RejectProofRun the free check

Privacy Policy

RejectProof · Last updated 16 September 2026

This page explains what RejectProof collects, why, and what never leaves your device. It is written to be checked, not just read: you can watch every request in your browser's DevTools → Network tab.

Your build stays in your browser

  • The .ipa / .app.zip you drop is opened locally by a Web Worker in your tab. There is no file-upload endpoint on our server.
  • The binary, your assets, your source and your signing certificates are never transmitted or stored by us.

What is sent to our server

Before anything is sent, the exact JSON and its size are shown on screen and nothing goes out until you click. The payload contains only:

  • Info.plist key names. Values are kept only for a fixed allowlist of Apple keys (bundle id, version, permission usage texts, ATS settings, background modes, etc.). Values of any other key are replaced by "[redacted]" — ad-network ids, Maps keys, custom API keys stay with you.
  • PrivacyInfo.xcprivacy (privacy manifest) keys, a summary of the embedded provisioning profile (team, expiry, Apple entitlements; custom entitlements redacted), and the names of embedded frameworks.
  • How many times each of our keywords (e.g. ATTrackingManager, SKPaymentQueue) appears in the main executable, with a short text snippet around the match.
  • Your answers to the 10-question survey.

This summary (typically 2–20 KB) is stored so that your report link keeps working.

Email

We ask for an email address to send you the permanent link to your report and to attach purchased credits to it. We do not send marketing email. Emails are delivered through Resend.

Payments (Paddle)

Payments are handled by Paddle.com (Paddle.com Market Ltd / Paddle.com Inc.) as merchant of record. Paddle collects your payment details, billing country and email to process the order, calculate tax and issue the receipt; we never see your card number. Paddle sends us the transaction id, the product purchased, the amount and the email you entered so we can add credits. See Paddle's privacy policy.

Hosting and logs

The site is hosted on Vercel and data is stored in Supabase (Postgres). Standard server logs (IP address, user agent, timestamps) are kept by the hosting provider for a limited time for security and debugging. We do not use advertising trackers or third-party analytics cookies.

Retention and deletion

Reports and the associated summary are kept so your link stays valid. Email us at support@rejectproof.com to have your reports, email and credit records deleted; we will do so within 30 days, except for transaction records Paddle requires us to keep for tax purposes.

Open source

The analysis engine (zip reader, plist parser, string scanner, rules) is plain TypeScript with no server dependency and is being published so you can read exactly what runs on your file.

Contact

Data controller: the individual developer operating RejectProof, based in Turkey. Contact: support@rejectproof.com.

Questions: support@rejectproof.com