DropHarbor
Mac app · Privacy policy

DROPHARBOR

Privacy Policy

Last updated: October 10, 2026

This policy explains how the DropHarbor Mac app handles data. DropHarbor is an independent app and is not affiliated with Twitch.

1. The developer does not collect user information

The DropHarbor developer does not automatically collect, receive, or store your personal information through this app. There is no developer-operated data server. The app does not upload account details, usage records, diagnostic logs, or device information to the developer, and it contains no advertising SDK, third-party analytics SDK, or automatic telemetry.

The developer does not sell your information, use app data for advertising tracking, or build cross-app user profiles. If you choose to contact support or share a file, the recipient receives the information you choose to provide.

2. Necessary processing on your device

To provide the features you choose to use, the app processes and stores the following information on your device:

  • Twitch sign-in information: Your account ID, login name, session tokens, and website cookies are used to maintain your sign-in and make account-related requests to Twitch. Session credentials are stored in your device’s Keychain; website cookies are stored by this app’s WebKit website data store. DropHarbor does not store your Twitch password. Information entered on Twitch’s sign-in page is handled by that page.
  • Settings and campaign information: Language, appearance, notification and background preferences, campaign selections, Drops progress, and claim status are used to display the app and run tasks.
  • Task display cache: Recent task information is used for up to 24 hours to restore the interface after restarting. It contains an account identifier and task information, but no sign-in token. Once expired, it is no longer used to restore the interface.
  • Optional proxy settings: The server address, port, username, and password you provide are stored in your device’s Keychain and used to connect to the proxy server you select.
  • Local diagnostic logs: Logs record timestamps, a random app-session identifier, task actions, request results, and public game, campaign, and channel information to help diagnose problems. They do not contain passwords, sign-in tokens, request headers, or response bodies, and are not automatically uploaded. Logs rotate at approximately 2 MiB per file, with one current file and up to four archives. They are not deleted on a fixed daily schedule.

DropHarbor does not automatically send these local records to the developer. Copies you save or share are handled by the recipient or storage service you choose.

3. Connections to Twitch and other services

Twitch features require network requests. The app connects directly to Twitch and its content delivery services to sign in, load campaign and reward images, synchronize progress, check playlists, and send watch-heartbeat and reward-claim requests.

Those services receive the account or session identifiers, client or device-session identifiers, actions, and network information such as your IP address needed for those requests. Twitch’s sign-in page may load other services and use cookies according to Twitch’s settings and policies. The DropHarbor developer does not receive this information sent to Twitch.

Twitch’s handling, retention, and deletion of account, website, and server-side information are governed by the Twitch Privacy Notice. The developer does not control Twitch’s data practices.

If you enable a custom proxy, requests pass through the proxy server you select. Proxy credentials are used only for that connection. The proxy provider determines its own data practices; DropHarbor does not provide a proxy service. External links use the settings and privacy policies of the browser or app you choose to open them.

4. Permissions and security

Notifications are optional and are used only after you enable them and grant system permission. Declining notifications does not restrict other features. You can pause tasks and disable background work, notifications, or idle-sleep prevention at any time.

The app uses the system Keychain for sign-in and proxy credentials with a device-only storage class. These credentials are not synchronized through iCloud Keychain. The app has no separate DropHarbor account system.

Diagnostic logs are excluded from device backups. Other local information may be copied according to your system or backup settings. System security features help protect data, but no storage or transmission method can guarantee absolute security.

5. Removing data and managing your account

Signing out in the app’s Settings stops tasks and removes the saved Twitch credentials, the app’s WebKit sign-in data, task display cache, and campaign selections. Signing out does not delete your Twitch account, revoke sessions on Twitch’s servers, or remove proxy settings, other preferences, local diagnostic logs, or files you have already shared.

To remove proxy authentication information, clear the username and password in proxy settings and save your changes. Uninstalling the app does not guarantee removal of system Keychain items, so we recommend signing out and clearing proxy credentials first.

To delete your entire Twitch account, open Twitch’s official account deletion page from Settings → Twitch account and data, and complete the confirmation on Twitch yourself. This affects your whole Twitch account, not only its connection to DropHarbor. Twitch determines the scope and timing of server-side deletion.

Manage and delete any saved or shared log copies at their saved location or through the receiving service.

6. Children and policy changes

DropHarbor is not directed at children and does not collect children’s personal information for the developer through its own features. Follow Twitch’s account and age requirements when using its services.

If the app’s data handling changes, we will update this policy and the in-app explanation. Where new uses or permissions require notice or authorization, we will provide notice and obtain the appropriate authorization as required.

7. Contact the developer

For privacy questions, use the contact channel provided through the App Support link on DropHarbor’s App Store product page. Do not include passwords, sign-in tokens, website cookies, or proxy passwords when submitting a question.