Privacy

What leaves your devices, and what never does

A privacy app should be able to answer this precisely. Here it is, item by item, for both apps — and for the iPhone one the answer is nothing.

Last updated September 11, 2026

The short version

Shadow Sentinel for iPhone sends nothing anywhere. It has no account, no sign-in and no server of its own: nothing you type into it, tick off in it or scan with it leaves the phone. The detail is in its own section below.

Shadow Sentinel for Mac runs on your Mac and examines your Mac. It has no account system, no tracking pixels and no advertising. The contents of your files are never uploaded, read remotely or transmitted. The little that does leave your Mac is listed below, item by item.

Shadow Sentinel for iPhone

The iPhone app has no account system, no sign-in, no analytics and no server of its own. It makes no network requests, so there is no list of things it sends: the list is empty. Everything below happens on the phone and stays there.

  • The privacy switches. iOS gives no app a way to read another app's settings, and this app does not pretend otherwise. Each entry is documentation — where the switch is and what it does. When you mark one as checked, that is stored on your phone alone and is labelled as something you told us, not something the app measured.
  • Checking a message or link. Text you paste, and text you send in from Messages, Mail or Safari with the share sheet, is examined on the phone. The link is never opened and its address is never looked up. Nothing you check is stored after you leave the screen, and nothing is sent anywhere.
  • Bluetooth, during a sweep. When you tap "Start the scan", the app lists the Bluetooth devices advertising nearby so it can point out one that keeps appearing over several minutes. It does not connect to or pair with anything, and the list is held in memory for that scan only. Stopping the scan discards it.
  • The local network, during a sweep. The same button asks iOS for local network access, and the app listens for devices that announce a service on the Wi-Fi you are joined to. It only listens; it does not connect to them, scan ports or send anything to them.
  • The camera, during the lens check. Opening "Look for a lens" turns on the torch and shows the camera's view so you can look for the reflection of a lens. The capture session has no photo output and no video output: nothing is recorded, no frame is stored, and no image is analysed or transmitted.
  • The sweep report. It is written on the phone from what you ticked off and what the radios heard. It exists only there, and only reaches anyone else if you choose to send it.

What the iPhone app cannot do

  • It cannot read your settings. It tells you where they are; you look.
  • It cannot see your other apps — not what is installed, not what they store, not what they are doing.
  • It does not scan your phone. No iPhone app can, whatever its App Store page says.

Its App Store privacy label says no data is collected, because none is. If that ever changes — an AI second opinion or encrypted DNS would both mean data leaving the phone — this page, the label and the app's own screens change in the same release, before the feature ships.

Shadow Sentinel for Mac

What the Mac app sends, and to whom

  • Sentinel AI analysis (only when you turn it on). To explain a finding, the app sends its metadata to our server at api.shadowsentinel.com: file and folder names, paths, code-signature status, launchd labels, process names and similar descriptors. Our server forwards that to Anthropic's Claude API and returns the verdict. File contents are never included. Anthropic processes these requests under its API terms and does not use them to train its models. We do not keep copies of the requests or the verdicts; the app caches verdicts locally on your Mac so an unchanged item is never analysed twice.
  • Licence activation. When you enter a licence key, the app sends the key, an identifier derived from your Mac's hardware (so a seat survives renaming the Mac) and your Mac's name to api.shadowsentinel.com. We store these against your licence so you can see and free your seats from Settings. Deactivating removes the seat.
  • Update checks. The app fetches a small JSON file from shadowsentinel.com to learn the current version, and the threat-signature feed from GitHub. These are ordinary web requests; our hosting provider (Cloudflare) and GitHub see your IP address as with any download.
  • Payments. Subscriptions are handled by Stripe. Stripe collects and stores your card details; we never see them. We receive your email address and the status of your subscription so we can issue and manage your licence key.

What the Mac app does not do

  • It does not upload, read remotely or transmit the contents of your files, documents, photos, messages or browser data.
  • It does not send anything to us when Sentinel AI is turned off, other than licence checks and update checks.
  • It does not permanently delete anything. Every removal goes to the Trash.
  • It does not run advertising, analytics or crash-reporting libraries. Neither does the iPhone app.

This website

shadowsentinel.com is hosted on Cloudflare. If we enable Cloudflare Web Analytics it is cookieless and measures page views only; it does not track you across sites. The download itself is a plain file, served the same way to everyone.

Retention and your rights

Licence records are kept for as long as the subscription is active and for a short period afterwards to handle reactivation and support. To have your licence data deleted, or to ask what we hold, email [email protected] from the address you purchased with. Card and billing history live with Stripe and can be managed from the billing portal linked on the pricing page.

Changes

If this policy changes in a way that matters, we will update the date above and note it on the What's new page.

Contact

Blaze Creative Labs · [email protected]