Lupa Privacy Policy
Last updated: September 19, 2026
This policy explains what data Lupa, the macOS app that analyzes disk space, processes and what happens to it. It also covers this website.
1. Who is responsible
Lupa is developed by Sergio Abad. If you have any questions about this policy or your data, write to hola@lupamac.com.
Lupa's developer does not receive or store personal data from the app's users: everything described below happens on your Mac or between your Mac and the services you decide to connect.
2. Disk analysis
- Lupa analyzes the folders or the disk you choose. To do so, it only reads metadata: each file's size, type and dates. It never reads the contents of files when analyzing.
- Lupa runs inside Apple's App Sandbox with read-only permission for whatever you choose to analyze. macOS itself prevents it from deleting, moving, renaming or modifying your files.
- Lupa never triggers iCloud downloads: files that are only in the cloud stay in the cloud.
- Analysis results are kept in memory only and disappear when you close the app. They are not written to disk or sent anywhere.
The only case in which Lupa reads a file's contents
If you connect Google Drive or Dropbox, choose a file and click “Archive” («Archivar» in the app), Lupa reads that file to upload a copy to your account. This is the only situation in which Lupa reads the contents of a file. It happens one file at a time, only when you ask, never in the background or automatically.
3. What is stored on your Mac
Lupa stores very little information, and all of it on your Mac:
- In the app's preferences:
- your interface settings;
- an archive history with the name, size, date, service (Google Drive or Dropbox) and link of each copy you have uploaded. The file's path on your Mac is never stored. You can clear this history from the app at any time.
- In the macOS Keychain, only if you set up these services:
- the Groq API key;
- the Google Drive and Dropbox credentials and access tokens.
When you click “Disconnect” («Desconectar» in the app), this data is deleted from the Keychain.
4. Internet connections
Lupa connects to the internet only in these cases:
- if you have turned on Groq to write the explanations for the suggestions;
- if you have connected a Google Drive or Dropbox account to upload copies.
Otherwise, Lupa doesn't open any connection. It never connects to the developer's servers, because there are none.
5. Google Drive: what Google data Lupa uses
Connecting Google Drive is optional and stays off until you connect an account.
What Google data Lupa uses
- Lupa requests a single Google permission:
drive.file(https://www.googleapis.com/auth/drive.file). - With that permission, Lupa can only access the files it uploads itself. It can't see, read, modify or delete any other files in your Google Drive.
- From the files it uploads, Lupa uses what it needs to check the copy and give you a link: the size, the MD5 checksum and the link to the copy.
- Lupa receives from Google the credentials and access tokens needed to upload files on your behalf.
What it uses them for
Solely to keep a safe copy of a file you choose before you delete it yourself. Specifically:
- Uploading the file you chose when clicking “Archive” («Archivar» in the app) to your Drive, in the
Lupa/YYYY-MMfolder (for example,Lupa/2026-09). - Verifying that the copy is correct: the copy's size and MD5 checksum must match the original's.
- Saving the link to that copy in your archive history.
Uploading a copy doesn't delete anything from your Mac. Lupa doesn't use Google data for any other purpose: not for advertising, profiling, usage analytics or training artificial intelligence models.
Where it is stored
- Google credentials and tokens are stored in the macOS Keychain, on your Mac.
- The archive history (name, size, date, service and link of each copy, never the path) is stored in the app's preferences, on your Mac.
- The copies of your files are stored in your own Google Drive, in the
Lupa/YYYY-MMfolder. - Nothing is stored on the developer's servers: they don't exist.
Who it is shared with
No one. Google data only travels between your Mac and Google. Lupa's developer doesn't receive it, and Lupa doesn't transfer it to third parties, including Groq or any other artificial intelligence provider.
How to revoke access
You can revoke Lupa's access to your Google Drive at any time, in two ways (doing both is the most thorough):
- In Lupa: click “Disconnect” («Desconectar» in the app, whose interface is in Spanish) for Google Drive. This deletes the Google credentials and tokens from the macOS Keychain on your Mac.
- In your Google Account: go to https://myaccount.google.com/permissions, find Lupa and remove its access.
Retention and deletion
- Credentials and tokens remain in the Keychain until you click “Disconnect” («Desconectar» in the app).
- The archive history remains on your Mac until you clear it from the app.
- The copies you have uploaded are yours and stay in your Google Drive even if you disconnect Lupa. You can delete them from Google Drive at any time.
Limited Use
Lupa's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google processes your data according to its own privacy policy: https://policies.google.com/privacy.
6. Dropbox
Connecting Dropbox is optional and stays off until you connect an account.
- Lupa uses “App folder” access: it can only write to its own app folder inside your Dropbox and sees nothing else.
- It never overwrites an existing file.
- It only uploads the files you choose, one at a time, when you click “Archive” («Archivar» in the app).
- Each copy is verified: its size and Dropbox
content_hashmust match the original's. - Dropbox credentials and tokens are stored in the macOS Keychain; clicking “Disconnect” («Desconectar» in the app) deletes them.
- The copies stay in your Dropbox even if you disconnect Lupa; you can delete them from Dropbox. You can also revoke Lupa's access from your Dropbox account settings, in the connected apps section.
Dropbox processes your data according to its own privacy policy: https://www.dropbox.com/privacy.
7. Groq (optional cloud artificial intelligence)
Lupa's suggestions are decided by a local rules engine, not an AI. An AI can only, if you want, write and group the explanations. It never decides what to delete.
- Groq is off by default.
- It is only used if you turn it on, paste your own Groq API key and accept a consent screen.
- Groq receives an anonymized summary of the analysis, with internal identifiers instead of file paths.
- Your API key is stored in the macOS Keychain and deleted when you disconnect Groq in Lupa.
- Since you use your own key, the relationship with Groq is directly between you and Groq.
Groq processes data according to its own privacy policy: https://groq.com/privacy-policy/.
Without Groq, the explanations are generated on your Mac, from local templates or with Apple Intelligence.
8. Apple Intelligence
If you use Apple Intelligence (Foundation Models) to write the explanations, everything happens on your own Mac, with no internet connection. Nothing leaves your computer.
9. What Lupa doesn't do
- It includes no telemetry, analytics or usage reports.
- It has no Lupa accounts and doesn't ask you to sign up.
- It has no servers of its own and sends nothing to the developer.
- It doesn't sell, rent or share data with anyone.
10. This website
- This website uses no cookies, analytics or tracking pixels.
- If you choose a theme (light, dark or system) on this website, that preference is saved only in your browser's local storage (localStorage): it isn't a cookie, it isn't sent anywhere and it is strictly functional. The website's language is chosen through the URL, and no cookie is used for that either.
- It is hosted on Vercel. Like any web server, the hosting provider may process technical data about visits, such as the IP address, the date and the page requested, in order to serve the website and keep it secure. Lupa's developer doesn't use that data to identify you or to analyze your visits. You can read Vercel's privacy policy at https://vercel.com/legal/privacy-policy.
- If you write to hola@lupamac.com or use the contact form, we will use your data only to reply to you (more details in the next section).
11. This website's contact form
If you write to us through this website's contact form:
- What data: your name, your email address and your message.
- What for: only to reply to you. We don't use it for advertising or to send you marketing communications.
- How it gets to us: the message is sent through Resend, an email delivery provider, and delivered to the inbox of the person responsible. Resend keeps a temporary log of the emails it sends and processes the data according to its own privacy policy: https://resend.com/legal/privacy-policy.
- Where it is stored: it isn't stored on any server or database of ours; it stays in the inbox of the person responsible and, temporarily, in Resend's sending log.
- How long: only as long as needed to handle your message and, at most, 12 months.
- Deletion: you can ask us at any time to delete your messages by writing to hola@lupamac.com.
- To prevent abuse, the website counts for a few minutes how many messages are sent from each IP address. That count only exists in the server's memory and is discarded right away; it isn't stored or linked to your message.
12. Your rights
Since Lupa's developer doesn't receive data from the app, it doesn't store anything from it that you could ask to access or delete: the data Lupa generates is on your Mac and you control it (you can clear the archive history and click “Disconnect” («Desconectar» in the app) for each service). Data stored by Google, Dropbox or Groq is governed by their own policies.
If you have written to us by email or through the contact form, you can ask us at any time to delete those messages by writing to hola@lupamac.com. You also have the right to lodge a complaint with the data protection authority in your country.
13. Children
The Lupa app doesn't collect personal data from anyone, including children. This website's contact form is not directed to children. The third-party services you can connect (Google Drive, Dropbox and Groq) have their own age requirements.
14. Changes to this policy
If this policy changes, we will publish the new version on this same page and update the “Last updated” date. If the change affects how Lupa uses Google, Dropbox or Groq data, we will say so prominently.
15. Contact
For any questions about this policy or your data, write to hola@lupamac.com.