Back to Home

Preflight

Privacy Policy

Last updated: August 14, 2026

Short version: Preflight inspects and safely optimizes documents privately on your Mac. It collects no data, performs no network requests, and never modifies the source PDF you select.

1. Data collection

Preflight does not collect or transmit personal data, usage data, diagnostics, analytics, document contents, or locally saved settings to the developer or any third party. It includes no advertising or tracking technology. The settings described below are stored locally on your Mac so the app can provide its features; this local app storage is not developer data collection.

2. Network access

Preflight performs no network requests. Document inspection, optimization, local comparison, and verification-receipt export do not upload files, candidates, outputs, receipts, or results to the developer or to any third party.

3. Document processing

Preflight accesses only source PDFs that you explicitly select or drop into the app, or that macOS Shortcuts provides to a Preflight action, and output folders or receipt locations you explicitly select in a macOS panel or Save File action. This includes batches of up to 100 directly selected PDFs in the app; folders are not searched. Shortcuts actions process one file per invocation. Preflight's App Sandbox user-selected read/write entitlement is required so it can read provided files and create chosen outputs. Despite that entitlement, source PDFs are read-only by Preflight's behavior: they are inspected, hashed, compared, and used to generate candidates, but are never modified, overwritten, moved, or removed. Optimization creates a separate PDF in a user-selected destination or app-owned temporary storage for return to Shortcuts.

After a successful single-file optimization, Preflight can display the original and output locally side by side after recalculating and matching both SHA-256 hashes. At your request it can export an unsigned single-file JSON receipt or a batch JSON/CSV receipt. Receipts contain file names without directory paths, exact byte counts, hashes, and relevant profile, result, and optimization fields. They are local evidence rather than digital signatures or external acceptance proof, and Preflight does not retain a separate receipt copy.

4. Local profile settings

Named submission profiles and optimization presets are stored only on your Mac in Preflight's Application Support container. A saved profile contains its name, identifier, creation/update dates, and requirement values such as byte and page limits, searchable-text preference, and encryption preference; a saved optimization preset contains its name, identifier, dates, and curated optimization mode. This storage never contains PDF paths, PDF contents, inspection results, or optimization results. You can update or delete these settings in the app. The built-in email profile is part of the app and is not written to profile storage.

5. Recent Activity

Preflight keeps a local Recent Activity list of up to 100 past scans in the app's macOS preferences storage, retained across launches until you clear it with Clear History. Each entry contains the PDF's file name with all directory path information removed, the scan outcome and timestamps, the profile name and requirement values in effect, the observed file size and page counts, and per-check results. Entries never contain file paths, security-scoped bookmarks, cryptographic hashes, or document text. Scans still running when a new PDF is selected finish in the background and are recorded the same way; their in-progress status exists only in memory.

6. On-device Apple Intelligence explanations

On Macs running macOS 26 with Apple Intelligence enabled, Preflight can summarize what a scanned PDF is about. Bounded native text extracted from the PDF is processed entirely on the Mac by Apple's on-device Foundation Model; Preflight sends nothing over the network, and displayed explanations consist only of verbatim passages that Preflight independently verifies against the PDF's own text before showing them. An explanation can also be viewed from its scan's Recent Activity entry during the same app session. Because explanations contain verbatim document excerpts, Preflight holds them in memory only: they are never written to disk and disappear when the app quits. Apple Intelligence availability and platform behavior are subject to Apple's terms.

When you import a publisher-guidelines PDF to draft requirement values, the guideline text is extracted in a separate sandboxed helper process with no file access, proposed values must cite exact supporting excerpts, and nothing from the guideline PDF is stored unless you choose to save the resulting profile.

7. Temporary files and retention

Inspection, including the Shortcuts inspection action, does not create document copies or exports. During an optimization request, Preflight creates bounded candidate PDFs in a private local temporary directory and attempts to remove that directory when the request succeeds, fails, or is cancelled. The final verified candidate for an in-app export is staged in a cryptographically random, owner-only hidden directory beside the user-selected output, then published as the new output with an exclusive atomic rename. That rename is the commit point: cancellation observed before it creates no output, while a rename that wins a cancellation race is retained and reported as a successful output. Staging and candidate files are local and normally cleaned up.

The Shortcuts optimization action returns its verified PDF from a separate, UUID-named invocation directory in Preflight's app-owned temporary storage. You must pass that result to Shortcuts' Save File action to retain it. Whenever Preflight prepares another Shortcut output, it makes a best-effort attempt to remove prior UUID-named invocation directories whose trustworthy filesystem modification time is older than seven days. It leaves recent directories, the current invocation, symlinks, non-UUID entries, and entries whose type or age cannot be trusted. Individual cleanup failures do not fail the Shortcut. This seven-day threshold is not a guaranteed retention period: macOS may reclaim temporary files sooner, and unreadable files, races, or conservative safety checks may leave an artifact longer. Preflight does not promise that the operating system will delete temporary output on a particular schedule.

Under namespace interference, if Preflight can no longer prove that a staging entry is the one it created, it deliberately avoids deleting that entry. This conservative threat-model behavior can leave a hidden staging artifact rather than risk deleting another process's file. Batch state and file access are session-only: Preflight creates no persistent file bookmarks and does not resume batches. Apart from the Recent Activity summaries described above, Preflight retains no document contents or inspection results after the app process ends; document text and on-device explanations are never persisted. Standard macOS and Apple frameworks remain subject to Apple's platform behavior and privacy terms.

8. Children's privacy

Since Preflight collects no data, it is safe for users of all ages. We do not knowingly collect any information from children under 13.

9. Changes to this policy

This policy must be updated before releasing a version whose data or network behavior differs from the statements above.

10. Contact us

For support or privacy questions, contact trolls.dev LLC at [email protected] or visit the Preflight support page.