Legal
Privacy Policy
How DevScape.io LLC collects, uses, discloses, retains, and safeguards information across our websites, applications, and services — and the rights and choices available to you.
Effective July 3, 2026 · Last updated October 9, 2026
DevScape.io LLC (“DevScape.io,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy describes how we collect, use, disclose, retain, and safeguard information in connection with our websites, applications, and services, the legal bases on which we rely, and the rights and choices available to you.
We have written this Policy to be read in plain language wherever possible, with defined terms and legally required disclosures grouped so you can find what applies to you. If a provision of this Policy conflicts with a separate agreement you have signed with us, that agreement controls to the extent of the conflict.
By using our Services, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Services.
1. Scope of This Policy
This Privacy Policy applies to personal information we process through:
- Our websites, including devscape.io and guide.devscape.io (the “Sites”);
- Our software applications, including SupportID and Mac Admin Loadout (the “Apps”); and
- Our sales, support, and other business interactions (collectively with the Sites and Apps, the “Services”).
It does not apply to:
- Third-party products, services, or websites that we do not own or control;
- Information handled by your organization when it configures and deploys our Apps to its own devices as an independent data controller; or
- Information you provide to third parties through channels we do not operate.
Where your organization deploys our Apps to you as an employee or end user, your organization — not DevScape.io — determines what information is configured and displayed, and that organization’s privacy notice governs that processing.
2. Key Definitions
- Personal information (or “personal data”) means information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, to an identified or identifiable individual or household.
- Sensitive personal information means categories treated as sensitive under applicable law, such as government identifiers, precise geolocation, account credentials, or data revealing health, biometric, racial, or similar characteristics.
- Processing means any operation performed on personal information, such as collection, use, storage, disclosure, or deletion.
- Controller (or “business”) means the entity that determines the purposes and means of processing personal information.
- Processor (or “service provider”) means an entity that processes personal information on behalf of a controller.
- Aggregated or de-identified data means information processed so that it no longer reasonably identifies, and is not linked or reasonably linkable to, an individual.
- MDM means a Mobile Device Management platform used by organizations to configure and manage devices and apps.
3. Information We Collect
3.1 Information you provide directly
- Identity & contact data — name, email address, organization name, job role, and phone number when you contact us or make a purchase inquiry.
- Support content — the contents of support requests, feedback, bug reports, and any attachments or logs you choose to send us.
- Business & licensing data — organization identifiers, license quantities, purchase order references, and billing contact details.
- Communications preferences — the topics you ask to hear about and your subscription or opt-out choices.
Please do not send us sensitive personal information in free-text support requests unless it is strictly necessary, and never include passwords or full payment card numbers.
3.2 Information collected automatically
When you visit our Sites, we and our infrastructure providers automatically collect:
| Category | Examples | Purpose |
|---|---|---|
| Device & browser | Browser type, OS, device type, screen size, language | Rendering, compatibility, security |
| Network | IP address, approximate location (city/region), ISP | Security, fraud prevention, coarse analytics |
| Usage | Pages viewed, referring URL, on-site search terms, time on page, timestamps | Measuring and improving the Sites |
| Diagnostics | Server logs, error and performance metrics, crash traces | Reliability and troubleshooting |
| Cookie identifiers | First-party cookie and local-storage identifiers | Preferences and aggregate measurement |
3.3 Information from our Apps
Our Apps are built for data minimization. None of them contains advertising or third-party analytics SDKs, defines a tracking domain, tracks users across apps or websites, or requires an account. What follows describes each App individually.
SupportID
SupportID does not collect, transmit, or store personal or device data. All information it displays (such as serial numbers, asset tags, or usernames) is supplied by your organization’s MDM configuration and rendered locally on the device. SupportID:
- does not track users across apps or websites;
- contains no advertising or third-party analytics SDKs;
- defines no tracking domains; and
- transmits no device data off the device.
Mac Admin Loadout
Mac Admin Loadout does not collect, transmit, or store personal or device data, and we receive nothing from it. It is a set of read-only administrator tools that runs in the macOS App Sandbox. It reads three kinds of local information and renders all of it on the device:
- This Mac’s own configuration — hardware and operating-system details such as the serial number, model identifier, hardware UUID, storage, battery, and network configuration. These are displayed to you and are never transmitted;
- Files you open — configuration profiles, app archives, Jamf Pro summaries, and property-list manifests that you choose through the system file picker. They are parsed locally and are never uploaded; and
- Certificates already in your keychain — read only, to list signing identities. No private key material is read, exported, or transmitted.
Anything the App exports — a profile, a report, a downloaded installer — is written only to the location you pick in the save dialog.
The App makes network requests to the following services, and to nothing else. It sends no identifier that distinguishes you or your Mac:
| Service | Purpose | What is sent |
|---|---|---|
| Apple software update catalogs and content delivery network | Listing and downloading the macOS installers and firmwares Apple publishes | Nothing beyond the request itself |
| Apple iTunes Search API | Looking up App Store apps by name or link | The search text you type, and a storefront region you choose |
| GitHub (raw content) | Fetching the public manifest catalog the configuration editor reads | Nothing beyond the request itself |
| ipsw.me firmware index | Determining which firmwares suit this Mac | This Mac’s hardware model string, such as “Mac14,10”. Millions of Macs share a model string; it identifies no individual device or person |
These requests are made directly from your Mac to the services named. They do not pass through us, and we receive no record of them. Apple and ipsw.me handle what they receive under their own privacy policies, which are outside our control — see Section 19.
If a future App or feature processes data differently, we will disclose that in the App’s listing, its in-product notices, or an addendum to this Policy before that processing begins.
Note — We do not intentionally collect special categories of data (such as health, biometric, precise geolocation, or government identifiers) through the Services.
4. Sources of Information
We obtain personal information from:
- You, when you contact us, purchase, or use the Services;
- Automated technologies, such as server logs and cookies, when you visit the Sites;
- App marketplaces, such as the Apple App Store and Apple Business Manager, which process purchases and share aggregated sales, download, and crash information with us. We do not receive your payment card details from Apple;
- Your organization, when it engages us for sales, support, or deployment and shares contact or licensing details; and
- Service providers, such as our hosting, email, and analytics vendors, acting on our behalf.
5. How We Use Information
| Purpose | Legal basis (EEA/UK) |
|---|---|
| Provide, operate, and maintain the Services | Contract; legitimate interests |
| Respond to inquiries and provide support | Contract; legitimate interests |
| Process purchases, licenses, and administration | Contract; legal obligation |
| Send service and security communications | Legitimate interests; legal obligation |
| Send optional product news where you have opted in | Consent |
| Analyze usage to improve reliability and features | Legitimate interests; consent (where required) |
| Detect and prevent fraud, abuse, and security incidents | Legitimate interests; legal obligation |
| Create aggregated or de-identified insights | Legitimate interests |
| Comply with law and enforce our agreements | Legal obligation; legitimate interests |
We do not sell your personal information, and we do not use it for cross-context behavioral or third-party advertising.
6. Legal Bases for Processing (EEA/UK)
If you are in the European Economic Area, United Kingdom, or Switzerland, we rely on the following legal bases under the GDPR/UK GDPR:
- Performance of a contract — to deliver the Services and support you request;
- Legitimate interests — to operate, secure, analyze, and improve the Services, balanced against your rights and freedoms;
- Consent — for certain cookies and optional communications, which you may withdraw at any time; and
- Legal obligation — to comply with applicable law.
Where we rely on legitimate interests, you may ask us for information about that balancing assessment by contacting us.
7. Cookies & Tracking Technologies
Our Sites use a limited set of cookies and similar technologies:
| Type | Purpose | Duration |
|---|---|---|
| Strictly necessary | Core site functionality and security | Session |
| Functional | Remember preferences such as theme or language | Up to 12 months |
| Analytics | Aggregate, non-identifying usage measurement | Up to 12 months |
We do not use advertising or cross-site tracking cookies. You can control or delete cookies through your browser settings, and most browsers let you block or receive alerts about cookies. Blocking some cookies may affect site functionality. Where required by law, we request consent before setting non-essential cookies, and you may change or withdraw that consent at any time.
On devscape.io, analytics are provided by Cloudflare Web Analytics and load only after you choose Accept in the cookie banner. Your choice is stored in your browser, and you can change it at any time with Cookie settings in the site footer. A Global Privacy Control signal is treated as declining.
8. How We Disclose Information
We disclose personal information only as described below, and never sell it:
- Service providers that process information on our behalf under contract (see Section 9);
- App marketplaces and platform providers, such as Apple, to distribute Apps and process purchases;
- Professional advisors, such as lawyers, auditors, and accountants, where necessary;
- Legal, regulatory, and safety recipients, when required to comply with law, respond to lawful requests, or protect rights, property, or safety; and
- Business transfers, in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
We may also disclose aggregated or de-identified information that cannot reasonably be used to identify you.
9. Categories of Service Providers
We engage vetted providers under data-protection agreements. Representative categories include:
| Category | Function |
|---|---|
| Cloud hosting & content delivery | Serving and delivering the Sites and Apps |
| App distribution & payments | Distributing Apps and processing purchases |
| Email & support tooling | Communicating with and supporting customers |
| Analytics & monitoring | Aggregate usage measurement and error tracking |
We can provide a current list of specific sub-processors on request at [email protected].
10. Data Retention
We retain personal information only as long as necessary for the purposes described in this Policy, then delete or anonymize it. When determining retention periods, we consider the amount and sensitivity of the data, the potential risk of harm, the purposes for which we process it, and applicable legal requirements. General guidelines:
| Data | Typical retention |
|---|---|
| Support correspondence | Up to 24 months after resolution |
| Billing & licensing records | As required by tax and accounting law (often 7 years) |
| Website server logs | Up to 12 months |
| Marketing preferences | Until you unsubscribe, plus a suppression record |
| Aggregated analytics | Retained in de-identified form |
11. Data Security
We implement reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction — including encryption in transit, access controls, least-privilege practices, logging, and vendor due diligence. No system is perfectly secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for notifying us promptly of any suspected unauthorized use.
12. International Data Transfers
We are based in the United States and may process information in the U.S. and other countries where we or our service providers operate. Where we transfer personal data from the EEA, UK, or Switzerland to countries not deemed to provide adequate protection, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses and the UK Addendum. You may request a copy of the relevant safeguards by contacting us at [email protected].
13. Your Privacy Rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you, and to know how we process it;
- Correct inaccurate or incomplete information;
- Delete your personal information;
- Port your data to another provider in a structured, machine-readable format;
- Object to or restrict certain processing;
- Withdraw consent where processing relies on it;
- Opt out of “sale,” “sharing,” or targeted advertising (we do not engage in these); and
- Lodge a complaint with your local data protection authority.
To exercise any right, email [email protected]. We will verify your request against information we already hold and respond within the time frame required by applicable law. We will not discriminate against you for exercising your rights. You may use an authorized agent where permitted by law, and we may ask that agent to provide proof of authorization.
14. U.S. State Privacy Disclosures
For residents of California and other U.S. states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and Montana), the rights above — access, correction, deletion, portability, and to opt out of “sale” or “sharing” and targeted advertising — apply as provided by your state’s law. The categories of personal information we collect, together with their sources, purposes, and recipients, are described in Sections 3, 4, 5, 8, and 9, which together serve as our notice at collection.
We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA) or other U.S. state laws, and we do not process personal information for targeted advertising. We do not knowingly process sensitive personal information for purposes requiring a right to limit.
If you are a California resident, you may also request the categories of personal information we have disclosed for a business purpose in the preceding 12 months; that list matches the categories described in Sections 8 and 9.
15. Do Not Track & Global Privacy Control
Because there is no consistent industry standard for “Do Not Track” signals, our Sites do not respond to them differently. Where required by law, we honor recognized opt-out preference signals such as the Global Privacy Control (GPC), treating a valid signal as a request to opt out of “sale” or “sharing” for the browser or device that sends it.
16. Automated Decision-Making
We do not use your personal information to make decisions that produce legal or similarly significant effects about you based solely on automated processing, including profiling.
17. Marketing Communications & Your Choices
If you have opted in, we may send you occasional product news, release notes, or event information. Every marketing email includes an unsubscribe link, and you can also opt out by emailing [email protected]. Opting out of marketing does not stop service, security, transactional, or legal communications, which are necessary to operate the Services.
18. Children’s Privacy
Our Services are intended for businesses and IT professionals and are not directed to children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
19. Third-Party Links & Services
Our Services may link to third-party sites and services we do not control, including code repositories, MDM vendors, and Apple platforms. This Policy does not apply to them, and we are not responsible for their content or privacy practices. Please review their policies before providing information.
20. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights, we will notify affected individuals and relevant authorities as required by applicable law and without undue delay, and we will describe the nature of the incident and the steps we are taking in response.
21. Accessibility of This Policy
We want this Policy to be usable by everyone. If you use assistive technology and have trouble accessing any part of this Policy, or would like it in an alternative format, contact us at [email protected] and we will work to provide the information you need.
22. Changes to This Policy
We may update this Privacy Policy periodically. When we make material changes, we will revise the “Last updated” date above and, where appropriate, provide additional notice such as a banner on the Sites or an email. Prior versions are available on request. Your continued use of the Services after changes take effect constitutes acceptance of the revised Policy.
23. How to Contact Us
For questions, requests, or complaints regarding this Policy or our privacy practices:
- DevScape.io LLC
- Legal & Privacy: [email protected]
- Support: devscape.io/support
- Web: devscape.io
If you are in the EEA or UK and have concerns we have not resolved, you also have the right to contact your local data protection authority.