Privacy Policy for CodePeek
Effective date: September 7, 2026
1. Controller
The controller responsible for processing personal data in connection with CodePeek is:
Max Anton Schneider
c/o MDC Management #1582
Welserstraße 3
87463 Dietmannsried
Germany
Email: info@maxantonschneider.com
The contact details above may also be used for data-protection enquiries.
2. Privacy at a glance
CodePeek is designed as a local-first macOS application. Content that you paste, type, open, drop, generate, format, convert, or preview is normally processed only on your Mac.
CodePeek does not require a user account and does not operate its own cloud sync, analytics, advertising, tracking, or telemetry service. The provider does not receive your documents, snippets, clipboard content, generated values, or local preferences merely because you use the App.
Data may leave your Mac only when you deliberately use a feature that requires an external connection, such as enabling remote images, opening an external link after confirmation, contacting support, or using Apple’s Mac App Store services.
3. Data processed locally by the App
Depending on the features you use, CodePeek may process the following information locally:
- text and code pasted or typed into the App;
- clipboard content when you ask CodePeek to preview the clipboard or enable the corresponding open behaviour or global shortcut;
- files and folders that you select, open, drop, watch, or export;
- structured data, markup, diagrams, tokens, hashes, passwords, UUIDs, diffs, and other content supplied to or generated by a tool;
- preview and display preferences, including selected language, tool or mode, theme, font, word wrapping, syntax highlighting, pane state, split position, window behaviour, remote-image preference, and shortcut configuration;
- local snippet-history entries and pinning status; and
- operational state required to restore your current workspace.
This processing occurs on your Mac to perform the features you request. The provider does not have access to this locally processed content.
4. Local storage and retention
CodePeek stores preferences and workspace state in macOS user defaults. This can include the last content, selected language and mode, preview theme, window preferences, editor settings, remote-image preference, shortcut configuration, and current snippet selection.
Snippet history is stored as a JSON file in CodePeek’s Application Support directory, currently at Application Support/CodePeek/history.json within the App’s sandbox container. The App retains up to 10 unpinned history entries. Pinned entries are retained in addition to that limit until you unpin or delete them or remove the App’s local data.
Files exported by you are retained at the location you choose. Files opened by you remain under your control in their original location.
You can delete individual local history items in the App. You can also remove locally stored App data using macOS facilities or by uninstalling the App and deleting any remaining container data. The provider cannot remotely recover local content.
5. Clipboard access and global shortcut
CodePeek accesses clipboard content only when you request clipboard preview behaviour, use the configured global shortcut, or enable the relevant open preference. Clipboard content is processed locally and may be stored in the local workspace or snippet history as described above.
The provider does not receive clipboard content. You should avoid invoking clipboard preview while the clipboard contains passwords, authentication tokens, private keys, personal data, or other confidential information unless you intend to process it in the App.
6. Files, drag and drop, file watching, and exports
CodePeek uses the macOS App Sandbox and requests access to user-selected files. The App reads or writes files only after an action such as selecting, opening, dropping, watching, or exporting a file. File contents are processed locally.
If you enable watching for a selected file, CodePeek monitors that file for changes so the preview can be refreshed. Monitoring ends when the feature or relevant App session ends. The provider does not receive the file or its changes.
7. Preview isolation and security
CodePeek renders previews using a private codepeek:// scheme and a non-persistent WebKit data store. Bundled preview libraries are loaded from the App. Content Security Policy restrictions block ordinary network connections, form submissions, remote fonts, and non-bundled scripts from the preview.
External links require confirmation before being opened. These measures reduce unintended disclosure but cannot eliminate every risk from malformed or hostile content. Keep macOS and CodePeek updated and review untrusted content with appropriate care.
8. Optional remote images
Remote images are disabled by default. If you expressly enable remote images and preview content that references an HTTPS image, the App may connect directly from your Mac to the image host to retrieve it.
The external host may receive technical connection data such as your IP address, request time, requested URL, user-agent information, and other data normally transmitted in an HTTPS request. The host processes that information under its own privacy policy. The provider does not proxy, receive, or control those requests.
You can disable remote images in the App’s settings at any time.
9. Generated values and sensitive content
Passwords, UUIDs, and other random values generated by CodePeek are created locally using cryptographic randomness provided by the operating system. Hashing, token decoding, formatting, and conversion also occur locally.
JWT decoding does not verify a token’s signature. Hashing is not encryption. Do not treat decoded or hashed content as confidential merely because it has been processed by these tools.
10. No accounts, analytics, advertising, or developer telemetry
CodePeek does not use a CodePeek account system. The App does not contain developer-operated analytics, advertising SDKs, cross-app tracking, custom usage telemetry, or developer-operated crash reporting.
Apple may independently process App Store, purchase, installation, diagnostic, or device information under Apple’s own terms and privacy notices. That processing is not controlled by the CodePeek provider.
11. Mac App Store and Apple services
When you view, purchase, download, update, or review CodePeek through the Mac App Store, Apple processes personal data as an independent provider of the App Store service. This may include account, transaction, device, usage, and diagnostic information.
For details, consult Apple’s applicable privacy policy and App Store privacy information. CodePeek does not receive your full Apple payment details.
12. Contact and support requests
If you contact the provider by email, the provider processes the information you provide, such as your email address, name, message, attachments, and technical details, to respond to your request.
Depending on the context, the legal basis is Article 6(1)(b) GDPR for pre-contractual or contractual communication, Article 6(1)(c) GDPR for compliance with legal duties, or Article 6(1)(f) GDPR for the legitimate interest in handling enquiries, providing support, preventing abuse, and documenting communication.
Support correspondence is retained only as long as necessary to handle the request and meet applicable legal retention or defence requirements. Do not send secrets or personal data that are not necessary for support.
13. Legal bases for local processing
To the extent that local processing performed by CodePeek falls within the provider’s responsibility under data-protection law, it is necessary to provide the App’s requested functions and is based on Article 6(1)(b) GDPR. Optional features initiated by you, such as loading remote images, are performed at your request. Where consent is legally required, processing is based on Article 6(1)(a) GDPR and you may withdraw consent with future effect by disabling the feature.
Processing necessary to comply with law is based on Article 6(1)(c) GDPR. Security, abuse prevention, and the establishment, exercise, or defence of legal claims may be based on Article 6(1)(f) GDPR.
14. Recipients and international transfers
Because the App processes content locally, the provider does not ordinarily disclose App content to recipients or transfer it to another country.
Information sent in a support request may be processed by the provider’s email, hosting, or technical service providers where necessary. Those providers act under applicable data-protection requirements. Depending on the provider and routing used, data may be processed outside the European Economic Area. Where required, an adequacy decision, standard contractual clauses, or another lawful transfer mechanism is used.
Direct requests to remote-image hosts, external websites, and Apple are governed by the practices and transfer arrangements of those independent recipients.
15. Retention
The provider does not set or control retention for content stored only on your Mac. Local retention is described in Section 4.
Personal data received by the provider, such as support correspondence, is deleted when it is no longer necessary for the purpose for which it was collected, unless statutory retention duties or legitimate legal-claim interests require longer storage. German commercial and tax records may need to be retained for the applicable statutory periods.
16. Automated decision-making and marketing
The provider does not use personal data from CodePeek for automated decision-making, profiling, targeted advertising, or direct marketing.
17. Your rights
Subject to the conditions in applicable law, you may have the right to:
- obtain access to your personal data under Article 15 GDPR;
- rectify inaccurate data under Article 16 GDPR;
- request erasure under Article 17 GDPR;
- restrict processing under Article 18 GDPR;
- receive data in a portable format under Article 20 GDPR;
- object to processing based on legitimate interests under Article 21 GDPR;
- withdraw consent at any time with future effect under Article 7(3) GDPR; and
- lodge a complaint with a competent data-protection supervisory authority under Article 77 GDPR.
To exercise rights concerning data processed by the provider, contact info@maxantonschneider.com. Because most App content remains solely on your Mac, the provider cannot access, identify, export, correct, or delete that local content for you.
18. Security
CodePeek uses the macOS App Sandbox, user-selected file permissions, local processing, non-persistent preview storage, and restrictive preview policies to reduce data exposure. No security measure is infallible. Users remain responsible for securing their Mac, account, backups, files, and confidential content.
19. Children
CodePeek is a general developer utility and is not specifically directed at children. The provider does not knowingly collect personal data from children through a CodePeek account or online service because no such account or service is provided.
20. Websites and external pages
This Privacy Policy covers the CodePeek macOS App. A website, product page, support page, or other external service used in connection with CodePeek may require its own privacy information, especially where it uses hosting logs, cookies, forms, analytics, embedded content, or other online services.
21. Changes to this Privacy Policy
This Privacy Policy may be updated to reflect changes in the App, law, or processing practices. The current version will be made available at the Privacy Policy URL shown in the Mac App Store. Material changes will be communicated where required by law.
22. Contact
For privacy questions or requests, contact:
Max Anton Schneider
Email: info@maxantonschneider.com