Legal information

Privacy policy

What Mountit collects, why, and for how long — and the much longer list of what we never see.

Last updated: 1 September 2026 · Version française — seule version faisant foi

1. In one paragraph

Mountit connects your device straight to your storage. Your files, your credentials and your access tokens pass through none of our servers, because no server of ours is on that path. Stronger still, as of the date above: the app makes no request to any server we operate at all — not for licensing, not for announcements, not for updates. What it does send goes to a storage service or an identity provider you configured yourself — and, on the App Store edition, to Apple, whose StoreKit framework establishes your entitlement without passing through us.

2. What we never see

  • The contents of the files you open, copy, save or delete
  • The names of your files, folders, servers, buckets or shares
  • Your passwords, SSH keys, OAuth tokens or any other credential
  • Which storage providers you use, or what you mount
  • Any hardware identifier: the app reads no serial number, no platform UUID and no advertising identifier — there is no trace of one in the source

One reservation, entirely in your hands: if you write to us, we read what you send. A support message, a screenshot, or a diagnostic export in which you chose to include server names and paths (see §5) shows them to us. There is no other route by which any of this could reach us.

This is not merely a policy commitment. The app contains no telemetry, no analytics SDK and no crash-reporting SDK, and the privacy manifest shipped with it declares no tracking and an empty list of collected data types. We accepted a commercial cost for that: we gave up pricing by number of connected servers, precisely because checking it would have meant knowing them.

3. What is written to your own disk

None of this leaves your device. We describe it because an honest privacy policy also says what is written locally, and under what protection.

  • Cached file contents and pending writes are encrypted at rest with AES-256-GCM, under a key unique to each connection, derived from a secret held in the system Keychain.
  • The metadata index — file and folder names, sizes, dates, extended attributes, symlink targets — is a plain, unencrypted SQLite database inside the app's container. We would rather write that down than let you assume otherwise. The cache directory is excluded from Time Machine so it is not copied into a backup.
  • Credentials — passwords, SSH keys, S3 access keys, OAuth tokens, pinned host keys, and deliberately also server and user names — live in a local vault sealed with AES-256-GCM whose key is in the Keychain, marked this device only: it is never synchronised to iCloud Keychain and cannot be restored onto another machine.

4. Google user data

This section is written to answer Google's OAuth verification review point by point. Everything in it is also true of the other storage providers Mountit connects to.

4.1 What Google user data the app accesses

Mountit requests exactly two Google scopes, and only when you connect the corresponding service:

  • https://www.googleapis.com/auth/drive.file — Google Drive. This is a non-sensitive, per-file scope: it reaches only the files and folders you yourself pick, or that Mountit created. Mountit does not request the restricted drive scope, a deliberate limit on what the app can see at all.
  • https://www.googleapis.com/auth/devstorage.read_write — Google Cloud Storage, for the buckets you name.

The data reached through those scopes is: the contents, names, sizes and modification times of the files and folders you chose to mount. Mountit requests no openid, email or profile scope, makes no UserInfo request and keeps no ID token, so it receives no Google account identity at all — not your name, not your email address.

4.2 How it is used

Solely to provide the app's one user-facing feature: presenting your chosen storage as a location in the Finder sidebar, and in the Files app on iPadOS and visionOS, so you can list, open, read, write, rename and delete files. The access happens on your own device, directly against Google's APIs. There is no other use, and no secondary use.

4.3 With whom it is shared

Nobody. It is never transmitted to ASKLERA or to any server we operate — as of the date above the app contacts no server of ours for any purpose. It is not sold, rented, disclosed or transferred to any third party, and no subprocessor of ours ever touches it. See §6 for the two subprocessors we do use, neither of which is on this path.

One third-party script, named rather than left to be discovered: when you pick a Google Drive folder, the app opens Google's own picker, which loads https://apis.google.com/js/api.js from Google into a local web view holding the access token. That is Google's code seeing Google's own data, on your machine.

4.4 How it is protected

Transport is TLS 1.2 or 1.3 to Google's endpoints, direct, with no proxy of ours in between. OAuth uses PKCE and the token request goes straight to Google's token endpoint. Tokens rest in the sealed vault described in §3, keyed from the Keychain and marked this device only. Cached file contents are encrypted at rest with AES-256-GCM. Because the data never reaches us, no employee, contractor or subprocessor of ours can read it — the protection is architectural rather than procedural.

4.5 Retention and deletion

We retain no Google user data, because we never receive any. On your device, removing a connection in Mountit erases its tokens from the vault and its cached data from disk; merely disconnecting or ejecting a volume ends the session and deliberately keeps both, so you can reconnect. You can also revoke Mountit's access at any time at myaccount.google.com/permissions, which takes effect immediately and independently of the app. To have erased the data we do hold — support correspondence, and licence records once the shop opens — write to privacy@mountit.app; we answer within one month.

4.6 Limited Use

Mountit's use of information received from Google Workspace scopes will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Equivalently, in the wording many reviewers still look for: Mountit's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Restated in full: we limit our use of this data to providing the user-facing feature above. We do not transfer it, except where you direct it, where security or the law requires it, or as part of a merger, acquisition or sale of assets and then only with your prior explicit consent. We do not let humans read it — nobody can, because it never leaves your device. We never sell it, never transfer or use it for advertising, retargeting or interest-based advertising, and never use it to determine creditworthiness or for lending. These obligations bind our employees, agents, contractors and successors.

4.7 Artificial intelligence and machine learning

Google Workspace APIs, and data obtained through any Google scope, are not used to develop, improve or train generalised or non-personalised artificial-intelligence or machine-learning models. Mountit contains no model trained on user data, and no such training happens anywhere else, because the data never reaches us. The one predictive component in the app — a read-ahead heuristic that decides which blocks to fetch next — runs entirely on your device and is keyed on inode numbers, never on file names or contents.


5. Other data we do process

Licence and trial
No server is contacted. On the App Store edition, entitlement comes from StoreKit — from Apple — under Apple's privacy policy; we receive neither your Apple Account, nor your payment method, nor your address. The trial is measured by a single local Keychain item of eight bytes: the trial start date, and nothing else. When the direct shop opens, licence activation will send us the licence key, a locally computed device identifier, a device name you choose, the platform, the app version and a flag saying whether the install runs without a graphical session — and nothing about your storage. Separately, the update-entitlement check, once enabled, will send only an opaque licence token, the installed version and the platform name; the server answering it records no IP address and no requested path, and rejects any request carrying a URL parameter or a cookie before processing it. This page will be updated and re-dated before either goes live.
In-app announcements
Read from a signed catalogue already installed on the device and filtered locally by edition and date. Nothing is sent; no server knows an announcement was shown to you, and dismissing one stays on your machine.
Support
The support form on this site sends the topic, your email address, a subject and your message. Nothing else. Diagnostic exports you may attach carry connection state, server responses and error codes. Passwords and keys are never included, and secrets inside an address are stripped at the source. Server names, volume names and file paths are removed by default: an export includes them only if you switch on “Include server names and file paths” yourself before producing it.
Browsing this site
No cookies, no third-party analytics; the content-security policy forbids third-party scripts, styles and fonts outright. See the cookie policy. Like any web server, ours records requests in an access log that includes the IP address; that is the only processing of its kind.

6. Legal bases, retention and recipients

Legal bases (GDPR art. 6): performance of the contract, for supplying the software and issuing a licence; legitimate interest, for security and incident diagnosis, for answering support requests and for preventing licence abuse; legal obligation, for accounting records.

  • Accounting records — 10 years (French commercial code, art. L.123-22)
  • Licences and activations — the licence's validity, then 3 years
  • Support correspondence — 3 years from the last exchange
  • Server access logs — 6 months at most, then deletion

Nothing is sold, rented or handed on. Our only recipients are two technical subprocessors: Hetzner Online GmbH (site and mail hosting, Germany / Finland, EU) and OVH SAS (domain names and DNS, France, EU). That list is complete. Mail is self-hosted on that infrastructure — no third-party email, newsletter or CRM service is used, and there is no mailing list. All infrastructure is in the European Union and no transfer outside the EU takes place.

The storage services and identity providers you configure are not our subprocessors: they are yours, chosen by you, and the app connects to them on your behalf from your device.

No payment processor is in place: the shop is not open, no payment is processed and no card data is collected. We deliberately do not name a provider we do not use — a policy that lists a non-existent subprocessor is false the day it is published. The row will be added, with purpose and location, before the first transaction.

7. Are we your GDPR processor?

For your file data, no — and the architecture, not a contract, is why. No infrastructure we operate receives, stores or transmits your files, their names, your servers or your credentials, so there is no processing "on your behalf" within GDPR art. 4(8) and nothing for an art. 28 agreement to govern. You remain the controller; your storage provider's role depends on the facts — usually your processor, sometimes a separate controller for some operations, and there is no third party at all if you mount your own server. For licence, billing and support data we are the controller, not a processor. The full reasoning, and what we will put in writing if your procurement process needs a document, is on the sous-traitance page.

8. Your rights

You have the rights of access, rectification, erasure, restriction, objection and portability (GDPR arts. 15–22). Write to privacy@mountit.app; we answer within one month. You may lodge a complaint with the French supervisory authority, the CNIL — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr.

Controller: ASKLERA — société en cours d’immatriculation (a company in the course of registration). Full details in the mentions légales. No data protection officer is appointed: none of the three cases in GDPR art. 37 applies — we are not a public authority, our core activity is not large-scale systematic monitoring, and we process at scale neither special-category data under art. 9 nor criminal-conviction and offence data under art. 10. Requests are handled by the controller in person.

Three things art. 13 requires that are easy to omit: no decision producing legal effects is taken by automated means and no profiling is carried out; where processing rests on consent you may withdraw it at any time, without affecting what was lawful before; and providing your data is required only where it conditions the contract or an accounting obligation — declining to give an email address simply makes it impossible to answer a support request or deliver a licence key.

9. Security

Traffic is encrypted with TLS 1.2 or 1.3. The domain carries a CAA policy restricting certificate issuance, and mail enforces SPF, DKIM, DMARC and MTA-STS in enforce mode. A breach likely to result in a risk to your rights and freedoms is notified to the CNIL within 72 hours (GDPR art. 33); where the risk is high, you are additionally informed without undue delay (GDPR art. 34). Found a vulnerability? security@mountit.app — we will not pursue anyone reporting in good faith.

10. Changes

Any substantial change will be flagged on this page and, where it concerns you directly, by email. Earlier versions are available on request.

11. Language

This is a translation, published so that customers and platform reviewers outside France can read it. The French version is the original and the only binding one: ASKLERA is a French company, its consumer-facing documents are drafted in French, and in the event of any discrepancy the French text prevails. Both are kept in step, and both are dated.

Mountit

Remote storage, mounted as a drive in Finder on Apple platforms. A Rust core, a SwiftUI app, and no kernel extensions.

Product

  • Features
  • Protocols
  • Backends
  • Compatibility ledger
  • Pricing
  • Download
  • macFUSE on macOS
  • Compare alternatives

Help

  • Documentation
  • Mounting a volume
  • Contact support
  • Changelog
  • News
  • Accounts — coming soon

Légal

  • Mentions légales
  • Confidentialité
  • CGU
  • CGV
  • Cookies
  • Licence
  • Sous-traitance

Legal (EN)

  • Privacy policy
  • Terms of use
  • Licence agreement
  • Security
  • Leaving Mountit

© 2026 Mountit. All rights reserved.

Mac, macOS, iPadOS, visionOS and Finder are trademarks of Apple Inc. Mountit is not affiliated with Apple.