Privacy Policy
Last updated: September 5, 2026
This Privacy Policy describes how Apis Systems LLC ("we", "us", "our") handles information in the applications we publish. It applies to all of our applications unless an application section below states otherwise.
Summary: our applications do their work on your device. Your files, and what our apps find in them, never leave it. A few things can: anonymous counters of which features get used, which you can switch off, and a feedback report, but only if you write one and press Send. Disk Reviewer also asks the App Store once a day whether a newer version of itself exists, which carries nothing about you. Foliata identifies plants on the device, and sends one photograph to our server only when it cannot name what it sees and you are online — that too can be switched off. There is no advertising and no tracking of any kind. DeckMirror has neither: it makes no network requests at all.
1. Data we collect
What our applications process to do their job — the files they scan, their names, paths, sizes and what a scan found — stays on your device and is never sent to us. That is the part that matters most, and it has not changed.
Three narrow exceptions exist, all described in full below:
- Anonymous usage counters. Which features are opened or run, and nothing about what they found. No account, no sign in, no identifier of ours. There is a switch for this in the app's settings.
- Feedback you choose to send. If you write a report in the app and press Send, we receive the message, any files you attached, the app and macOS version, and — only if you leave one — an email address for replying. A diagnostic log is attached when you leave its box checked; it records app events and errors, never file names, paths or scan results.
- A photograph, when an app cannot answer on its own. Foliata recognises plants on your device. When its offline model cannot name the plant in front of it and you are online, that one photograph is sent to our server, passed to Google’s Gemini API for a second opinion, and dropped. It is used to produce the answer and for nothing else: it is not stored by us, not used to train anything, and not linked to you. We keep a count of how many such requests an installation has made, which is how the free allowance is enforced, and that count says nothing about what was in the picture. There is a switch for this in the app’s settings, and turning it off means no photograph is ever sent.
- Crash reports, if you allow them. Our mobile applications ask, once, whether they may send anonymous usage counters and crash reports. If you say no, neither is collected and the reporting library is never switched on. A crash report describes where the app failed — the device model, the operating system version and the stack of the crash — and carries nothing about your files, photographs or plants.
- Where a find was made, if you turn it on. Foliata can note the coordinates of a plant you keep, so its herbarium label carries a place. This is off until you switch it on, and the coordinates live in your herbarium: they go to our server only when you have an account and only as part of your own collection.
- A once-a-day check for a newer version. Disk Reviewer reads its own public listing in Apple's App Store catalogue to notice when an update exists, so it can offer you a link to it. The request carries the app's numeric identifier and nothing else — no account, no identifier of ours, nothing about you or your files — and it goes to Apple, not to us. It runs at most once a day, and failing quietly is its normal behaviour when you are offline.
We do not collect contacts, browsing data, or any advertising identifier, and none of our applications contains an advertising SDK. Crash reports and location are collected only in the narrow cases named above, and only after you have allowed them.
2. How we use information
Usage counters tell us which parts of an app people actually use, so we can improve those parts and stop guessing. Feedback is used to understand and fix the problem you reported, and to reply to you if you left an address. That is all. We do not profile you, build advertising audiences, or make automated decisions about you.
Information that our applications process to perform their function, such as the file listings in a disk cleanup tool, is processed locally on your device and is never transmitted to us or to anyone else. The one exception is the photograph described above, which is transmitted for a single purpose — naming the plant in it — and is not kept afterwards.
3. Sharing with third parties
We never sell, rent or trade data, and we share nothing for advertising. Two processors handle data on our behalf, both in the European Union:
- TelemetryDeck (Germany) receives the anonymous usage counters. It is built for privacy-preserving analytics and does not profile individual users.
- Supabase (Frankfurt region) stores feedback reports and their attachments for us, and runs the small server function that forwards a photograph for identification.
Two more processors serve our mobile applications:
- Google receives a photograph through the Gemini API when Foliata asks for a second opinion, and operates Firebase Crashlytics and Firebase Cloud Messaging for crash reports and notifications. The Gemini API is used on its paid terms, under which Google does not use what is sent to it to improve its models; we chose to pay rather than use the free tier precisely because the free tier reserves that right.
- RevenueCat records which subscription an installation holds, so an app knows what you have paid for. It receives no name, email or payment details.
Apple processes purchases and subscriptions, and answers Disk Reviewer's once-a-day question about whether a newer version is on the App Store; we never receive your payment details. Beyond these, nothing is shared — including with advertisers, data brokers, or tracking networks. There are no tracking SDKs in our applications.
3a. How long we keep it
Feedback reports and their attachments are kept for up to 12 months and then deleted; we may delete a report sooner once it has been dealt with. Where a report's attachments and reply address are removed as soon as it has been dealt with, the text of the report may be kept longer, as a record of what was reported and what we changed. Usage counters are aggregate and are not tied to you, so there is no individual record to retain or remove. The diagnostic log on your Mac keeps the last seven days and prunes itself; it never leaves the device unless you attach it to a report.
A photograph sent for identification is not retained at all: it exists for the length of the request and is gone when the answer comes back. What remains is a number — how many such requests an installation has made — which we keep for as long as the installation exists, because it is what makes the free allowance mean something.
Photographs you take in Foliata stay on your phone. Every scan is kept in the app’s own storage so that your scan history and your herbarium can show it later, and it stays there until you remove the find, delete your account, or uninstall the app — we do not age them out. They are not uploaded, not backed up to us, and not readable by other apps. Deleting your account removes them from the device along with everything else the app had stored.
4. Our applications
Disk Reviewer (macOS)
- All scanning and cleanup happens locally on your Mac. File names, paths, sizes and scan results never leave the device.
- Anonymous usage counters record that a feature was opened or run — never what it found. Settings › "Share anonymous usage data" turns them off; switched off, the app makes no such request at all.
- The Feedback section sends a report only when you write one and press Send: your message, any files you attach, the app and macOS version, the interface language, whether the plan is free or paid, and an email address only if you type one. The diagnostic log is attached when its box is checked — it holds the last seven days of app events and errors and, by design, cannot contain file names, paths or scan results.
- Once a day the app asks Apple's public App Store catalogue whether a newer version of itself exists, so it can offer you a link to the listing. It sends the app's numeric identifier and nothing else, and it cannot install anything — a Mac App Store app has no way to update itself.
- There is no advertising and no tracking of any kind.
- Files you choose to remove are moved to the macOS Trash, and photos are moved to the Recently Deleted album in Photos. The app never removes anything without your explicit confirmation.
- In app purchases, if offered, are processed entirely by Apple. We do not receive your name, payment details or any other personal information from a purchase.
DeckMirror (macOS)
- DeckMirror shows the screen of an iPhone or iPad connected to your Mac with a cable. The picture travels from the cable to your screen and nowhere else: there is no network path in the mirroring flow at all.
- Both exceptions described above apply to this app, and only those two. Anonymous counters record which features are used — never what is on your screen — and Settings › Share anonymous usage data turns them off. A feedback report is sent only when you write one and press Send; it carries what you typed, anything you attached, and the reply address if you gave one. The mirroring itself stays untouched by both: nothing is recorded, and the picture never leaves your Mac.
- macOS asks for camera access the first time you mirror. This is required because the screen of a connected device is published to macOS as a capture device — the same mechanism QuickTime Player uses for “New Movie Recording”. DeckMirror never uses your Mac’s camera and never opens one; it filters Continuity Camera devices out of its list so only device screens are offered.
- The microphone permission is used only to play the connected device’s sound through your Mac, and it is off by default.
- The purchase is one time and is processed entirely by Apple. We do not receive your name, payment details or any other personal information from it.
Foliata (iOS, Android)
- Recognition runs on your phone. The camera picture is examined by a model inside the app, and neither the viewfinder nor the photographs you keep are uploaded as a matter of course.
- When that model cannot name the plant and you are online, the single photograph you just took is sent to our server, passed to Google’s Gemini API, and dropped once it has answered. It is not stored, not used for training, and not tied to you. The first time this is about to happen the app says so, and there is a switch in Settings — Ask online when unsure — that stops it entirely.
- Your herbarium — the plants you kept, their photographs, the dates and any places — lives on your device. It is copied to our server only if you create an account, and only then; without one it stays local. Deleting your account deletes that copy, photographs included.
- Recording where a find was made is off until you turn it on. The coordinates belong to your herbarium entry and are sent nowhere else.
- Anonymous usage counters and crash reports are collected only if you allowed them when the app asked. Saying no is respected permanently and can be changed in Settings at any time.
- Notifications are used for watering reminders for the plants you kept. They are never marketing.
- Subscriptions are processed by Apple or Google; we never receive your payment details.
5. Your rights
You remain in full control of everything our applications touch on your device. For the little we do hold — a feedback report you sent us — you can ask for a copy, a correction, or its deletion, and we will act on it. Write to [email protected] from the address you used, or describe the report well enough for us to find it; we respond within 30 days. There is no account to close: we never created one for you.
You can also stop the usage counters at any time in the app's settings, without asking us. Because they are anonymous and aggregate, they hold nothing tied to you that could be retrieved or erased individually.
6. Children's privacy
Our applications are not directed at children and do not knowingly collect personal information from them. The only way a person can send us anything is by deliberately writing a feedback report.
7. Our websites
This website (apissystems.dev) is a static site served through Cloudflare. Like most hosting providers, Cloudflare processes basic technical request data, such as IP addresses, to deliver the site and protect it from abuse. We use Cloudflare Web Analytics, a privacy first, cookie free service that shows us aggregate page statistics and cannot identify individual visitors. The site sets no cookies and runs no advertising or cross site trackers.
We also run diskreviewer.com, a single page site for Disk Reviewer that we advertise. It is hosted the same way, and it uses TelemetryDeck — the same analytics provider as the app — to record page views and whether a visitor followed the link to the Mac App Store. TelemetryDeck sets no cookies and does not fingerprint your device. Instead of an identifier that follows you around, it derives a one way hash from your IP address, your browser's user agent string and a salt that changes every day, so a visitor cannot be recognised the next day or on any other site. It also records the page address, including any campaign parameters an advertising link carries, together with coarse browser, operating system and country information. We use this only to see whether our advertising reaches people who actually want the app. No cookie banner is required because no cookies are set, and that site carries no advertising or cross site trackers either.
8. Changes to this policy
We may update this policy from time to time, for example when we release a new application. The date at the top of this page always reflects the latest revision. Material changes will be described in the relevant application section.
9. Contact
Questions about this policy or about your privacy in our applications: [email protected]