Legal

Privacy Policy

Verscout privacy: local inventory, required network requests, optional catalog contributions and website measurement.

Effective date: September 26, 2026.

1. Who is responsible

Vohux Inc. provides Verscout and is responsible for the personal information described in this policy. Contact our privacy contact at [email protected] to ask questions, make a privacy request, or raise a concern. Verscout is local-first: most inventory and update work happens on your Mac, but necessary network requests and optional contributions can send information off the device.

2. Information used on your Mac

Verscout reads application and package names, installed versions, bundle identifiers, available update-source metadata, and basic compatibility information such as your macOS version and processor architecture. It uses this information to identify installed software, check update availability, display your inventory, and perform actions you request. Preferences, local inventory, update history, and cached results are stored in the application's local support directory. Local paths may be needed to locate and update your applications; they are not included in optional catalog contributions.

3. Update checks and downloads

Update checks may contact Verscout services, software publishers, update feeds, public registries, and package managers. Requests disclose the names, identifiers, versions, or public URLs needed for the particular lookup. For example, Verscout may send bundle identifiers to its cloud catalog to retrieve known update-source information even when optional catalog sharing is off. Downloads disclose the requested software or download URL to its host. Like other internet requests, these connections expose your IP address and request metadata to the receiving service and its infrastructure. Publisher and registry operators handle their own service data under their privacy policies.

Necessary update lookups are separate from optional catalog contributions. Declining catalog sharing does not prevent normal update checks from reaching their required sources.

4. Purchases and license verification

Lemon Squeezy handles checkout, payment processing, taxes, invoices, subscriptions, and license issuance. It collects the payment and billing details you provide directly. Vohux receives or can access the order, purchase email, subscription status, billing records, and license information needed to deliver access, provide support, process refunds, and meet accounting or legal obligations. Vohux does not receive your full card number or card security code.

The app stores your activation information locally and sends your license key and activation identifier to Lemon Squeezy for activation and validation. A hashed device identifier is used to identify a Mac's activation and enforce the three-Mac limit. A hash is a pseudonymous identifier, not a promise of anonymity. See Lemon Squeezy's privacy policy for its processing practices.

5. Optional contributions to improve update coverage

This setting is off by default. An active subscriber can enable it separately in Verscout settings.Your subscription, price, and paid update features do not depend on sharing. If you opt in, Verscout periodically contributes eligible public software metadata so we can discover, check, and improve update sources.

The preview shows the next eligible batch. Later scans can contribute additional eligible software while sharing stays enabled. Contributions contain:

  • The software's display name and bundle identifier, where present.
  • Public HTTPS publisher, update-feed, or download URLs that pass the contribution filters.
  • The publisher's public signing-team identifier and update strategy, when available. This version of the desktop app does not contribute installed or latest-release version numbers.
  • A random contribution identifier and submission/consent metadata needed to authenticate the submission, prevent abuse, and honor deletion.

They do not contain your installed version, update or application-usage history, local file paths, documents, email address, payment details, license key, or hardware serial number in the catalog contribution rows. The contribution service checks subscription eligibility separately using license information; it must not store that information in catalog rows. The filters reject URLs with embedded credentials, query strings or fragments, non-HTTPS schemes, nonstandard ports, literal private-network addresses, and recognized local-only hostnames. They cannot establish that every public-looking hostname or URL path is public or free of identifying information. Inspect the preview and leave sharing off if the eligible metadata includes confidential or user-specific information.

Software metadata can reveal interests or aspects of your work, and a pseudonymous contribution identifier can link submissions until it is removed. We therefore do not describe these submissions as unconditionally anonymous. Transport and security systems can also process IP addresses and request metadata.

We use the submissions to investigate candidate update sources, verify public publisher information, improve software matching, and prevent poisoning or abuse. An unverified submission does not automatically become a trusted update source. Independently verified public software names and update links may be included in the shared catalog used by other Verscout installations. We do not sell contributed inventories, use them for advertising profiles, or publish contributor identifiers with the catalog.

6. Stopping contributions and deleting linked submissions

Use Stop sharing and delete contributions in Verscout settings to stop new uploads from that Mac immediately and request deletion. This setting is separate on each installation; changing one Mac does not silently change another Mac's preference. This also revokes that installation's contribution authorization. The app shows whether the server confirmed deletion or whether an internet connection or retry is still needed. Deletion remains available after a subscription expires.

A deletion credential stored on the Mac lets the service find and remove its linked submissions without requiring your email address in each row. Keep that credential until the server confirms the request. If you no longer have the Mac or its local data, contact support; we will explain what we can identify and may request proportionate verification. We cannot promise to locate submissions solely from your email if no link to that email exists.

Deletion removes the linked contribution records from the active contribution system. Public software facts that we independently verified and separated from your contribution identifier may remain in the catalog. They are no longer a record of your software inventory. Withdrawing consent does not undo lawful processing already completed and does not affect paid features.

7. Storage location and retention

The contribution service currently runs on Google Cloud in the United States, and the associated BigQuery dataset is in the United States. Raw, linked contributions made through the current opt-in controls described in this policy are retained for no more than 90 days unless you request earlier deletion. Verified public catalog facts may be retained while useful for providing update-source information.

Legacy catalog submissions and crawl-queue data from earlier releases are excluded from trusted serving data until independently verified. A restricted migration archive may retain remaining legacy records for up to 90 days from migration, after which its entries expire. These records are not treated as fresh consent under the current sharing controls.

Active consent records are kept while contribution sharing remains enabled. A confirmed deletion removes that installation's consent record, linked submissions, and submission-batch records from the queryable contribution tables. A minimal revocation record, containing the random contributor identifier and a hash of the deletion credential, is kept for up to 30 days to prevent replay and support retries. A separate keyed hash of license information may be retained for up to two days to enforce submission limits and prevent repeated registrations from bypassing them. That security record is not included in the public catalog.

The Google Cloud default application and HTTP request log bucket currently retains logs for 30 days. Platform request logs can include IP addresses, timestamps, response status, and request paths. A deletion request path contains the random contribution identifier; deleting active contribution rows does not immediately erase that request log. Our application logs do not record contribution bodies, license keys, or deletion credentials. BigQuery retains recoverable historical data for a seven-day time-travel window, followed by a further seven-day fail-safe window. These provider recovery periods can keep deleted data for up to 14 additional days after deletion from the active tables. Other security or administrative audit records can have different retention periods. Deletion from the active application database does not promise immediate deletion from every provider backup or legally retained audit record. Recovery copies are not used to rebuild a deleted personal inventory, and a restored system must reapply recorded deletion requests.

Purchase, support, consent, and security records are retained only as needed for their stated purposes, to resolve a documented dispute, to prevent abuse, or to meet applicable legal obligations. Payment providers determine the retention of records they must keep independently. Local inventory remains on your Mac until removed through the app or by deleting its local data.

8. Optional iCloud sync

If you enable iCloud Settings Sync, Verscout writes preferences, pinned packages, schedules, and recent update history to your personal iCloud Drive. The sync file also contains a hashed machine identifier, your Mac's network name, operating-system information, Verscout version, and sync timestamps so your Macs can distinguish one another. It does not include license keys or optional catalog-contribution consent credentials. Apple processes that data under its own terms and privacy policy. Verscout does not receive your iCloud password. Turning off sync does not automatically delete a copy already stored in iCloud; manage that copy through iCloud Drive.

9. How this website measures visits

The Verscout website is separate from the desktop application. Cloudflare hosts the site and processes network and security information needed to serve and protect it. Cloudflare Web Analytics measures page views, referrers, country, browser/device context, and performance. Cloudflare states that it does not set cookies or use your browser's local storage for this service, and does not use your IP address or browser information to fingerprint you. See Cloudflare's privacy policy. Our font provider may receive your IP address and request metadata when the site loads a remotely hosted font.

Optional measurement is disabled until you choose to accept it using the website's privacy controls. You can reject it without losing access to the site and change your choice through Privacy choices in the footer. We store your choice in this browser for up to 180 days, where browser storage is available. Global Privacy Control keeps optional measurement off. If your browser prevents saving consent, optional measurement stays off. Changing your choice to reject removes accessible first-party measurement cookies and storage, blocks further optional measurement requests, and reloads an active measurement page. Your browser controls third-party cookies and storage that this website cannot access; withdrawal does not itself erase data already received by a provider. Accepting website measurement does not enable desktop catalog contributions, and accepting catalog contributions does not enable website tracking.

With your website measurement consent:

  • TruConversion measures page interactions, including clicks, scrolling and pointer movement, for heatmaps and session replay. It processes page content, browser/device context and network information. Its cookies can last for a session or up to two years, depending on the cookie. See TruConversion's privacy policy and cookie information.
  • Growify processes page URLs, referrers, campaign identifiers and browser/device context to measure campaign visits and recognize returning browsers. It can use a first-party browser cookie for up to one year and process information in the United States. See Growify's privacy policy.

These tools are loaded only on this marketing website after consent; they are not embedded in the desktop application or Lemon Squeezy checkout by Verscout. Do not put license keys, sensitive personal information, or other secrets in website URLs. Provider-held measurement data is subject to the provider's retention practices and our applicable service settings. Contact us to request access to or deletion of identifiable measurement data; we may need a browser identifier or visit details to locate it. Tools we use to improve how our pages appear in search engines and AI assistants work only with our public page content and receive no information about you. You can block or delete cookies in your browser settings in addition to using our privacy controls.

10. How and why we share information

We use hosting, payment, support, and other service providers only for the functions described in this policy and subject to appropriate safeguards. We may disclose information when legally required, to address fraud or a concrete security threat, or to establish or defend a legal claim. If ownership of Verscout changes, any transfer of personal information remains subject to this policy and applicable law; we will provide required notice and obtain any consent required for a different use.

Data can be processed outside Canada, including in the United States, and may be accessible under the laws of the processing country. We remain responsible for information handled by processors on our behalf and use contractual and technical safeguards appropriate to the transfer. Do not interpret a location disclosure as a guarantee that foreign laws match the laws of your home country.

We rely on your consent for optional catalog contributions and optional website measurement. Necessary licensing, delivery, and support processing is used to perform our contract with you. Where applicable law permits, limited security and service-protection processing is based on our legitimate interests, balanced against your privacy rights; required accounting or legal records are processed to meet legal obligations. We do not use contributed software metadata to make automated decisions that have legal or similarly significant effects on you.

Depending on applicable law, you may ask to access, correct, delete, restrict, or receive a portable copy of your personal information, object to processing, or withdraw consent. Some rights have exceptions, including legally required records and the rights of other people. Contact [email protected] and identify the right you want to exercise. We may request information necessary to verify the request without collecting more than needed. We respond within the period required by applicable law and explain any lawful extension or refusal.

You may complain to the Office of the Privacy Commissioner of Canada, your applicable provincial authority, the UK Information Commissioner's Office, or the relevant EU/EEA data-protection authority. You do not have to contact us first to exercise that right.

12. Security, children, and policy changes

We use appropriate access controls, transport protection, data minimization, and other safeguards. No software or internet service can promise absolute security. Do not include secrets, confidential documents, or payment-card details in support messages or contributed links.

The optional contribution service is not directed to children under 16. If you are under 16, do not enable catalog sharing. A parent or guardian can contact us about information supplied by a child. Purchases must be made by someone legally able to enter the subscription contract.

We will update this policy when our practices change and identify the effective date. We will give appropriate notice of material changes and request new consent where required before using optional data for a new purpose.