Privacy Policy
Privacy for Chest and chest.boringbar.app.
Last updated: October 5, 2026. This Privacy Policy explains how BORINGBAR LLC handles data when you use Chest, the macOS menu bar manager, or visit chest.boringbar.app.
1. Scope and Controller
BORINGBAR LLC is responsible for the Chest app it builds and distributes and for the chest.boringbar.app website. This policy covers both.
boringBar, our taskbar for macOS, and boringbar.app have their own Privacy Policy. If you build Chest yourself from its source code, the update checks described below only happen if your build is set up for them.
2. Data the App Collects
None. Chest does not collect, store or send personal data to us or anyone else.
To do its job, Chest keeps a few settings on your Mac, in its macOS preferences:
- which apps’ menu bar items you hid left of the dot, and which you put in the chest;
- where you placed the dot in the menu bar.
These settings never leave your Mac.
3. Permissions on Your Mac
Chest asks for two macOS permissions and uses them only on your Mac, only for what is described here:
- Accessibility, to find the items in the menu bar and where they are, and to open an item’s menu from the drawer.
- Full Disk Access, because macOS keeps the list under System Settings › Menu Bar › Allow in the Menu Bar in a protected folder. Chest reads and changes that one list, in Control Center’s preferences, to switch apps’ menu bar items on and off. It reads no other files.
When Chest starts, it opens and immediately closes your Mail folder without reading anything in it. That attempt is what makes macOS add Chest to the Full Disk Access list in System Settings, so you can switch it on there.
Spotlight’s menu bar item is switched through Spotlight’s own setting, which needs neither permission. Nothing Chest sees through these permissions is recorded or sent anywhere, and the source code is open for anyone to check.
4. Update Checks
Chest uses Sparkle, an open-source updater for Mac apps, to check for new versions. About once a day, and when you choose Check for Updates, it downloads a small update feed from files.boringbar.app. When a new version is available, it downloads it from the same place and checks its signature before installing it.
Like any request on the web, an update check reveals your IP address and a user agent naming the versions of Chest and Sparkle. Chest does not send system profile information or any identifier of its own. Our file host may keep standard request logs, such as IP address, time and file requested, for security and reliability. We do not use them to identify you.
If you install Chest with Homebrew, Homebrew’s own analytics and privacy policy apply to that install.
5. The Website
chest.boringbar.app does not use cookies, analytics, tracking pixels or browser storage. The demo on the page runs entirely in your browser and keeps nothing.
The page loads its typeface from Google Fonts, so Google receives your IP address and browser details when you visit, under Google’s Privacy Policy. Our hosting provider may keep standard request logs for security and reliability.
Links to GitHub, boringbar.app and other sites lead to services with their own privacy practices.
6. Sharing of Personal Data
We do not sell, rent or share personal data, and we do not use it for advertising. The only data we handle are the request logs described above, which stay with the hosting providers that serve our files and website.
7. Data Retention
Chest’s settings stay on your Mac until you remove them. Uninstalling with brew uninstall --zap --cask chest, or deleting Chest and its preferences, removes them. Request logs are kept only as long as our hosting providers retain them for security and reliability.
8. Your Rights and Choices
Depending on where you live, you may have rights to access, correct or delete personal data held about you. Since Chest does not collect personal data, we generally have nothing to provide or delete. You can turn off update checks by blocking Chest’s network access, and you can stop Google Fonts requests with your browser’s content settings.
For questions about this policy, open an issue on GitHub.
9. Children’s Privacy
Chest is not directed to children, and it does not collect personal data from anyone, including children.
10. Changes to This Policy
We may update this Privacy Policy from time to time, for example if Chest gains a feature that uses data differently. The revised version becomes effective when posted on this page unless a later date is stated.