PRIVACY POLICY

NetMaster Privacy Policy

Effective August 23, 2026

NetMaster is designed to diagnose a network without a developer-managed account, tracking the user, serving advertising, or sending analytics to the developer. Optional Mac monitoring uses the user’s Apple iCloud account and private CloudKit database.

Information stored on the device

NetMaster keeps up to 250 completed diagnostic reports in protected, atomic files in the app’s private Application Support storage. A recovery copy protects against partial writes. By default a saved report retains what the scan measured, including the Wi‑Fi name, interface name, local and public addresses, gateway, resolver addresses, tunnel-interface names, network organization information, and egress-location details, so a stored report reads the same as it did when the scan finished. This history is not transmitted automatically. A report leaves only when the user uses the system Share action or requests the optional written interpretation described below; both paths use a separately generated redacted copy by default. Under More → On-device history, “Keep full detail in history” can be turned off; NetMaster then saves metrics only, removing those values before saving and stripping them from both copies of reports already stored.

An opaque per-network grouping token lets history compare scans from the same network even when its name is not retained. It is generated from the Wi-Fi name using a random device-only Keychain secret. Users can delete history from the History or More screen. System backups may include local app data according to the user’s backup settings.

Dropout Investigator sessions are not added to scan history. One redacted checkpoint of categorical samples, incidents, and timestamps is atomically updated in protected Application Support storage, excluded from backup, and replaced by the next session so a crash or system expiration can restore an honest partial report. Gateway, Wi‑Fi, resolver, and IP addresses are absent from that checkpoint. Optional access-point identifiers are compared in memory only to detect that a handoff occurred; the identifiers are not included in the checkpoint or session report.

Optional private Mac monitoring

When the user enables “Share this Mac with my devices,” the Mac samples processor, memory, storage, thermal, battery, uptime, and aggregate network-interface counters about every five seconds. It keeps one-minute samples locally for up to 30 days and writes hourly archives, alert settings, alerts, device status, and short-lived live samples to the user’s private CloudKit database. The developer has no monitoring server and cannot view that private database. Top-app names and per-app resource estimates are off by default and are included only when public sandbox-compatible macOS APIs provide them reliably.

The iPhone and Mac must use the same iCloud account and complete a six-digit pairing step. Invitations expire after 15 minutes and store a salted SHA-256 digest rather than the code. One viewer identifier is authorized; generating a new code replaces it. The foreground iPhone dashboard renews a short viewer lease and polls CloudKit for best-effort updates. CloudKit can delay or combine changes. A remote speed test runs only after confirmation and transfers real test data from the Mac; passive traffic counters create no test traffic. The Mac can optionally use Apple’s Service Management framework to launch at user login.

Information shown and shared

Live reports can show network names, addresses, resolver information, public network organization, and approximate public egress location. Displaying these values on the device does not send them to the developer. A system-shared report uses address redaction by default. The separate written-interpretation action below is always redacted regardless of the sharing toggle.

Optional written interpretation

Only when the user taps “Explain these results,” NetMaster creates a redacted text copy of that report and sends it through a developer-operated Netlify function and Netlify AI Gateway to Anthropic’s commercial Claude API. The copy removes local and public IP addresses, Wi‑Fi name and access-point identifier, network organization and approximate egress location, resolver IP addresses and provider details, and custom expected-resolver identifiers. It can still contain non-identifying diagnostic measurements and general findings about resolver behavior because those are the evidence being interpreted.

Netlify necessarily processes the source IP and ordinary request metadata to deliver and rate-limit the request. The NetMaster function does not write the report or interpretation to a developer database. Netlify states that its AI Gateway does not store prompts or model outputs and routes requests only to providers operating under a zero-data-retention policy. Anthropic processes the redacted text under that route only long enough to return the interpretation. The returned interpretation is held in the app for the current report view and is labeled as interpretation rather than measurement. See the Netlify privacy statement, AI Gateway policy, and Anthropic privacy information.

Optional Wi‑Fi identity access

If the user chooses to reveal Wi‑Fi identity, the operating system may request Location Services authorization before providing the current Wi‑Fi name, BSSID, and security. NetMaster does not request geographic coordinates and does not start location updates. The app remains usable when permission is declined.

On native macOS, NetMaster also reads connected-radio band, channel, channel width, PHY mode, RSSI, noise, signal-to-noise ratio, and negotiated transmit rate through Apple’s public CoreWLAN framework. Those radio measurements do not require Location Services and contain no SSID or BSSID. They may be retained in local diagnostic history and included in a user-shared report because they are the requested diagnostic evidence. Public iPhone and iPad APIs do not expose these exact radio values.

Local network access

NetMaster tries up to four short TCP connections to common service ports on the gateway address the operating system already reports, then reuses only the answering port for first-hop timing. This separates local first-hop delay from upstream delay. It does not scan, enumerate, or identify other devices. The gateway address is retained in saved history only while “Keep full detail in history” is on, and is redacted from shared reports by default.

Remote measurement services

Network diagnostics require communication with remote systems, which necessarily receive the public source IP and ordinary request metadata needed to respond. For conservative App Store disclosure, NetMaster treats IP-derived coarse location and diagnostic request data as linked to the source network address that sent the request. NetMaster does not attach an advertising identifier, account identifier, contact information, or cross-app tracking token, and it does not use this data for tracking.

The user-started Services check makes three small, bodyless HTTPS HEAD requests to each listed public web endpoint and starts equivalent Apple and Cloudflare controls in the same rounds. Each request has a one-time random cache-busting value that is not retained or reused and is unrelated to a person, device, or account. NetMaster retains only the resulting local timings and response coverage for the on-screen comparison; it sends no account credentials or user content. A timing difference cannot identify whether the cause is local Wi‑Fi/router conditions, the device, VPN or filtering, DNS/TLS, geography, routing, an ISP, the tested service, or a transient event.

Those measurement providers process request data under their own policies. The developer does not receive a copy of NetMaster’s diagnostic results from those probes. The optional written interpretation follows the separate, user-started path described above.

Tracking, accounts, and children

NetMaster contains no advertising, analytics, tracking, or crash-reporting SDKs. It has no developer-managed user account and does not sell personal information. Optional monitoring relies on the user’s Apple iCloud account. It is not directed to children and does not request names, contact lists, dates of birth, or account profiles.

Data use and finite monitoring

A full scan uses a user-selected throughput-payload budget. Light allows up to roughly 17.5 MB, Balanced up to roughly 54.5 MB, Thorough up to roughly 148.5 MB, Gigabit up to roughly 932.5 MB, and Multi-gigabit up to roughly 2.4 GB, including bounded throughput retries. Small diagnostic requests, response headers, TLS handshakes, UDP DNS checks, and normal protocol overhead are additional. NetMaster asks before running a full speed test on a path the operating system marks cellular, expensive, or constrained unless the user has enabled that preference. The Dropout Investigator sends small recurring HTTPS heartbeats and bounded controls after a suspected failure. On iOS 26, only after the user taps Start, it requests Apple’s finite continued-processing task so the selected session may continue when the phone locks; the system may reject, cancel, or expire it, and any later gap is reported as unknown. iOS 17–25 requires NetMaster to remain visible. On macOS, a finite user-started session holds a scoped user-initiated activity to avoid App Nap while its window is covered or the display is locked; intentional whole-system sleep remains a reported unknown gap. No VPN, audio, location-based background execution, or daemon is used. The optional Mac health monitor may be registered as a user-visible login item.

Changes and contact

This policy may be updated when NetMaster’s behavior or service providers change. Questions and privacy requests can be sent to jacknrichmond@gmail.com.