undisclosed, repeated uploads are not.
- **Don't rely on the built-in firewall** to stop outgoing data. It isn't designed for that.
- **Don't confuse notarization with a privacy audit.**
- **Don't use a cleaner that scares you into buying** with alarming popups. That tells you the sale matters more to them than you do.

## How does Freshist handle this?

We'd rather you check than take our word for it, so here is what you'll see if you run the checks above against Freshist. The app has **no telemetry, no analytics and no account**. Scanning and cleaning happen locally, and its log of removed items stays on your Mac in `~/Library/Logs/Freshist/`. You *will* see two kinds of network activity. When you activate a license, the app sends your license key and a short device identifier to the payment provider (to count activations). It also checks for new versions by fetching its release feed, and that request contains no personal content. The website is separate: fresh.ist uses Google Analytics with storage disabled until you accept the cookie banner, and that is never part of the app. The full details are in the [privacy policy](/privacy/). See [how it compares](/compare/) with the typical subscription-based cleaner, or [pricing](/#pricing).

## Related guides

- [Mac cleaner without a subscription: what to check](/blog/mac-cleaner-without-subscription/)
- [How to completely uninstall apps on Mac](/blog/uninstall-apps-mac-completely/)
- [What is System Data on Mac?](/blog/what-is-system-data-on-mac/)
- [MacBook fan loud or running hot?](/blog/macbook-fan-loud-running-hot/)

## Sources

- Apple Support: [Change Privacy & Security settings on Mac](https://support.apple.com/guide/mac-help/change-privacy-security-settings-on-mac-mchl211c911f/mac)
- Apple Platform Security: [Controlling app access to files in macOS](https://support.apple.com/guide/security/controlling-app-access-to-files-secddd1d86a6/web)
- Apple Support: [View network activity in Activity Monitor on Mac](https://support.apple.com/guide/activity-monitor/view-network-activity-actmntr1006/mac)
- Apple Support: [Block connections to your Mac with a firewall](https://support.apple.com/guide/mac-help/block-connections-to-your-mac-with-a-firewall-mh34041/mac)
- Apple Platform Security: [Protecting against malware in macOS](https://support.apple.com/guide/security/protecting-against-malware-sec469d47bd8/web)
- Apple Developer: [Notarizing macOS software before distribution](https://developer.apple.com/documentation/security/notarizing-macos-software-before-distribution)

## Frequently asked questions

### Do Mac cleaner apps collect data?

Some do and some don't. Many apps include usage analytics or crash reporting, which their privacy policy should disclose. To know for sure, read the policy and then watch the app's network activity yourself with Activity Monitor or Terminal.

### Why does a Mac cleaner need Full Disk Access?

To measure and clean caches, logs and app leftovers in protected locations, a cleaner needs to read folders macOS otherwise guards. Apple notes that Full Disk Access lets an app read all files, including data from Mail, Messages, Safari and Time Machine backups, which is why trust matters.

### Does the macOS firewall block apps from sending data?

No. The built-in macOS firewall controls incoming connections to your Mac. To see or block outgoing connections per app, you need a third-party outbound firewall or network monitor.

### Does Apple notarization mean an app is private?

No. Notarization is an automated Apple scan for known malware and code-signing problems. It says nothing about whether an app collects analytics or what its developer does with your data.

### Is any network activity from a cleaner a red flag?

Not necessarily. Checking for updates or activating a license requires a connection. What matters is whether the developer says what is sent, and whether the traffic you observe matches that description.

---

Canonical page: https://fresh.ist/blog/mac-cleaner-privacy-telemetry/
Official site: https://fresh.ist/ (fresh.ist only)
Generated: 2026-10-10
