APPKEY
Privacy Policy
Last updated: September 27, 2026
AppKey is a Mac app launcher for the apps in your Cloudflare Access catalog. It works directly between your Mac and Cloudflare. We don't run an AppKey server, we don't have an AppKey account system, and the app sends nothing to us. This policy explains what the app and this website handle, where that information lives, and what you can do about it.
1. Information we collect
The AppKey app collects no data. Nothing you connect, import or organize in AppKey is sent to us or to any server we operate. AppKey does not collect or transmit:
- Your Cloudflare password, API tokens or sign-in codes
- Your app catalog, starred apps, collections or recently opened apps
- Advertising or device identifiers
- Location, contacts, browsing history or files
- Usage analytics or behavior profiles
AppKey does not require you to create an account with us.
2. What the app reads from Cloudflare
When you connect a workspace, you enter your Cloudflare Zero Trust team name and sign in on Cloudflare's own page in your browser. You then choose whether to give AppKey read-only access. AppKey asks for four read permissions:
- User details, to confirm which Cloudflare user authorized the connection
- Account settings, to list the accounts you allowed and match one to your team
- Access organization, to confirm that the account owns the team name you entered
- Access applications, to read the apps in your catalog: names, addresses, icons and whether they're visible
AppKey can't change anything in your Cloudflare account. It uses this information only on your Mac to show and open your apps. Requests go directly from your Mac to Cloudflare's own servers (such as dash.cloudflare.com and api.cloudflare.com). Cloudflare handles them under its own privacy policy.
Sign-in uses the industry-standard OAuth method with PKCE. To receive Cloudflare's answer, AppKey briefly listens on your Mac at 127.0.0.1, which can't be reached from other devices. It stops listening when sign-in finishes or you cancel. No password or client secret is built into AppKey.
3. What stays on your Mac
- Your connection: a short-lived Cloudflare access token, saved in your macOS Keychain. AppKey doesn't keep a long-lived refresh token, so when it expires you reconnect.
- Your catalog: app names and addresses are held in memory while AppKey runs and are not written to disk.
- Your preferences: starred apps, personal collections, recently opened apps, appearance, and any workspace branding you set up. Branding can include a company name, colors, a welcome message, a support link and a logo image you pick. These are saved in AppKey's own app container on your Mac.
AppKey uses the standard Mac app sandbox. It opens only the image files you choose for a logo, and only to read them. You'll find a short version of this policy in AppKey under Settings › Privacy.
4. App icons and opening apps
To show icons, AppKey downloads each app's icon from the address set for that app in your Cloudflare Access settings. These requests carry no cookies, passwords, tokens or referrer. Like any web request, the server hosting an icon can see your IP address.
When you open an app, AppKey hands its address to your default web browser. Your browser, Cloudflare Access and the app itself decide whether you need to sign in. AppKey never passes its Cloudflare token or any cookies to your browser.
5. Analytics, advertising and tracking
AppKey contains no advertising, analytics or crash-reporting code, from us or anyone else. It doesn't track you across apps or websites. If this ever changes, we'll update this policy and the App Store privacy details first.
6. Crash reports and diagnostics
AppKey relies only on Apple's standard, opt-in crash and diagnostic reporting. If you choose to share analytics with app developers in your Mac's settings, Apple may give us reports with details like your Mac model, macOS version, AppKey version and technical crash information. We use them only to fix problems. They aren't meant to include your catalog, your app addresses or your Cloudflare details.
7. Start at login
AppKey can open automatically when you log in to your Mac. This is off until you turn on “Start AppKey at login” in Settings, and you can turn it off at any time there or in macOS System Settings.
8. Disconnecting and deleting your data
Disconnect Cloudflare in AppKey's Settings clears the catalog from the app, deletes the saved token from your Keychain, and asks Cloudflare to revoke AppKey's access. You can also remove AppKey's access from your Cloudflare account at any time.
To remove everything, disconnect, then delete AppKey. On a Mac, preferences can remain in AppKey's container (~/Library/Containers/app.appkey.macos) after you delete the app, so remove that folder too. Since AppKey has no account with us and we never receive your data, there's nothing for us to delete on our side.
9. This website and the launch list
The statements above describe the AppKey app. This website works a little differently:
- Launch list. If you join, we store your email address, when you signed up and which list you joined, so we can email you about AppKey's availability and early access. Joining doesn't create an AppKey account or connect your Cloudflare account. Your signup is kept in our own mailing-list system, which RYSNAS runs itself, and launch emails are sent through our Google Workspace email. We don't send an automatic message when you join.
- Spam protection. Your IP address is used only for a moment to limit repeated signups. It isn't stored with your signup.
- Hosting. The site runs on Cloudflare, which processes website requests, including normal network information such as IP addresses, to deliver and protect the site.
- Visit counts. This website uses Umami, a cookieless analytics tool that RYSNAS runs itself, to count page visits: the page, the site that sent you, your browser, device type and language, and your rough location (country and city). It builds no profile of you, doesn't follow you to other sites, and doesn't store your IP address. This applies to the website only; the AppKey app has no analytics.
- No cookies for tracking. This website uses no advertising or analytics cookies.
We keep your signup while the launch list is active, unless you ask us to remove it. To leave the list, use the link in any launch email or write to support@appkey.app from the address you signed up with.
10. Support communications
If you contact us, we receive your name, your email address, your message, and any screenshots, files or device details you choose to send. We use them only to answer you, investigate problems and improve AppKey.
Please don't send passwords, Cloudflare API tokens, access tokens, or screenshots that show them. We never need them. Support email is kept for no more than 24 months, unless a longer period is required for legal, security or recordkeeping reasons.
11. Data sharing
We don't sell or rent personal information. We don't share it with advertisers, data brokers or marketing companies. Service providers process information only as needed to run what you choose to use: Apple for the App Store and diagnostics, Cloudflare for your Access connection and for hosting this website, and Google Workspace for our email. Each processes information under its own terms and privacy policy.
12. Legal requirements
We may disclose information we hold when reasonably necessary to comply with the law, respond to a valid legal request, protect our rights, or investigate fraud, abuse or security problems. Because AppKey never sends us your catalog or Cloudflare details, we don't hold them.
13. Security
AppKey stores its token in the macOS Keychain, runs in the Mac app sandbox, uses HTTPS for every request, and only imports apps with safe HTTPS addresses. No system is perfectly secure. You help by protecting your Mac with a password, keeping macOS up to date, and using two-factor authentication on your Cloudflare account.
14. Children's privacy
AppKey is a work and IT tool and isn't directed to children under 13. We don't knowingly collect personal information from children. If you believe a child has sent us personal information, contact us and we'll delete it.
15. International users
AppKey may be available in many countries. Apple, Cloudflare and Google may process information in countries other than yours, under their own data-transfer practices.
16. Changes to this policy
If AppKey's features, service providers or privacy practices change, we'll update this policy at appkey.app/privacy and change the date at the top. We may also mention material changes in the app or its App Store listing.
17. Contact us
Questions about this policy or AppKey's privacy practices:
AppKey Support
Published by Ryan Hendrickson (RYSNAS)
Email support@appkey.app
Website appkey.app/support
Location South Carolina, United States