Last updated: September 2026
Overview
QuickSweep (listed on the App Store as QuickSweep: Disk Cleaner) is developed and operated by Velorion Technologies ("we", "us"). It is a native macOS app that identifies reclaimable disk space on your Mac and removes the items you select. This policy explains what we collect, why we collect it, and what we do not collect.
What QuickSweep does
QuickSweep scans known safe cleanup targets (app and browser caches, system logs, Trash, diagnostic reports, temp files, developer caches such as Xcode DerivedData and package manager caches) and lets you browse your own folders by size.
Scanning and cleaning happen locally on your Mac. QuickSweep does not upload file contents, file names, file paths, or folder listings. Removed items are moved to the Trash.
Folder access and the App Store sandbox
QuickSweep is a sandboxed app, so it scans only the folders you select yourself.
- You grant access through the standard macOS Finder picker, and the app can read only what that grant covers.
- If you want a broader scan, you can select your startup disk in the picker.
- macOS permissions and protected system locations still apply on top of that. System-critical and SIP-protected paths are never touched, whatever you select.
What we don't collect
- We don't upload your file names, paths, folder structure, or file contents to any server.
- We don't require an account, an email, or any sign-in.
- We don't collect contacts, precise location, photos library, microphone, or camera data.
- We don't use a third-party advertising network, an advertising identifier, or any cross-app tracking. QuickSweep does not use Apple's App Tracking Transparency permission and never accesses your Identifier for Advertisers (IDFA).
- We don't sell or rent your data.
What we do collect
What leaves the app is limited to the product telemetry, first-party promotion requests, and purchase status described below. The usage and crash data we collect is a small amount of non-identifying information used solely to improve the product: to prioritize features, tune defaults, and catch regressions. We never sell or rent it.
- Aggregate usage analytics (Firebase Analytics). We collect aggregated, non-identifying events about how the app is used: app opens, which scan was run, which cleanup categories were selected, and the total number of bytes reclaimed by a completed clean. These events are not linked to any person. File names, paths, and file contents are never included.
- Crash and diagnostic reports (Firebase Crashlytics). When the app crashes or hits a non-fatal error, a redacted report (stack trace, OS and app version, device model) is sent to Firebase Crashlytics so we can diagnose and fix the bug. Reports do not contain file names, paths, contents, or other personal information.
- Redacted operational errors (Firestore). Some operational errors are also written to a write-only Firestore collection that the app can add to but never read back. Error text is sanitized before it is sent, so file names and paths are not transmitted.
- Remote configuration (Firebase Remote Config). The app fetches configuration values from Firebase Remote Config: the promotion on/off switches, the promotion manifest URL, and which subscription period is selected by default on the purchase screen. This is a read of our settings, not a report about you.
- Purchase-completion analytics. When a subscription purchase completes, the event may include the product ID, the selected billing period, the price, and the currency. It never includes payment-card details or your Apple Account details.
- Crash reports (Apple). Apple's built-in crash reporter may also send us a non-identifying report. You can opt out in macOS System Settings, under Privacy & Security, then Analytics & Improvements.
- Email (only if you contact us). If you reach out via the contact form on our website, we collect your name, email, and message so we can reply.
First-party promotions in the free tier
The free version may show a banner promoting Velorion's own apps, websites, and services.
- The banner is driven by a text-only manifest the app fetches from
https://velorion.tech/projects/quickclean/promos.json. That file is a small list of our own products: no images are loaded from it, and no third party is involved in choosing what it shows. - There is no third-party advertising SDK, no tracking pixel, no advertising identifier, no personalization, and no cross-app tracking behind it. Nothing about you is used to decide which of our products is shown.
- If you tap a promotion, that tap is recorded as an aggregate Firebase Analytics event, in the same non-identifying form as the rest of our usage analytics.
- QuickSweep Pro removes the banner. We can also switch promotions off remotely for everyone.
Network requests the app makes
QuickSweep makes ordinary network requests to two places, and to nothing else:
- Google Firebase, for the analytics, Crashlytics, Firestore error logging, and Remote Config described above.
- velorion.tech, to fetch the promotion manifest.
As with any HTTPS request, the receiving server sees the connection metadata it needs to answer, including your IP address. We do not use that metadata to profile you, and it is not used for advertising, because the app serves no third-party advertising.
Subscriptions
QuickSweep Pro is an optional auto-renewable subscription sold through your Apple Account. Apple processes purchases, renewals, cancellations, and refunds, so we never see your name, card, or billing address. We receive from Apple only the subscription status needed to unlock Pro, plus anonymous aggregate sales reports in App Store Connect. See the terms of service for the billing detail.
Third parties
QuickSweep uses:
- Firebase Analytics, Firebase Crashlytics, Cloud Firestore, and Firebase Remote Config (Google) for the non-identifying product-improvement data and configuration described above.
- Apple as the payment processor and distributor for QuickSweep Pro.
No advertising SDKs, no social SDKs, and no cross-app tracking SDKs are embedded. We do not share collected data with any other third party.
Each of these providers is bound by terms that require it to protect the data described here to at least the standard set out in this policy, and to process it only to deliver the function it is used for. Google and Apple also process that data under their own published policies.
Children's privacy
QuickSweep is not directed at children under 13 and we do not knowingly collect data from them.
Your rights (GDPR / CCPA)
We hold no account for you, so in most cases there is no per-user record for us to access, correct, or delete. Analytics, crash reports, and sanitized error reports are not linked to an identity we can look you up by.
Our lawful basis for the telemetry described above is our legitimate interest in keeping the app working and improving it, processed in the minimized, non-identifying form set out in this policy. If you have emailed us, we also retain that message, on the basis of handling your request.
To ask about either record, or to request deletion of an email record, write to contact@velorion.tech. You also have the right to lodge a complaint with your local data protection authority. We do not sell personal information, and we do not share it for cross-context behavioural advertising as those terms are defined under the CCPA.
Data retention
Analytics and crash data are retained by Firebase for up to 14 months and then deleted automatically. Sanitized operational error records are kept while the underlying bug is being investigated. Email correspondence is kept for as long as needed to handle your request.
Changes to this policy
If we change this policy, we'll update the date at the top. Material changes will be noted in the app's release notes.
Contact
Questions about privacy? Email contact@velorion.tech.
See also the QuickSweep terms of service, which cover the subscription, promotion, and licence terms.