What Greypaint reads. Greypaint reads application metadata already stored on your Mac, such as an app's name, bundle identifier, installed version, and update-feed settings. It also contacts public update sources you have enabled: appcast feeds, Homebrew, GitHub Releases, and Apple's App Store lookup service.
What leaves your Mac. Greypaint sends ordinary requests to those public update sources so it can compare versions and download updates you request. It does not upload your app list, file contents, browsing history, or personal documents. There are no accounts, ads, analytics, or telemetry.
Local data. Preferences, the last scan, update logs, and rollback copies are stored locally in macOS application-support and cache locations. You can remove rollback copies from Finder or by uninstalling Greypaint.
Notifications. If you allow notifications, Greypaint creates local security-update notifications. The notification permission is controlled by macOS.
Third parties. Updates are hosted by the source that publishes them. When you choose an App Store or release-notes link, macOS opens that third-party destination. Their own privacy policies apply there. Software attributions are listed on the Licenses page.
Contact. For privacy questions, email hello@greypaint.app.
Last updated: September 9, 2026.