Privacy Policy

Last updated: July 10, 2026

JarGrid is designed as a local-first website launcher and workspace organizer.

Data Stored on Device

JarGrid stores saved website titles, URLs, domains, descriptions, notes, folders, named shelves, shelf environment themes, folder-to-shelf assignments, profiles, tags, Smart Rules, browser preferences, workspace membership, favorite status, launch settings, custom icon initials and colors, optional user-selected custom icon images, website icon source URLs, verified local website icon files, and optional Website Health result metadata on the device. Health metadata can include check time, availability category, HTTP status, response timing, resolved destinations, a login-page change flag, and a short failure summary. Icon files use deterministic website identifiers in the shared App Group container so stale absolute paths can be repaired without contacting the website when the local copy still exists.

Optional credential usernames and Keychain references are stored locally. Password values are stored in the iOS Keychain and are not stored in SwiftData, UserDefaults, JSON backups, or CSV exports.

Shared App Data

JarGrid uses an App Group to share limited snapshots with its widgets, Shortcuts and App Intents, Spotlight, share extension, and Safari Web Extension. These snapshots contain non-secret launcher data such as website titles, URLs, domains, favorite status, custom icon initials, colors and image paths, verified favicon paths, folder names, profile names, and workspace names.

Website Metadata and Icon Repair

When a website is added, its icon is refreshed, or a saved local icon is missing, JarGrid can request page metadata and icon files from that website's server. JarGrid validates downloaded image data before replacing the saved path. A failed download or invalid response does not erase the last verified icon. JarGrid does not use a third-party favicon service in production icon repair.

Website Health Checks

Website Health checks are user initiated unless automatic stale checks are enabled in Settings. A check contacts the saved website and, when configured, its saved login URL using an ephemeral session that does not accept or store cookies and does not use a persistent URL cache. JarGrid normally sends a lightweight HEAD request and uses a limited GET fallback only when a server rejects HEAD. The destination server can receive information normally exposed by an HTTPS connection, such as the device's network address.

JarGrid saves only the resulting status, timing, HTTP code, resolved destination, check time, login-page change flag, and short error summary. It does not save website response bodies. Automatic checks are disabled by default, run in small batches, and exclude private sites unless the user explicitly chooses to include them.

Local Smart Organization

JarGrid's category suggestions, smart tags, launcher command matches, and workspace suggestions run locally from saved website metadata, notes, tags, folders, profiles, favorites, and recent-launch state. These features use deterministic on-device matching and do not require Apple Intelligence, Foundation Models, or any country-gated Apple Intelligence service. The current build does not send saved website data to an external AI service.

Motion Effects

When the optional Shelf motion setting is enabled, JarGrid samples processed device motion only while the 3D Shelf is visible. Tilt and shake values apply local RealityKit impulses that animate and settle shelf objects. The Shelf uses RealityKit's fully virtual non-AR camera mode and does not access the device camera. JarGrid does not save, share, or transmit motion samples, and motion effects can be disabled in Settings.

JarGrid stores a local list of website identifiers already surfaced by each jar so later shakes can prioritize unseen logos. This reveal history contains no motion samples, URLs, titles, or credentials; it is not transmitted, included in JarGrid JSON or CSV exports, or synced through JarGrid CloudKit, and removed websites are pruned from it.

Browsing Data

JarGrid can clear cookies, caches, local storage, and website data created by its in-app WebKit browser. Safari and Chrome browsing data remain controlled by Safari and Chrome. iOS does not allow JarGrid to read or erase another browser's cookies, cache, passwords, or history.

JarGrid only receives Safari page details when the user explicitly shares a page or taps the Add to JarGrid Safari Web Extension action for the active page. JarGrid does not automatically collect Safari browsing history. Launch history tracking can be turned off in Settings. When disabled, JarGrid does not update recent-launch timestamps when websites or workspaces are opened.

Credentials

Credential storage is optional. Password fill and password copy require local authentication with Face ID, Touch ID, or device passcode. Settings can also require local authentication before opening any private-mode website. In-app browser form detection and automatic autofill offers are disabled until the user enables them in Settings. JarGrid cannot inspect or autofill forms in Safari, Chrome, or other external browsers.

Backups

JSON backups can include saved website organization, named shelves, shelf themes, folder-to-shelf assignments, metadata, notes, favicon source metadata, readable favicon data, custom icon metadata and image data, Smart Rules, launch settings, credential metadata, and Website Health result metadata. Backups do not contain website response bodies. Protected JSON backups encrypt the same payload with a user-entered passphrase using Apple OS cryptography APIs. JarGrid does not store or recover that backup passphrase.

When iCloud Drive is available for JarGrid, users can manually save JSON or protected JSON backup files to JarGrid's iCloud Drive container. When CloudKit is available, users can manually sync a JSON snapshot through JarGrid's private CloudKit database; JarGrid merges timestamped website, credential-reference, and Smart Rule records before saving the merged snapshot back to CloudKit. JarGrid does not sync Keychain password values through iCloud Drive or CloudKit backups. CSV exports include website-list metadata only. Password values are not exported.

Analytics

JarGrid does not include third-party analytics or tracking SDKs in the current build.

Purchases

JarGrid Professional is an optional non-consumable in-app purchase processed by Apple. JarGrid uses StoreKit entitlement information to determine whether Professional is active and does not receive or store the user's payment-card details. Free includes up to 12 saved websites; Professional removes that limit. Existing saved websites remain available if a library is already at or above the free limit.

Deleting Data

Users can delete saved websites, folders, profiles, workspaces, and credential references inside JarGrid. Deleting a website also removes its durable favicon and custom icon image files. In Grid mode, deleting a folder after the non-empty-folder warning also deletes every website inside it, removes those website identifiers from workspaces, and removes their credential references and local icon files. Cancel leaves the folder and websites unchanged. Settings includes maintenance actions for clearing in-app browser data and launch history.

Contact

For privacy questions or requests, email volome@gmail.com or visit the JarGrid support page.