Your files and photos stay on your device. Spaceback has no account, no advertising and no tracking, and it never sends your file names, file contents or photos to us. If you turn on usage statistics, it tells us how the app is used, with every total rounded into a broad range.

The Mac app

Spaceback is a sandboxed Mac App Store app. You choose the folders it may inspect through macOS, and its storage analysis runs locally on your device.

What the Mac app sends

Spaceback never collects, transmits, sells or shares your file contents, file names, folder paths or cleanup history, and it never uses your Mac’s hardware identifiers or advertising identifier. There is no Spaceback account or sign-in. Versions before 2.3.0 send nothing to us at all. From 2.3.0, two things can leave your Mac, each only when you choose: usage statistics, if you turn them on, and what you look at or copy between your own devices once you link your iPhone.

How it works with your files

  • File sizes, duplicate comparison and photo analysis happen on your Mac.
  • Spaceback can only inspect locations you grant through macOS. It discloses protected or unreadable locations instead of treating them as empty.
  • Cleanup actions require approval. Spaceback asks macOS to move confirmed files to the Trash and reports anything that does not reach it.
  • Receipts and cleanup history are stored locally on your Mac.

The iPhone app

Spaceback for iPhone (also called Storage Cleaner: Spaceback) is a photo-library cleaner. It reads your photo library through Apple’s Photos framework after you grant access, and every measurement and comparison it performs runs on the device itself.

What the iPhone app sends

Your photos, videos, thumbnails, file names, sizes, comparison results and cleanup history never reach any server of ours. Up to version 1.2 the iPhone app makes no network request to any server of ours, and it has no account, sign-in, advertising SDK or crash reporter in any version. From version 1.3 it can send usage statistics if you turn them on, and it talks directly to your own Mac once you link them. Apple’s StoreKit checks your purchases with the App Store, as described under Purchases.

Photo library access

  • You grant access through iOS. If you choose Select Photos rather than full access, Spaceback measures only the photos you selected, and says so on screen rather than presenting a partial figure as a whole-library total.
  • Photo and video analysis — sizes, near-identical shots, duplicate detection and screenshot comparison — runs locally using Apple’s Vision and Photos frameworks.
  • When measuring and comparing your library, Spaceback never downloads originals from iCloud: every image request it makes for that work sets network access to disabled, so an item stored only in iCloud is reported as unavailable rather than fetched. The one exception is importing into the vault, which you start yourself through the system photo picker — iOS retrieves the full-resolution item so it can be encrypted on the device, and if that item lives only in iCloud, retrieving it is a download.

Deleting photos

Spaceback only removes what you have selected and confirmed, and it asks iOS to move those items to Recently Deleted, where they remain for 30 days. Space is not reclaimed until that album is emptied, which only you can do — no app is permitted to empty it for you.

The vault

  • Vault items are encrypted on the device with AES-GCM. The content key is protected by a key derived from your PIN with PBKDF2-HMAC-SHA256, and the salt is held in the iOS Keychain.
  • There is no recovery. We never receive your PIN, your key or your items, so a forgotten PIN cannot be reset by us or by anyone else.
  • Moving a photo into the vault removes it from your Photos library only if you ask for that; otherwise the original stays where it is.
  • Exporting the vault writes decrypted copies to a location you choose through the iOS Files app. If you choose a location that syncs, such as iCloud Drive, those copies are then handled by that service under its own terms.

What is stored on the device

Spaceback keeps a small amount of its own state in an app group shared with its widgets, including: the per-category size figures the widgets display, your reclaim history, your Keep list, your storage-headroom preference, your swipe decisions (which photos you staged or bookmarked, held as photo identifiers), your reminder settings, and vault settings such as the auto-lock delay, whether biometric unlock is on, whether originals are removed after importing, and the failed-attempt count used to throttle PIN guessing. This data stays on your device and is not readable by us.

Usage statistics (optional)

From Spaceback for Mac 2.3.0 (App Store), Spaceback Pro 2.3.1 and Spaceback for iPhone and iPad 1.3, you can choose to share usage statistics. The app asks once, with two equally weighted buttons, and nothing is recorded or sent unless you choose to share. You can change your mind at any time in Settings.

What is sentWhich screens and features you use and which of a fixed set of buttons you tap; how far you get through setup; which permissions were requested and whether you allowed them; scans and cleanups started, finished or failed, with durations and totals rounded into broad ranges (for example “1–5 GB”); on iPhone, swipe sessions and vault use, counted in ranges; paywall views, the plan you pick, how long the paywall stayed open, and whether a purchase, restore or trial succeeded, was cancelled or failed, with Apple’s error code; which setting you changed, and the look you picked; whether linking devices worked; error codes the app showed you.
With every reportThe app and OS version, the device type (Mac, iPhone or iPad), language, App Store country (not in Spaceback Pro), whether Pro is active and on which plan, how many days ago the app was installed, a random ID created when you turned sharing on, and a random session ID.
What is never sentYour name, email address, Apple Account or licence key; file or folder names and paths; file contents, photos or thumbnails; anything you type; your device’s name, hardware identifiers or advertising identifier; your location. Every value comes from a fixed list or a range, and our server rejects anything else.
Where it goesTo our own service on Google Cloud in the European Union: Cloud Run in Belgium, stored in BigQuery in the EU. Only the developer can see it, on a password-protected dashboard. It is not sold, shared, used for advertising or combined with other data. Until they are sent, reports wait on your device: at most 500, and none older than seven days.
Your IP addressOur service does not read or store it, and keeps no request log. Google’s network necessarily sees it in order to deliver the request.
Why, and the lawful basisTo see where people get stuck, which tools are used, and whether setup and the paywall work, so the app can be improved. The lawful basis is your consent (Article 6(1)(a) GDPR), which you can withdraw at any time.
RetentionEach report is deleted automatically 14 months after it arrives.
Turning it offSettings → Share usage data. Nothing more is sent, and the random ID is deleted from your device. If you turn sharing on again later, a new ID is created with no connection to the old one.
Deleting what was sentWhile sharing is on, Settings shows your Analytics ID. Email it to vlada@queazy.app, or choose Turn Off and Request Deletion when you switch sharing off, and every report with that ID is deleted.

Separately, Apple gives us aggregate statistics about the app: downloads, sales, crash counts, and usage from people who agreed in their device settings to share analytics with app developers. Apple’s subscription reports identify a subscriber only by an anonymous ID, never by name or Apple ID. We use them for the same purposes, on the same dashboard.

Spaceback Pro (direct edition)

Spaceback Pro is the version sold outside the Mac App Store. Everything above about local analysis applies to it too, and from version 2.3.1 so do the optional usage statistics. It does not include Spaceback Link. One difference the App Store edition does not have: licence activation contacts our server.

What is sentA one-way hash of your licence key, an installation id derived from your Mac's hardware UUID, and the app version. No file names, paths, file contents or scan results are ever transmitted.
WhenOnce, when you activate a licence. Spaceback Pro does not check in on a schedule, and it keeps working if the request fails.
What the server storesNothing about the check. It reads the installation id and ignores it. A row exists only for a licence that has actually been refunded, and it holds just that fact.
Are these identifiers anonymousNo — they are pseudonymous. Because we issue the licences, we can link a hash back to the purchase it came from. We describe them accurately rather than calling them anonymous.
Why, and the lawful basisTo detect licences that were refunded or charged back. The lawful basis is Article 6(1)(b), performance of the sales contract.
RetentionA revocation flag is kept for as long as that licence exists, because a refunded licence must stay refunded. Nothing else is retained, because nothing else is written.
UpdatesSpaceback Pro can check for new versions via Sparkle, which reaches updates.spaceback.queazy.app and therefore sees your IP address and app version. That host runs on Google Cloud in the European Union, and update files download from Google Cloud Storage; neither keeps a log of the request. Automatic checks are off unless you turn them on.
Processor and locationFrom Spaceback Pro 2.3.0, Google Cloud in the European Union: Cloud Run in Belgium, with the revocation list in Firestore stored across Europe. Versions 2.2 and earlier have their server address built in and keep checking with Amazon Web Services in the United States (API Gateway, Lambda and DynamoDB), which stays in place for them.
Redeeming an AppSumo codeOur activation page exchanges the code you paste for your licence. The page and the exchange both run on Google Cloud in the European Union. The code is marked as claimed so it cannot be used twice; nothing else about you is stored.

Buying Spaceback Pro directly

When you buy Spaceback Pro on this website, the payment provider that acts as merchant of record, named at checkout, sells the licence as our reseller and handles the payment, tax, receipt and any refund. It collects your payment and billing details and processes them under its own privacy policy, which the checkout links to. We never see your card details.

Who processes the paymentThe payment provider named at checkout, as merchant of record, for payment, tax and fraud checks.
What we receiveYour email address, your country, the order number, and the amount and currency you paid. The provider also gives us its own reference for you as a customer, which we keep with the order.
WhyTo deliver your licence (on the page you see after paying, and by email), to answer your support questions, and to revoke the licence if the order is refunded or charged back.
Where it is storedIn Firestore on Google Cloud in the European Union. The licence email is delivered by Amazon SES in the United States.
Sales reportsOnce a day, each order’s date, country, currency, amount and refund status are copied to our own analytics store in the EU (BigQuery), for the developer’s sales dashboard. The copy has no email address and no customer reference, and the order number is replaced by a one-way hash.
The page after checkoutIt shows your licence to anyone who has its link, so keep the link to yourself. The link carries the provider’s order number and nothing else about you.
Loading the checkoutThe Spaceback Pro page loads the provider’s checkout only when you choose Buy. It then comes from the provider’s servers, which see your IP address and run the checkout under the provider’s own terms and privacy policy. Just reading the page sends nothing to the provider.
Lawful basisPerformance of the contract, Article 6(1)(b) GDPR.
RetentionAs long as the licence exists, plus the period that tax and accounting law requires sales records to be kept.

Purchases and subscriptions

Monthly, annual and lifetime Pro purchases are handled by Apple through StoreKit and the App Store. Apple processes payment, storefront, subscription and transaction information under the Apple Privacy Policy. Spaceback does not receive your card or billing details.

The app reads verified App Store entitlement information needed to decide whether Pro is active. That entitlement state may be cached locally so an existing purchase remains recognized when offline. Monthly and annual subscriptions can be managed or cancelled through the App Store subscription settings.

This website

The public Spaceback pages do not use advertising, third-party analytics, tracking pixels or behavioral cookies. The site runs on Google Cloud Run in the European Union (Belgium). Google’s servers necessarily see your IP address to deliver a page, but the site keeps no request log, so we do not store it. We do not use request information to build profiles or follow visitors across websites. The one page that loads anything from another company is the Spaceback Pro page, and only when you choose Buy (see Buying Spaceback Pro directly).

The optional email offer

If you enter your email on the early supporter offer page, this is the only part of Spaceback where you directly provide personal information. The app itself does not send us your address.

What is storedYour email address; the exact consent wording and time; confirmation status; the single-use code issued to you; and the minimum suppression status needed to honor an unsubscribe.
Why it is usedTo confirm your address, deliver the requested code, and send the occasional Spaceback and developer-news email described beside the checkbox.
Legal basisYour consent. The checkbox starts unticked and no address is stored when consent is not given.
RetentionAn unconfirmed signup is automatically deleted after seven days. Confirmed records remain until you unsubscribe or request deletion, subject to the minimal record needed to honor an opt-out or legal obligation.
ProcessorsGoogle Cloud stores these records in Firestore in the European Union. Amazon Web Services delivers the emails through Amazon SES in the United States. Records created before September 29, 2026 were stored in Amazon DynamoDB in the United States; that copy is no longer used and will be deleted. Redemption itself is handled by Apple.

We cannot see whether a given code was redeemed, and we never receive the billing details used with it.

Your choices and rights

You can unsubscribe through the link in any email. You may also ask to access, correct, export or delete the personal data connected to your email address, or withdraw consent, by contacting us below. You may lodge a complaint with the data-protection authority where you live.

Children

Spaceback is rated 4+ but is not directed at children, and it does not knowingly collect personal information from children. Usage statistics are off unless someone turns them on. The optional email offer is intended for adults.

Changes

If this policy changes, the updated version and date will be posted on this page.

Contact

Spaceback is developed by Vlada Misici under the Queazy name. For privacy questions or a data request, email vlada@queazy.app.