Privacy Policy
Last updated: September 20, 2026
Introduction
BucketMate ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we handle information when you use:
- The BucketMate macOS app
- The BucketMate iOS app (iPhone and iPad)
- The BucketMate Web app at https://web.bucketmate.app
- This website at https://www.bucketmate.app
Together, these are the "Services." The browser extension has a separate privacy policy.
Data Collection
BucketMate is designed with privacy as a core principle. We collect only what we need to run the product, process purchases, and improve stability.
- Account data (Web, iOS, and macOS App Store): If you sign in, we collect the email address you provide, send a one-time verification code, and keep a session so we can restore your Pro status. Signing in with the email used for a website license that includes that platform unlocks Pro. We do not use this account to store your S3 credentials or files.
- Purchase data: For macOS, Web, and Universal licenses we receive order details from Polar (processed by Stripe), such as email, product purchased, and license status. For App Store iOS and macOS purchases, Apple processes payment. We may receive App Store / RevenueCat entitlement status needed to unlock Pro, including when a website license is applied on those apps.
- Error reporting and usage analytics: We use PostHog for crash/error reports and product analytics on macOS, iOS, and Web. The Web app also uses OpenPanel for usage analytics. Data may include error messages, stack traces, device or browser information, app version, and anonymized product events. This data is not intended to include your S3 credentials, file names, bucket names, or object contents. You can turn analytics off where the product offers that setting.
- Local storage: S3 credentials, connection settings, workspaces, and preferences stay on your device. macOS and iOS use Apple Keychain and on-device storage. The Web app stores data in your browser profile, with optional passkey encryption.
- Network transmission: We send data off your device only when you (1) talk to your S3-compatible storage providers, (2) sign in, activate a license, or check Pro status with BucketMate, Polar, Apple, or RevenueCat, (3) complete a purchase, or (4) send error/analytics events when that is enabled.
Credentials and Security
Your S3 credentials and connection information are handled securely:
- Secure storage: Access keys, secret keys, and session tokens are stored in macOS/iOS Keychain, or locally in the browser for the Web app.
- No credential upload: Credentials are never sent to BucketMate servers.
- Local processing: S3 operations run directly from your device (or browser, via the extension) to your storage providers. We do not proxy object data.
Third-Party Services
BucketMate uses the following third-party services:
- S3-compatible storage providers: AWS, Cloudflare, Backblaze, DigitalOcean, MinIO, Supabase, and others you connect. Their privacy policies apply to those operations. We do not see your storage data.
- PostHog: Error tracking and product analytics. PostHog's privacy policy can be found at https://posthog.com/privacy.
- OpenPanel: Usage analytics for the Web app.
- Polar / Stripe: Payment and license delivery for macOS, Web, and Universal purchases.
- Apple App Store: Payment processing for the iOS app and the macOS App Store app.
- RevenueCat: App Store entitlement checks so Pro unlocks after an Apple purchase or after you sign in with a website license that includes that platform.
App Store and Payment Processing
Payment processing is handled by Apple (iOS App Store) or Polar/Stripe (website licenses). We do not collect or store card numbers. We may receive basic purchase information needed to verify your license or refund a Polar order.
Children's Privacy
BucketMate is not intended for use by children under the age of 13. We do not knowingly collect information from children. If you believe we have inadvertently collected information from a child, please contact us immediately.
Your Rights
You have the following rights regarding your data:
- Local Data Control: You have full control over credentials and settings stored on your device or browser.
- Analytics: You can turn analytics off where the product provides a setting.
- Data Deletion: You can delete the app, clear browser data, or remove Keychain items to delete local data. Error reports may be retained according to our analytics providers' retention policies.
- Access and Correction: Questions about account or error-report data can be sent to support@bucketmate.app.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.
Contact Us
If you have any questions about this Privacy Policy, please contact us at:
Email: support@bucketmate.app