← Parallex

What leaves your Mac

Parallex runs on your Mac and keeps your instances, their data and your settings there. This page lists everything it sends anywhere. It's short.

The daily update check

Once a day, and whenever you choose Check for Updates, Parallex asks parallex.mandip.dev whether there's a new version. The request says six things:

X-Parallex-Version: 0.20.0 (this Parallex)
X-Parallex-OS: 26.6 (macOS version)
X-Parallex-Arch: arm64 (Apple silicon or Intel)
X-Parallex-Active: day,week (first check today, this week, this month, or ever)
X-Parallex-Bucket: 42 (a number from 0 to 99 picked at random once)
X-Parallex-Mac: 3f2a…9c1e (a random number picked once, from Parallex 1.7)

That's how many Macs use Parallex gets counted, and which versions, without knowing whose they are. The random number is there so each Mac is counted once, whether it checks once a month or ten times a day: it's made on your Mac, isn't derived from anything about you or it, and is never tied to the usage report's number. The server keeps a count per day, version, macOS, chip and kind of check; the days each number was seen, for 90 days; each number with the day it was first seen and the version, macOS and chip it last came with, until 90 days after its Mac last checked, when it's forgotten; and a running total of Macs. The request also names Parallex and its version in its User-Agent, as apps do.

The number lets a new version go out to a few Macs first (those under 10, say) before everyone, so a bad release reaches few people. About one Mac in a hundred has each number, so it doesn't single yours out.

Like any website, the server sees the address a request comes from while answering it. Parallex doesn't store it and keeps no request logs; for a minute it's used, in memory, to ignore a burst of checks from one place. Cloudflare, which runs the server, handles requests under its own privacy policy.

If the server doesn't answer, Parallex asks GitHub directly instead, and GitHub is told only that a Parallex is checking (it sees the address too, as it does for any download from GitHub). Updates are verified against a signing key built into the app either way, so the server couldn't hand you a bad update even if it wanted to.

You can turn automatic checks off in Settings › About.

The Terminal installer

curl -fsSL https://parallex.mandip.dev/install | sh asks the same server for the latest version and says it's an install, with the macOS version and chip. It's counted the same way.

The anonymous usage report

Parallex is free, and it changes every week. To know which releases and app updates break things, often before anyone has to write in, it sends a short report once a day, with the update check. New installs choose in the first-run setup, where it's on unless you turn it off; people who used Parallex before version 1.6 are asked once (if you had turned the old weekly report off, it stays off). Nothing is recorded before you've said yes. It's one switch, Share anonymous usage in Settings › About (or parallex usage --no-share in Terminal), and See What's Sent shows the whole report first, as does parallex usage.

What it holds:

{ "name": "instance.created", "props": { "app": "com.tinyspeck.slackmacgap", "kind": "copy", "result": "ok" }, "n": 1 }

Never sent: instance names, file names, paths, what's inside your instances, sites of your own, or apps that aren't well-known. The server accepts only the event names and values listed in its public code, checks app IDs, app names and versions against fixed patterns, takes only a few new app IDs a day, and drops anything else. It doesn't store your IP address with a report, or at all.

What a Mac reported on a given day is kept for 90 days; after that only totals remain, per day and version, with no install numbers. The number itself is forgotten 90 days after a Mac last reports. Turning sharing off deletes the number and anything waiting to be sent on your Mac, and nothing more is recorded.

Notices and the compatibility list

Twice a day Parallex downloads parallex.mandip.dev/advisories.json, a signed list of notices about apps whose copies misbehave. It's the same file for everyone, and fetching it sends nothing about you or your apps. The compatibility list shows only apps Parallex's maintainer adds, with usage reports summed up; reports alone never put an app there.

Things you do yourself

Nothing else

Inside a copy, the app's own updater is turned off, and its update address is parallex.mandip.dev/no-updates.xml, a file that never has an update, so the vendor's build can't replace the copy. Should that updater ever ask, it gets that file, like any web page; nothing about it is counted or kept.

No analytics beyond the report above, no third-party trackers or SDKs, no account. Your instances' names and anything inside them stay on your Mac.

The server's code is public, so you can check all of this.