The short version
- No advertising or third-party analytics SDKs.
- No Sentinel Sweep account is required. An Apple Account is used separately if you choose to make or restore an App Store purchase.
- No app feature uploads your files or scan results to an online service.
Overview and scope
This Privacy Policy covers the Sentinel Sweep macOS application, the public Sentinel Sweep website, and messages sent to the Sentinel Sweep support mailbox. “Sentinel Sweep,” “the app,” “we,” and “us” refer to the application published by Niko Lim unless the context identifies the website or email service separately.
The app is a local file-review and transfer utility. It does not create or require a Sentinel Sweep account. Its main features run on the Mac using files and locations the user chooses. Scanning, review, and manual transfer-queue planning are free. An optional Apple-processed purchase unlocks Quick Copy, Quick Move, the final Review Transfer screen, and new Copy and Move transfers.
Files, folders, and volumes you choose
Sentinel Sweep asks you to choose scan sources, quarantine locations, and transfer destinations through macOS controls. A source may be an individual file, a folder, or a folder on a removable volume. When you choose a folder or volume location, the app may enumerate items inside it to perform the scan you requested. Hidden-file scanning is included by default; scanning inside file packages is controlled separately in the app.
macOS security-scoped bookmarks can preserve access to a file or folder you previously approved. For removable volumes, Sentinel Sweep may save access to eligible items immediately inside a selected volume root so those items can be reopened after the drive reconnects. For a transfer root, the app may create or reuse the named child folder you requested and save access to that location. These bookmarks are opaque capability data created by macOS and can include a fallback path used to help locate the item again.
You can remove an item from the app, choose it again, or use the reset controls described below. Disconnecting, renaming, or reformatting a drive may make a saved bookmark stale and require reselection.
Information processed on your Mac
For the files you choose, Sentinel Sweep may process:
- file and folder names, paths, sizes, dates, types, volume identifiers, and transfer status;
- filename signals and local classification results;
- image content and locally sampled video frames;
- content fingerprints used to recognize earlier Adult or Safe decisions; and
- SHA-256 hashes used when you enable transfer verification.
To form a content fingerprint for learned decisions, the app can read up to three portions of a file, with each portion limited to 64 KB. The sampled bytes are used to calculate the fingerprint and are not stored as the learned-memory record.
Local analysis frameworks and FFmpeg
Sentinel Sweep passes local file URLs to Apple's Sensitive Content Analysis framework for supported analysis. It also uses macOS frameworks including AVFoundation, ImageIO, Vision, Core ML, and Quick Look when appropriate for the media type and system capabilities.
For supported video formats, Sentinel Sweep launches bundled FFmpeg and FFprobe command-line helpers as separate local processes. The included FFmpeg 8.1.2 build has network support disabled and enables only the file and pipe protocols. The Sentinel Sweep app executable is not linked to FFmpeg libraries. See the FFmpeg source and build page.
Temporary video frames
Sampled video frames are written to a randomly named folder in the app's temporary directory for local analysis. Sentinel Sweep removes that folder when the analysis finishes, is cancelled, or fails through the normal error path. As with other applications, an unexpected process or system termination can interrupt immediate cleanup; macOS may retain temporary data until the app or the operating system removes it.
Copy, move, quarantine, and overwrite actions
You choose the operation, destination, and conflict behavior. Copy leaves the source item in place. Move places a copy at the selected destination and removes the original after the required placement succeeds. Quarantine is an ordinary local folder you choose. If you select Overwrite, an existing item at the destination can be removed and replaced. Transfer history and undo information may help reverse eligible moves, but you remain responsible for reviewing the chosen operation and destination.
Information stored on your Mac
Sentinel Sweep stores settings and limited app state so it can present your choices, restore interrupted work, remember approved locations, and show transfer history. Depending on the features you use, this can include:
- application and interface preferences;
- learned Adult and Safe decisions, classification signals, and content fingerprints;
- a review-session checkpoint and an active-transfer checkpoint;
- transfer logs, status, history, and undo information; and
- security-scoped bookmarks for files, folders, removable-volume items, and transfer locations you approved.
Saved checkpoints, learned memory, and transfer logs can contain filenames or paths. Current versions write sensitive saved state using AES-GCM encryption with app-specific keys stored in your macOS Keychain. Ordinary preferences are stored in the app's local macOS preferences domain. Other local records are stored under Sentinel Sweep's Application Support directory inside the app's macOS container.
Current versions can recognize certain records written by earlier builds and may migrate them to the protected format. If a legacy record cannot be migrated, it may remain on the Mac until you remove the related app data or complete a factory reset.
What the app does not collect or share
Sentinel Sweep does not include a feature that uploads scanned media, filenames, file paths, scan results, learned decisions, bookmark data, transfer logs, or app-usage information over a network or to an online service. It does not contain advertising SDKs, third-party analytics SDKs, or cross-app tracking code. It does not sell personal information or share app data for behavioral advertising.
The Mac App Store build uses App Sandbox and does not request the outbound network-client entitlement. The bundled FFmpeg helpers are also sandboxed for the release and are compiled with FFmpeg networking disabled.
Apple services, purchases, and diagnostics
Apple independently operates macOS, the Mac App Store, StoreKit, and the Sensitive Content Analysis framework. Apple's handling of information is governed by Apple's policies and by the choices you make in macOS and the App Store.
Optional App Store purchase
Apple processes the optional Transfer Access purchase through the Mac App Store. Sentinel Sweep receives Apple-signed StoreKit transaction and entitlement information needed to decide whether Quick Copy, Quick Move, the final Review Transfer screen, or a new Copy or Move transfer can be used. The app does not receive your full payment-card or bank-account details, and the publisher does not operate a separate payment system for this purchase.
StoreKit purchase requests and entitlement checks do not include scanned media, filenames, file paths, classifications, learned decisions, bookmarks, transfer queues, or transfer logs. Choosing Restore Purchases asks Apple to synchronize eligible purchase status. A pending, refunded, or revoked transaction can affect Transfer Access for future file operations, but it does not remove safety controls for work already underway. Buying or restoring access does not automatically resume an attempted action or start a file operation.
Diagnostics
If you choose to share diagnostics with Apple or app developers, Apple may provide crash or performance diagnostics. Sentinel Sweep does not intentionally attach scanned file contents, file paths, or scan results to those diagnostics. System-generated reports can still contain technical context selected by macOS.
Public website and support email
GitHub Pages website
This public website is hosted through GitHub Pages. The site contains no advertising, analytics tag, tracking pixel, account system, or marketing form, and its navigation script does not store information in your browser. GitHub may collect and log visitor information, including IP addresses, for security and service operation under the GitHub General Privacy Statement. We do not operate a separate website-visitor analytics service for this site.
Gmail support mailbox
If you email SentinelSweepSupport@gmail.com, Google processes the message through Gmail. The publisher receives the information you choose to include, such as your email address, message headers, written description, and any attachments. Do not send private media, passwords, passkeys, signing keys, recovery codes, or unredacted logs.
Support messages may be kept while needed to respond, investigate technical or purchase-recognition issues, prevent abuse, maintain necessary business records, or comply with law. Do not send an Apple Account password, payment-card details, StoreKit transaction tokens, or full purchase receipts. You may request deletion of a support message by emailing the same address. A request may not cover copies that Google retains under its own policies or information that must be retained for security or legal reasons.
Your choices, deletion, and retention
Local app state remains on your Mac until you clear it, replace it through ordinary use, complete a factory reset, or macOS removes the app's container. Different controls affect different records:
- Clear Learned Memory removes learned Adult and Safe decisions.
- Clear Transfer History removes saved transfer logs and the latest transfer summary, which can also remove the in-app ability to undo moves described only by those logs.
- Queue and result controls remove the current in-app working state they name; they do not automatically erase unrelated history, bookmarks, learned memory, or every interrupted-work checkpoint.
- A review checkpoint or interrupted-transfer checkpoint remains separate until the app completes, discards, replaces, or resets that state.
- Saved access remains until the related item is removed or replaced in the app, the bookmark becomes unusable, or factory reset removes the app's saved bookmark state.
- Restore Factory Defaults schedules a full reset. The reset completes on the next launch and removes Sentinel Sweep's Application Support data, preferences, saved bookmarks, and—when macOS permits—its app-specific Keychain protection keys. It does not cancel, refund, or erase an App Store purchase record held by Apple.
These controls do not delete source files or files already copied or moved to locations you chose. Removing the app in Finder does not necessarily remove every item macOS retains in Application Support, preferences, or Keychain. If you want the in-app full reset, use Restore Factory Defaults and relaunch Sentinel Sweep before uninstalling. After a reset or reinstall, StoreKit may need to re-establish an eligible purchase entitlement.
See Privacy Choices for a plain-language guide to each control.
Security
The release is designed to use App Sandbox, user-selected file access, security-scoped bookmarks, local encryption for sensitive saved state, and device-only Keychain protection for app-specific keys. These measures reduce risk but cannot guarantee that every storage system, operating system, or software process will be completely secure. Keep macOS updated, protect your Mac account, and maintain backups appropriate for files you copy or move.
Children
Sentinel Sweep is a general-purpose Mac utility and is not directed to children. The app does not create user accounts or operate a service that collects scanned files. If you believe a child sent personal information to the support mailbox, contact the publisher using the address below.
Changes to this policy
This policy may be updated when Sentinel Sweep's behavior, hosting, support process, or legal obligations change. The current published version will show its effective date.
Privacy contact
For a privacy question or a request concerning information you sent to support, email:
Niko Lim
SentinelSweepSupport@gmail.com
A shorter contact-only version is available at the Sentinel Sweep Privacy Contact page.