Does Your Mac Cleaner Send Data? How to Check

By 7 min read

privacybuying-guideapps

Written for macOS 27 Golden Gate and macOS 26 Tahoe. The tools below are built into macOS and have been available for many releases.

A Mac cleaner asks for one of the broadest permissions macOS has: access to nearly every file you own. If everything stays on your Mac, that's fine. If the app also talks to the internet, you'll want to know what it says. Below is how to check what any app sends, using only tools that ship with macOS, and how to read a privacy policy without getting lost in it.

What is the short answer?

A Mac cleaner granted Full Disk Access can read almost everything on your disk, so it's reasonable to ask what it sends home. Start with the privacy policy and search for words like analytics, diagnostics and usage data. Then check for yourself: Activity Monitor › Network shows bytes sent per app, and nettop -p <PID> or sudo lsof -nP -a -p <PID> -i in Terminal show the app's live connections.

Key takeaways

  • Full Disk Access lets an app read your files, including other apps' data, so a cleaner's network behaviour matters.
  • Some network traffic is legitimate, like update checks and license activation. Undisclosed analytics is the thing to watch for.
  • macOS already includes everything you need to observe an app's connections.
  • The built-in macOS firewall handles incoming connections and doesn't show or block what apps send out.
  • Notarization means Apple scanned an app for known malware. It says nothing about privacy.

Why do cleaners need Full Disk Access, and what does it expose?

macOS protects many locations by default, including Mail and Messages data, Safari data and parts of ~/Library. A cleaner that wants to measure caches and leftovers in those places has to ask you for Full Disk Access in System Settings › Privacy & Security › Full Disk Access.

Apple describes this permission plainly: it lets an app access all files on your computer, including data from other apps (Mail, Messages, Safari, Home), data from Time Machine backups, and certain administrative settings. Apple also notes that once you give a third-party app access to your files, what it does with that data is governed by its terms and privacy policy, not Apple's.

With Full Disk Access, the cleaner can see your files. What you need to find out is whether anything it sees leaves your Mac. Privacy is one item on a longer list, and our honest buyer's guide to Mac cleaners covers the rest.

How can you check which apps connect to the internet?

You can start without installing anything. Run these checks with the cleaner open, then again while it scans, because some apps only send data at specific moments.

1. Activity Monitor (no Terminal needed)

  1. Open Activity Monitor (Applications › Utilities).
  2. Click the Network tab.
  3. Click the Sent Bytes column header to sort by data sent.
  4. Find the cleaner, plus any helper processes with a similar name. Choose View › Columns and enable PID if it isn't showing. You'll use the PID number below.

This shows how much each process sends and receives, but not where it goes. A few kilobytes during an update check is unremarkable. Steady uploads while you're only scanning deserve a closer look.

2. nettop: live connections per process

nettop is a built-in command-line tool that shows network activity per process, including the remote addresses each process is talking to.

# Watch one process live (use the PID from Activity Monitor, or the process name)
nettop -p 12345

# Per-process summary of everything currently using the network
nettop -P

Press q to quit. Options can vary slightly between macOS releases. Run man nettop to see what your version supports.

3. lsof: open network connections

lsof lists open files, and network sockets count as files. This gives you a snapshot of every connection a process has open right now:

# All network connections for one process (-a means "AND" the filters)
sudo lsof -nP -a -p 12345 -i

# Only established TCP connections, for every process
sudo lsof -nP -iTCP -sTCP:ESTABLISHED

-n and -P keep addresses and ports numeric, which makes the command faster. Drop -n if you'd like to see host names instead of IP addresses. sudo lets you see sockets that belong to processes running as other users.

4. An outbound firewall or network monitor

To get alerts the moment an app tries to connect, or to block it, you need a third-party outbound firewall (sometimes called a network monitor). These apps sit between your Mac and the network, ask you to allow or deny each new connection, and log which app contacted which server. Several established options exist. Pick one from a developer you trust, since it sees all your traffic too.

What about the built-in firewall? The macOS firewall, in System Settings › Network › Firewall, is designed to block unwanted incoming connections. Turn it on, but don't expect it to tell you what an app sends out.

How do you read a privacy policy for telemetry?

Privacy policies are long, but the parts that matter tend to use the same phrases. Search the page (Command-F) for:

Phrase in the policyWhat it usually means
"usage data", "analytics", "product analytics"The app reports how you use it: features, clicks, sessions
"diagnostics", "crash reports"Error data is sent, sometimes including system details
"improve our services"A broad purpose that often covers analytics
"device identifier", "advertising identifier"Your Mac is given a persistent ID
"third-party service providers", "partners"Data may go to outside analytics or marketing companies
"opt out"Collection is on by default and you have to turn it off
"we do not collect" followed by a specific listGood. Check that the list matches what you observe

A trustworthy policy is specific. It names what is sent, when, and to whom, and it separates the app from the website. Many apps have no analytics while their marketing sites use standard web analytics. That's a fair distinction to make, as long as the policy spells it out.

What does Apple notarization prove, and what does it not?

Apps distributed outside the Mac App Store are normally notarized: the developer submits the app to Apple, which runs an automated scan for known malware and code-signing problems, then issues a ticket that Gatekeeper checks when you open the app. Apple can also revoke an app later if it turns out to be malicious.

You can check an app's status in Terminal:

spctl -a -vv /Applications/AppName.app

A notarized app reports accepted and source=Notarized Developer ID, plus the developer's name.

Notarization is a meaningful safety signal, but it is not a privacy review. Apple's notary service is automated and separate from App Review, and a notarized app can still include analytics as long as it isn't malware.

What should a privacy-first cleaner do?

Use this as a checklist for any cleaner you're considering:

  • States plainly what leaves your Mac. "Nothing" is rarely literally true. Expect update checks and license activation, described in specific terms.
  • No usage analytics or tracking in the app, rather than "anonymous" analytics that's on by default.
  • No account required to scan or clean.
  • Keeps scan results on your Mac. File names and paths are personal data.
  • Keeps a local log of what it removed, which you can read.
  • Moves files to the Trash rather than erasing them, so mistakes can be undone.
  • Notarized, so Gatekeeper can verify it.
  • Behaves on the network the way its policy says, which you can confirm with the steps above.

What should you not do?

  • Don't grant Full Disk Access before you trust the developer. You can scan many locations without it, and you can remove the permission any time in Privacy & Security.
  • Don't treat every connection as spying. Update checks and license activation are normal. Undisclosed, repeated uploads are not.
  • Don't rely on the built-in firewall to stop outgoing data. It isn't designed for that.
  • Don't confuse notarization with a privacy audit.
  • Don't use a cleaner that scares you into buying with alarming popups. That tells you the sale matters more to them than you do.

How does Freshist handle this?

We'd rather you check than take our word for it, so here is what you'll see if you run the checks above against Freshist. The app has no telemetry, no analytics and no account. Scanning and cleaning happen locally, and its log of removed items stays on your Mac in ~/Library/Logs/Freshist/. You will see two kinds of network activity. When you activate a license, the app sends your license key and a short device identifier to the payment provider (to count activations). It also checks for new versions by fetching its release feed, and that request contains no personal content. The website is separate: fresh.ist uses Google Analytics with storage disabled until you accept the cookie banner, and that is never part of the app. The full details are in the privacy policy. See how it compares with the typical subscription-based cleaner, or pricing.

Sources

Frequently asked questions

Do Mac cleaner apps collect data?

Some do and some don't. Many apps include usage analytics or crash reporting, which their privacy policy should disclose. To know for sure, read the policy and then watch the app's network activity yourself with Activity Monitor or Terminal.

Why does a Mac cleaner need Full Disk Access?

To measure and clean caches, logs and app leftovers in protected locations, a cleaner needs to read folders macOS otherwise guards. Apple notes that Full Disk Access lets an app read all files, including data from Mail, Messages, Safari and Time Machine backups, which is why trust matters.

Does the macOS firewall block apps from sending data?

No. The built-in macOS firewall controls incoming connections to your Mac. To see or block outgoing connections per app, you need a third-party outbound firewall or network monitor.

Does Apple notarization mean an app is private?

No. Notarization is an automated Apple scan for known malware and code-signing problems. It says nothing about whether an app collects analytics or what its developer does with your data.

Is any network activity from a cleaner a red flag?

Not necessarily. Checking for updates or activating a license requires a connection. What matters is whether the developer says what is sent, and whether the traffic you observe matches that description.

Keep reading

11 min read

Do You Need a Mac Cleaner? An Honest Buyer's Guide

Most Macs don't strictly need a cleaner. What macOS already handles, when one actually helps, how to choose a safe one, and the red flags to avoid.

buying-guidecleanupprivacystorage