Security & Privacy
Scrubbr is built so your sensitive text never has to leave your Mac. Here’s exactly how.
Your documents stay on your device. Detection and redaction run entirely on-device using an on-device model. The text and files you scrub are never uploaded to us, and we never see them.
Data handling
On-device processing
All detection and redaction happen locally on your Mac — no content is sent to a server.
No accounts
There’s no sign-up. We don’t collect your name or email to use the app.
Opt-in analytics only
Anonymous usage stats are off by default. If enabled, they’re aggregate counts — never your content — and IP addresses are discarded after a coarse country lookup.
We never see card data
Payments are handled by Paddle (PCI-DSS Level 1). We don’t receive or store your payment details.
Application security
- Signed & notarized. The app is distributed as an Apple Developer ID-signed, notarized build, so macOS Gatekeeper can verify it.
- App Sandbox & Hardened Runtime. Scrubbr runs sandboxed with the hardened runtime enabled, limiting what it can access.
- Verified downloads. Optional model downloads are verified against a SHA-256 checksum before they are loaded, and Pro models are released only over an entitlement-checked, expiring link.
- Minimal network surface. The app only contacts our servers for update checks, the model catalog, and optional analytics — never to process your content.
Infrastructure
Our website and API run behind Cloudflare. We use Sentry for error monitoring, configured to exclude request bodies and personal data. We don’t sell data to anyone.
Reporting a vulnerability
If you believe you’ve found a security issue, we’d like to hear from you. Please email contact@scrubbr.app with details and steps to reproduce, and give us reasonable time to investigate before any public disclosure. See also our security.txt.